EDBT 2026 Demo / reviewers in the wild / expert
Zhixiu Guo
dblp:201/5394
· DBLP profile ↗
6ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-0107-3522ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Measuring and Explaining the Effects of Android App Transformations in Online Malware DetectionabstractIt is well known that antivirus engines are vulnerable to evasion techniques (e.g., obfuscation) that transform malware into its variants.However, it cannot be necessarily attributed to the effectiveness of these evasions, and the limits of engines may also make this unsatisfactory result.In this study, we propose a data-driven approach to measure the effect of app transformations to malware detection, and further explain why the detection result is produced by these engines.First, we develop an interaction model for antivirus engines, illustrating how they respond with different detection results in terms of varying inputs.Six app transformation techniques are implemented in order to generate a large number of Android apps with traceable changes.Then we undertake a onemonth tracking of app detection results from multiple antivirus engines, through which we obtain over 971K detection reports from VirusTotal for 179K apps in total.Last, we conduct a comprehensive analysis of antivirus engines based on these reports from the perspectives of signature-based, static analysis-based, and dynamic analysis-based detection techniques.The results, together with 7 highlighted findings, identify a number of sealed working mechanisms occurring inside antivirus engines and what are the indicators of compromise in apps during malware detection. Guozhu Meng, Zhixiu Guo, Xiaodong Zhang 0014, Haoyu Wang 0001, Kai Chen 0012, Yang Liu 0003 |
Internetware | 2 |
| 2025 | What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors
Chang Yue, Kai Chen 0012, Zhixiu Guo, Jun Dai 0001, Xiaoyan Sun 0003, Yi Yang 0100 |
NDSS | 3 |
| 2023 | SkillSim: voice apps similarity detectionabstractAbstract Virtual personal assistants (VPAs), such as Amazon Alexa and Google Assistant, are software agents designed to perform tasks or provide services to individuals in response to user commands. VPAs extend their functions through third-party voice apps, thereby attracting more users to use VPA-equipped products. Previous studies demonstrate vulnerabilities in the certification, installation, and usage of these third-party voice apps. However, these studies focus on individual apps. To the best of our knowledge, there is no prior research that explores the correlations among voice apps.Voice apps represent a new type of applications that interact with users mainly through a voice user interface instead of a graphical user interface, requiring a distinct approach to analysis. In this study, we present a novel voice app similarity analysis approach to analyze voice apps in the market from a new perspective. Our approach, called SkillSim, detects similarities among voice apps (i.e. skills) based on two dimensions: text similarity and structure similarity. SkillSim measures 30,000 voice apps in the Amazon skill market and reveals that more than 25.9% have at least one other skill with a text similarity greater than 70%. Our analysis identifies several factors that contribute to a high number of similar skills, including the assistant development platforms and their limited templates. Additionally, we observe interesting phenomena, such as developers or platforms creating multiple similar skills with different accounts for purposes such as advertising. Furthermore, we also find that some assistant development platforms develop multiple similar but non-compliant skills, such as requesting user privacy in a non-compliance way, which poses a security risk. Based on the similarity analysis results, we have a deeper understanding of voice apps in the mainstream market. Zhixiu Guo, Ruigang Liang, Guozhu Meng, Kai Chen 0012 |
Cybersecur. | 1 |
| 2022 | VITAS : Guided Model-based VUI Testing of VPA AppsabstractVirtual personal assistant (VPA) services, e.g. Amazon Alexa and Google Assistant, are becoming increasingly popular recently. Users interact with them through voice-based apps, e.g. Amazon Alexa skills and Google Assistant actions. Unlike the desktop and mobile apps which have visible and intuitive graphical user interface (GUI) to facilitate interaction, VPA apps convey information purely verbally through the voice user interface (VUI), which is known to be limited in its invisibility, single mode and high demand of user attention. This may lead to various problems on the usability and correctness of VPA apps. Suwan Li, Lei Bu, Guangdong Bai, Zhixiu Guo, Kai Chen 0012, Hanlin Wei |
ASE | 4 |
| 2020 | SkillExplorer: Understanding the Behavior of Skills in Large Scale
Zhixiu Guo, Zijin Lin, Kai Chen 0012 |
USENIX Security Symposium | 1 |
| 2017 | Characterizing Smartwatch Usage in the WildabstractSmartwatch has become one of the most popular wearable computers on the market. We conduct an IRB-approved measurement study involving 27 Android smartwatch users. Using a 106-day dataset collected from our participants, we perform in-depth characterization of three key aspects of smartwatch usage "in the wild": usage patterns, energy consumption, and network traffic. Based on our findings, we identify key aspects of the smartwatch ecosystem that can be further improved, propose recommendations, and point out future research directions. Tianyu Chen 0018, Feng Qian 0001, Zhixiu Guo, Felix Xiaozhu Lin, XiaoFeng Wang 0001, Kai Chen 0012 |
MobiSys | 4 |