EDBT 2026 Demo / reviewers in the wild / expert
Menghan Sun
dblp:192/8009
· DBLP profile ↗
7ranked-venue papers
1as first author
3since 2021 · last 2022
0009-0001-7947-9522ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | LiCA: A Fine-grained and Path-sensitive Linux Capability Analysis FrameworkabstractThe capability mechanism in Linux-based systems is designed for dispersing the root privileges into a set of more refined capabilities, making programs gain no-more-necessary privileges. However, it is challenging to check the necessity and sufficiency of capabilities assigned to programs due to the highly complicated call chains invoked in practice. Inappropriate capability assignment brings threats to the systems. For example, over-privileged programs could allow an attacker to misuse root privileges, while under-privileged programs may incur runtime errors. Menghan Sun, Zirui Song, Xiaoxi Ren, Daoyuan Wu, Kehuan Zhang |
RAID | 1 |
| 2022 | Convex Optimization of Mutual Inductance Between Multiantiparallel Coils for Distance-Insensitive Wireless Charging of Air-Ground RobotsabstractThis article proposes convex optimization of mutual inductance between multiantiparallel coils (MACs) for distance-insensitive wireless charging of air–ground robots. In order to reduce optimization costs, the proposed optimization method is developed by hybridizing analytical and numerical models. First, it is shown that the commonly used analytical model for MAC design becomes inaccurate as frequency increases. Second, a trial mutual inductance is introduced as an optimization variable. From the trial mutual inductance, an MAC is designed using the analytical model. Third, the realized mutual inductance of the analytically designed MAC is computed by a numerical model to correct the error of the analytical model. The difference vector$\bar {\rho }$between the realized and optimal mutual inductances is written as a function of the trial mutual inductance, and the$l_{2}$-norm of$\bar {\rho }$is minimized by changing the trial mutual inductance. The resultant optimization problem is shown to be convex, and it is conveniently solved by using a local searching method. Simulation results show that the proposed design method satisfies design specification much better than the conventional analytical-model-based design method. Using the proposed method, an MAC prototype is designed and fabricated, and a wireless charging system for air–ground robots is constructed and tested. Measurement results show that the efficiency of the designed MAC is maintained at around 80% in the transfer distance range of 15–55 mm, and stable efficiency is obtained when charging real air–ground robots of different heights. Huapeng Zhao, Jun Hu 0019, Zhizhang (David) Chen, Jiafeng Zhou, Menghan Sun, Danyu Yang |
IEEE Internet Things J. | 6 |
| 2021 | Understanding the Brains and Brawn of Illicit Streaming App
Kong Huang, Ke Zhang 0039, Jiongyi Chen, Menghan Sun, Di Tang 0001, Kehuan Zhang |
ICDF2C | 4 |
| 2020 | Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT TrafficabstractThe IoT (Internet of Things) technology has been widely adopted in recent years and has profoundly changed the people's daily lives. However, in the meantime, such a fast-growing technology has also introduced new privacy issues, which need to be better understood and measured. In this work, we look into how private information can be leaked from network traffic generated in the smart home network. Although researchers have proposed techniques to infer IoT device types or user behaviors under clean experiment setup, the effectiveness of such approaches become questionable in the complex but realistic network environment, where common techniques like Network Address and Port Translation (NAPT) and Virtual Private Network (VPN) are enabled. To this aim, we propose a traffic analysis framework based on sequence-learning techniques like LSTM and leveraged the temporal relations between packets for the attack of device identification. We evaluated it under different environment settings (e.g., pure-IoT and noisy environment with multiple non-IoT devices). The results showed our framework was able to differentiate device types with a high accuracy. This result suggests IoT network communications pose prominent challenges to users' privacy, even when they are protected by encryption and morphed by the network gateway. As such, new privacy protection methods on IoT traffic need to be developed towards mitigating this new issue. Shuaike Dong, Zhou Li 0001, Di Tang 0001, Jiongyi Chen, Menghan Sun, Kehuan Zhang |
AsiaCCS | 5 |
| 2019 | Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and UsersabstractNowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control. Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang |
DSN | 6 |
| 2019 | Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online PromotionabstractRecent years have witnessed the rapid progress in deep learning (DP), which also brings their potential weaknesses to the spotlights of security and machine learning studies. With important discoveries made by adversarial learning research, surprisingly little attention, however, has been paid to the real-world adversarial techniques deployed by the cybercriminal to evade image-based detection. Unlike the adversarial examples that induce misclassification using nearly imperceivable perturbation, real-world adversarial images tend to be less optimal yet equally effective. As a first step to understand the threat, we report in the paper a study on adversarial promotional porn images (APPIs) that are extensively used in underground advertising. We show that the adversary today's strategically constructs the APPIs to evade explicit content detection while still preserving their sexual appeal, even though the distortions and noise introduced are clearly observable to humans. To understand such real-world adversarial images and the underground business behind them, we develop a novel DP-based methodology called Male`na, which focuses on the regions of an image where sexual content is least obfuscated and therefore visible to the target audience of a promotion. Using this technique, we have discovered over 4,000 APPIs from 4,042,690 images crawled from popular social media, and further brought to light the unique techniques they use to evade popular explicit content detectors (e.g., Google Cloud Vision API, Yahoo Open NSFW model), and the reason that these techniques work. Also studied are the ecosystem of such illicit promotions, including the obfuscated contacts advertised through those images, compromised accounts used to disseminate them, and large APPI campaigns involving thousands of images. Another interesting finding is the apparent attempt made by cybercriminals to steal others' images for their advertising. The study highlights the importance of the research on real-world adversarial learning and makes the first step towards mitigating the threats it poses. Kan Yuan, Di Tang 0001, Xiaojing Liao, XiaoFeng Wang 0001, Xuan Feng 0005, Yi Chen 0024, Menghan Sun, Kehuan Zhang |
IEEE Symposium on Security and Privacy | 7 |
| 2018 | IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang |
NDSS | 8 |