EDBT 2026 Demo / reviewers in the wild / expert
Fannv He
dblp:204/2257
· DBLP profile ↗
9ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0008-3338-3972ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Review of Defect Detection Techniques for Power Information SystemsabstractAs a critical component of industrial infrastructure, the security of power information systems is directly related to the stable operation of power dispatch and supply. However, due to insufficient security considerations during the design phase and the diversity of customized implementations, power information systems widely suffer from defect at the software, firmware, and communication protocol levels, facing a variety of complex attack threats. This paper systematically reviews the development and research progress of existing defect detection techniques, based on the typical layered architecture of power information systems. First, focusing on customized industrial control software, it summarizes various detection methods, including classical program analysis, machine learning, and large language models (LLMs). Second, for embedded firmware security, it provides an in-depth comparison of static and dynamic analysis techniques, with a focus on key technologies such as taint analysis, firmware emulation, and fuzzing. Finally, for industrial communication protocols, it comprehensively analyzes the application scenarios and limitations of detection methods such as formal verification, symbolic execution, and protocol fuzzing. Building upon this, the paper further explores future research directions, including the deep application of LLMs, AI-driven firmware and protocol defect detection, efficient detection for complex industrial control protocols, and enhanced firmware emulation. Xingwang Dou, Shanquan Yang, Ziqing Lin, Baiji Hu, Jice Wang, Fannv He, Anmin Fu, Yuqing Zhang 0001 |
TrustCom | 8 |
| 2025 | FDLLM: A Dedicated Detector for Black-Box LLMs FingerprintingabstractThe proliferation of black-box Large Language Models (LLMs) makes source attribution essential for accountability and security. Yet, progress is limited by the lack of a large multilingual benchmark and by fragile or computationally intensive methods. We introduce FD-Dataset, a bilingual benchmark of 90,000 samples from 20 major LLMs, and FDLLM, a LoRA-adapted detector that extracts persistent decoding fingerprints from a foundation model. LoRA induces intra-model clustering and inter-model separation in representation space, explaining its effectiveness for fingerprinting. On FD-Dataset, FDLLM surpasses the strongest baseline by 22.1% Macro F1, generalizes to newly released models with 95% accuracy, and remains robust to polishing, translation, and synonym substitution, reducing average attack success rate from 49.2% (LM-D) to 23.9%. Zhiyuan Fu, Lan Zhang 0008, Ruidong Li 0001, Peng Liu 0005, Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 10 |
| 2025 | OSSDetector: Towards a More Accurate Approach for C/C++ Third-Party Library DetectionabstractIn today’s software development environment, third-party libraries (TPLs) enhance productivity but also introduce security risks. Effective Software Composition Analysis (SCA) is crucial for managing these risks. Yet, existing SCA tools for C/C++ projects struggle with challenges like detecting modified and nested TPLs, precise version representation, and comprehensive TPL databases. In modern software development, third-party libraries (TPLs) are commonly used to boost functionality and save development time. However, this convenience introduces security risks. We introduce OSSDetector, a new SCA tool that addresses these issues. OSSDetector uses sliding window and fuzzy hashing techniques to generate detailed signatures, improving detection of modified TPLs. It features a "Nested TPL Function Filtering" algorithm to accurately identify and filter nested TPL functions, and a "TPL Recognition" algorithm based on import ratios and function paths to determine the TPLs used in the software. It also addresses version representation by using function weights and release times. To overcome the lack of a comprehensive TPL database, we have developed a large database with 29,416 C/C++ TPLs and 767,405 versions. Experimental results demonstrate that OSSDetector surpasses state-of-the-art tools, achieving better precision (85.52%), recall (79.82%), and F1 score (82.57%), and higher precision (84.27%) at the library version level. Xiang Hai, Zhiyuan Fu, Yansong Shi, Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 8 |
| 2025 | Beyond Likes: Unraveling the Veil of Personal Data Exposure in Mobile Application GUIsabstractMobile applications (Apps) have become indispensable to our daily routines, infiltrating every facet of modern life. However, the widespread use of these apps also poses serious risks of privacy leakage for individuals. In this paper, we uncover a critical yet overlooked security issue: the ubiquitous exposure of private data within the graphical user interfaces (GUIs) of apps. Specifically, we revealed that many apps did not adopt the anonymity principle to protect users’ privacy data, and some apps even displayed more private data than users provided, underscoring a significant oversight in data privacy practices within the app ecosystem. We designed and implemented a novel semi-automated tool, PryDroid, for detecting private data exposed in Android app GUIs. This tool employs a depth-first search strategy to explore UI interfaces and minimizes redundant page exploration through sensory processing and template matching techniques. By measuring 234 real-world apps in Chinese app markets with the help of PryDroid, we found 95.7% of apps display private data in one or more UI pages. Our evaluation confirms widespread exposure of user data across the app ecosystem, underlining the urgent need for enhanced privacy protections and user awareness regarding digital privacy. Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 2 |
| 2025 | Identifying Implementation Flaws of SMS OTP AuthenticationabstractCurrently, the Short Message Service (SMS) One-Time Passwords (OTP) authentication is widely adopted in mobile applications. However, due to improper implementation by developers, significant security flaws exist in the SMS OTP authentication mechanisms of some apps. To provide a comprehensive and accurate assessment, we propose a new approach. First, we locate the SMS OTP authentication page through UI exploration. Then, using hooking technology, we conduct simulated attacks to verify the security of the SMS OTP authentication in the app, focusing on its susceptibility to brute-force attacks. This approach is applicable to apps with app-side or UI-layer protection measures, uncovering hidden implementation flaws beneath these protections. Technically, we employ dynamic analysis based on the ART virtual machine instrumentation to obtain runtime information of the app and generate vulnerability verification scripts, overcoming the challenges posed by code-packing in program analysis. We implemented a semi-automatic tool namedAuthCheckerand tested it on 950 popular apps, identifying 87 apps with security flaws that potentially allow attackers to achieve unauthorized account access. Our findings highlight the security issues in SMS OTP authentication of apps, promoting improvements in vulnerability patching and preventive strategies by developers. Fannv He, Yiyu Yang, Yuqing Zhang 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | LibGuard: Protecting Sensitive Data In Android Third-Party Libraries From XLDH AttacksabstractMobile app vendors/developers extensively integrate third-party libraries into mobile applications. While they enrich the functions of apps, third-party libraries also bring in security risks. It has been widely studied that malicious third-party libraries could collect users’ sensitive data from the host apps and the app backend servers. Recent research has reported a new attack vector — malicious libraries strategically target other vendors’ library(SDKs) integrated in the same host app to harvest private user data.In this paper, we found two new dimensions of cross library data harvesting(XLDH) attack with serious privacy impacts that start from two new attack surfaces — accessing sensitive fields and accessing sensitive storage. However, the mitigation scheme, significantly, has not been yet studied. To prevent the leaks of sensitive data due to XLDH activities, we first proposed a mitigation scheme - LibGuard, which has been proven to be effective without affecting user’s experience on real-world apps. Fannv He, Jice Wang, Xiancui Peng, Yuqing Zhang 0001 |
ICCCN | 1 |
| 2024 | Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile Apps
Fannv He, Yan Jia 0009, Jice Wang, Mengyue Feng, Peng Liu 0005, Yuqing Zhang 0001 |
NDSS | 1 |
| 2017 | Mixed Wavelet-Based Neural Network Model for Cyber Security Situation Prediction Using MODWT and Hurst Exponent Analysis
Fannv He, Yuqing Zhang 0001, Donghang Liu, Caiyun Liu 0003, Chensi Wu |
NSS | 1 |
| 2017 | A Novel Approach to Network Security Situation Assessment Based on Attack Confidence
Donghang Liu, Lihua Dong, Shaoqing Lv, Fannv He, Chensi Wu, Yuqing Zhang 0001 |
NSS | 5 |