Shaoyong Du

dblp:169/2216 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0002-7572-1959ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 6 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Tap Dance on Android External Storage: Covert Channels Built on File Operations
Shaoyong Du, Qinchen Guan, Tengyao Li, Chunfang Yang, Xiangyang Luo 0001
INFOCOM1
2026 A survey on network flow watermarking: A problem-oriented perspective
Tengyao Li, Kai-Yue Liu, Shaoyong Du
Comput. Secur.3
2026 An Empirical Analysis of Information Leakage of File Operations on Android External Storage
abstract
Current Android apps rely heavily on external storage. When using the external storage, apps apply different security strategies (e.g., randomizing file name, encrypting file content) to prevent privacy risks. Even so, we find that privacy risks still exist, i.e., information leakage of apps' file operations. Users follow their habits to run apps and some of the apps conduct file operations on external storage, which potentially expose users' regular activities. In this paper, we conduct the first empirical study on this problem and implement a file-operation-based pipeline, OP-PERUSE. Besides a dataset of 5,359,339 file operation events collected from the volunteers, we crawl 22,484 app records from the third-party app statistics websites. By combining these data, we get some timely and fine-grained information about the users, e.g., current affiliation, position, habits, etc. To further understand this problem's severity, we conduct a static code analysis on 15,098 apps. We find that 1,305 (8.64%) apps tend to collect file operation events, and more than half of these apps adopt the third-party SDKs which gather file operation events, indicating this problem could have persisted over a long period of time. To prevent this problem, we provide some security recommendations for different stakeholders.
Shaoyong Du, Qinchen Guan, Kerong Wang, Chunfang Yang, Xiangyang Luo 0001
IEEE Trans. Dependable Secur. Comput.1
2026 An Efficient Website Fingerprinting for New Websites Emerging Based on Incremental Learning
abstract
Website fingerprinting attacks leverage encrypted traffic features to identify specific services accessed by users within anonymity networks such as Tor. Although existing WF methods achieve high accuracy on static datasets using deep learning techniques, they struggle in dynamic environments where anonymous websites continually evolve. These methods typically require full retraining on composite datasets, resulting in substantial computational and storage burdens, and are particularly vulnerable to classification bias caused by data imbalance and concept drift. To address these challenges, we propose EIL-WF, a dynamic WF framework based on incremental learning that enables efficient adaptation to newly emerging websites without the need for full retraining. EIL-WF incrementally trains lightweight, independent classifiers for new website classes and integrates them through classifier normalization and energy alignment strategies grounded in energy-based model theory, thereby constructing a unified and robust classification model. Comprehensive experiments on two public Tor traffic datasets demonstrate that EIL-WF outperforms existing incremental learning methods by 6.2%–20.2% in identifying new websites and reduces catastrophic forgetting by 5.4%–20%. Notably, EIL-WF exhibits strong resilience against data imbalance and concept drift, maintaining stable classification performance across evolving distributions. Furthermore,EIL-WF decreases training time during model updates by 2–3 orders of magnitude, demonstrating substantial advantages over conventional full retraining paradigms.
Zhengge Yi, Tengyao Li, Meng Zhang 0044, Xiaoyun Yuan, Shaoyong Du, Xiangyang Luo 0001
IEEE Trans. Netw. Serv. Manag.5
2025 UeLP: accurate user linkage across social platforms against location errors
abstract
Abstract User linkage across social platforms can connect the accounts of the same user across different social networks, which is crucial for the identification of users’ multiple social identities and cross-platform association analysis. Cross-platform user linkage based on location is a typical method in current research. These methods typically rely on check-in data to calculate user similarity. However, different from check-in location, the location data obtained from instant messaging social platforms may contain random errors, leading to low accuracy of user linkage of such methods. To solve this problem, this paper proposes an accurate user linkage method across social platforms against location errors. First, unlike existing methods that employ fixed-size grids, this paper uses a multi-grained spatio-temporal grid to organize data, in order to accurately extract user features from error locations. Then, by extracting coarse-grained movement pattern features from user trajectories, candidate users are filtered out, and a small subset of candidate uses is generated to effectively reduce the search space. Next, we establish a weight model based on grid contribution and motion sequence similarity to extract location and temporal features with stronger user orientation. Finally, according to the weight model, the weighted cluster center distance of trajectories is used to calculate the similarity between two different user trajectories. The user with the highest similarity is selected from the candidate subset to complete the user linkage. The extensive experiments are conducted on six public datasets containing 115 866 trajectories and a self-built dataset with 5358 trajectories. The results show the following: compared with the four existing typical location-based methods $k$-BCT, GS, TF-IDF, and TF-IWF, the accuracy Acc@1 is improved by an average of 33%, 44.94%, 15.2%, and 14.55%, respectively, and the accuracy Acc@3 is improved by 30.52%, 34.67%, 13.84%, and 13.19%, respectively.
Ruiting Liu, Wenqi Shi 0001, Shaoyong Du, Yimin Liu 0004, Xiangyang Luo 0001
Comput. J.4
2025 Localization Algorithm Based on the Relationship Between Trapezoidal Trajectory and Energy Consumption of Mobile Anchor Nodes
abstract
Node localization technology is increasingly receiving extensive attention from academia and industry due to its strong concealment and high fault tolerance in wireless sensor networks (WSNs). Mobile anchor nodes (MANs) assisted localization is often used in existing WSNs. However, assisted localization based on MANs is still a challenging problem. On one hand, it is difficult to determine the number of anchor nodes (ANs) to support the energy required for the entire movement trajectory. On the other hand, unknown nodes at the boundary region are difficult to obtain sufficient beacon information for localization. A localization algorithm based on the relationship between trapezoidal trajectory and energy consumption of MANs is proposed to solve this challenging problem in the current research. In the proposed algorithm, we design a trapezoidal trajectory based localization algorithm for MANs (TTLMA) to optimize the movement trajectory of ANs. At the same time, determine the number of ANs by analyzing the relationship between the initial energy of ANs and the energy required by the localization algorithm. Select an appropriate algorithm to locate unknown nodes (UNs) according to the number of beacon information received by them. We conducted multiple simulations to evaluate the proposed algorithm’s performance. The experimental results indicate that compared with five existing typical localization algorithms, the proposed algorithms have positive advantages in terms of localization error and coverage, with average localization error reduced by 0.15m-1.16m, average localization coverage improved by 8%-38%. Moreover, the energy consumption of the proposed algorithm is relatively low, requiring only one anchor node to traverse the designed trapezoidal trajectory.
Wenyan Liu 0004, Xiangyang Luo 0001, Shichang Ding, Shaoyong Du
IEEE Internet Things J.4
2025 Twitter User Geolocation Based on Location Feature Enhancement
abstract
User location discovery from social media is crucial for location-based services such as emergency awareness and event monitoring. Existing approaches generally integrate user-generated text features and social relationships but insufficiently explore location-specific features and geographically proximate relationships, leading to suboptimal accuracy. In this article, we propose a Twitter user geolocation method based on location feature enhancement to better capture the location characteristics in users’ tweets and social relationships. Specifically, a user tweet representation algorithm based on location feature separation (TwLS) is designed. By leveraging words’ location-aware weight matrix and pre-trained embeddings, TwLS calculates a tweet representation for each user in every location, explicitly indicating the relevance between users and various locations. Additionally, we develop the local celebrity discovery method (LocCel) to construct social networks by identifying and preserving geographically concentrated high-degree nodes while filtering noise. Thereby, LocCel enhances local relationships and strengthens location-proximate connections within the user social network. Experiments on two real-world datasets show that our method outperforms seven baselines, improving user geolocation accuracy by 3.1% ∼ 8.1% and 1.8% ∼ 8.8%, while reducing median error by 22.2% ∼ 52.8% and 19.4% ∼ 50.7%, respectively.
Meng Zhang 0044, Xiangyang Luo 0001, Ningbo Huang, Yimin Liu 0004, Shaoyong Du
ACM Trans. Web5
2024 A Framework for Detecting Hidden Partners in App Collusion
abstract
Nowadays, in Android ecosystem, to bypass current malware detections, adversaries often distribute the malicious and sensitive functions into different apps. These apps collude to conduct some malicious activities, such as illegally collecting the user’s sensitive data. To further understand the harm of app collusion, we conduct a real-world study. Besides the simple collusion case with two apps, which has been well studied, there are also some complicated collusion cases that have seldom been studied but would greatly endanger users’ privacy. These cases can be categorized into N-to-1 collusion, 1-to-N collusion, and chain-based collusion. To deal with such complicated collusion attacks and detect the hidden partners, a detection framework CSCdroid was proposed. CSCdroid obtains sensitive data flow and static features such as ICC (Inter-Component Communication) channels in apps through static analysis. Then it detects potential collusion apps by data flow linking. To show the effectiveness of CSCdroid, we apply it to the app dataset provided by DroidBench, and its F1 score can reach 0.91, which is better than the current existing work Amandroid and DIALDroid. We conduct experiments on a real-world app dataset (4,100 apps) with CSCdroid, and results show that 73 apps leak the user’s sensitive data. Some of the 73 apps present complex collusion scenarios with other apps. These complex collusion scenarios can result in the aggregation of sensitive information within an app, posing a significant threat to user privacy.
Qinchen Guan, Shaoyong Du, Kerong Wang, Chunfang Yang, Xiangyang Luo 0001
TrustCom2
2023 UGCC: Social Media User Geolocation via Cyclic Coupling
abstract
Social media user geolocation is to infer users’ resident locations based on social media data, including user texts and social relationships. Existing methods mainly rely on the textual feature propagation in the social graph to fuse users’ textual and social information. The geolocation accuracy is susceptible to insufficient data sources and inadequate fusion. In this paper, a social media user geolocation algorithm based on cyclic coupling (called UGCC) is proposed. We collapse the social graph based on the neighbor location proximity, which reduces noisy information while enriching social relationships. Unlike existing methods that ignore the social graph's structure, UGCC measures the probability of users being in the candidate locations according to users’ structural location in the social sub-graph. Finally, we design a cyclic coupling mechanism to fuse the users’ textual and social information, which enables the two kinds of information to enhance each other and geolocate users cooperatively. Compared with ten typical existing methods (such as RELP and HGNN), experimental results show UGCC's superior performance. On two public datasets, the city-level accuracies of UGCC reach 40.8% and 50.1%; the median errors are 35.1% and 23.4% lower than the state-of-the-art methods.
Yimin Liu 0004, Xiangyang Luo 0001, Zhiyuan Tao, Meng Zhang 0044, Shaoyong Du
IEEE Trans. Big Data5
2023 Neural Attention Networks for Recommendation With Auxiliary Data
abstract
With the rapid development of Internet technologies, an increasing amount of auxiliary data can be readily obtained through Web services. To alleviate the data sparsity issue, auxiliary data based recommendation has emerged for better recommendation performance. However, existing auxiliary data based methods suffer from two problems. First, only the relation features related to the meta-paths are extracted from auxiliary data, which may lead to features useful for recommendation being lost irreversibly. Second, an assumption is made that an individual has the same preference over the identical characteristic of different items, which is often invalid and may lead to misleading recommendations. Actually, a user may place different importance on the same feature of different items, and an item may get different attention from the same feature of different users. In this paper, we propose a neural network framework, named Neural Attention Recommendation model (NARec), for auxiliary data based collaborative filtering. For the first problem, we characterize users and items from three aspects, namely latent features, attribute features, and meta-path based relation features, which can comprehensively extract the useful recommendation features from auxiliary data. Regarding the second problem, we integrate different user features and item features into an attention mechanism based rating prediction model for recommendation, which can adaptively characterize the personalized features of users and items. Extensive experiments on three real-world datasets demonstrate that NARec significantly outperforms the state-of-the-art recommendation methods in the rating prediction task.
Daofu Gong, Zhenyu Li 0004, Shaoyong Du, Fenlin Liu
IEEE Trans. Netw. Serv. Manag.4
2022 Watch Out for Race Condition Attacks When Using Android External Storage
abstract
Currently, in Android, applications (apps for short) rely heavily on external storage to provide their services. Race conditions are introduced by the inappropriate file operations. Through race conditions, the malicious app can manipulate the file content and induce the victim app to perform unexpected actions, which we callrace condition attack. Race condition attack can cause a series of security problems and prior work has already implemented some of them. From Android 10, Google has introduced scoped storage to defend against attacks based on external storage. However, considering current market shares of different Android versions, it is still a long way to have scoped storage deployed on each device. To protect current users from this kind of attack, it is essential to raise app developers' security awareness. Therefore, we conduct a comprehensive survey on race condition attack to learn about its current status over Android apps. We propose an analysis engine, named RECAST, which gathers file operation events on external storage and infers the associated file operation processes. With RECAST, we collect 5,359,339 file operation events over 105,963 files. From the analysis result, we find that, with the limited kinds of events, a tremendous number of unique file operating patterns (1,977) are constituted. Over these file operating patterns, the time window is much common and available to launch a series of attacks (94.26% of the tested files are vulnerable to this problem). Consequently, race condition attack has become a non-negligible issue for app developers when using Android external storage.
Shaoyong Du, Guoqing Lai, Xiangyang Luo 0001
CCS1
2022 Who Moves My App Promotion Investment? A Systematic Study About App Distribution Fraud
abstract
As the mobile era matures, it is increasingly competitive to market mobile apps, forcing companies to invest heavily on mobile user acquisition campaigns. This has unfortunately given birth to a new form of Internet fraud, which we refer to as “app distribution fraud”. This new fraud involves collusion between ISPs and fraudulent app distributors where app download is hijacked/redirected. In this article, we have the unique opportunity to cooperate with a major e-commerce company (with about 0.2 billion active users per month) to take a first peek at this problem. Through the nationwide measurement results, we find that app distribution fraud is ubiquitous yet stealthy — about 1.55 percent app downloads are hijacked/redirected, affecting more than 75 percent of the cities we tested and causing an estimated 7.46 billion U.S. dollars financial loss per year. We follow up with additional measurements on the technical mechanism of the fraud and the scope of the fraud (i.e., what other apps are also affected). Surprisingly, we find that sometimes the original app a user intends to download can be replaced with a completely different app, rendering the user's device at risks.
Shaoyong Du, Minrui Zhao, Jingyu Hua, Hang Zhang 0012, Zhiyun Qian, Sheng Zhong 0002
IEEE Trans. Dependable Secur. Comput.1
2021 An Empirical Analysis of Hazardous Uses of Android Shared Storage
abstract
Android shared storage is shared with all the applications (apps for short) and the user. It is common to see that a large amount of apps store different kinds of files on it. It is well known that apps granted the read or write permissions can freely access any files in the shared storage. As a consequence, the shared storage has been demonstrated to expose sensitive information and jeopardize users' privacy. In this paper, we systematically study a simple but overlooked threat related to the shared storage-the lack of input validation (e.g., integrity verifications) when consuming files on the shared storage. We argue that the untrusted input from the shared storage is a much ubiquitous problem. By undertaking an empirically study through a static analysis tool we develop, we find over 30 percent of the 13,746 analyzed popular apps on the market suffer from such problem. By investigating the types of files consumed, we find shockingly a large fraction of apps store and consume sensitive files, which allows us to construct end-to-end attacks. Considering the ubiquity of this class of vulnerabilities, we finally define better access control policies for external storage to eliminate them for most apps.
Shaoyong Du, Pengxiong Zhu, Jingyu Hua, Zhiyun Qian, Sheng Zhong 0002
IEEE Trans. Dependable Secur. Comput.1
2019 Securing peer-assisted indoor localization leveraging acoustic ranging
Shaoyong Du, Jingyu Hua, Sheng Zhong 0002
Comput. Secur.1
2016 Secure Keyboards Against Motion Based Keystroke Inference Attack
Shaoyong Du, Jingyu Hua, Sheng Zhong 0002
SecureComm1
2016 EV-Linker: Mapping eavesdropped Wi-Fi packets to individuals via electronic and visual signal matching
Shaoyong Du, Jingyu Hua, Sheng Zhong 0002
J. Comput. Syst. Sci.1
2015 Towards Attack-Resistant Peer-Assisted Indoor Localization
Jingyu Hua, Shaoyong Du, Sheng Zhong 0002
ESORICS (2)2