EDBT 2026 Demo / reviewers in the wild / expert
Jice Wang
dblp:217/2370
· DBLP profile ↗
11ranked-venue papers
2as first author
11since 2021 · last 2026
0009-0005-6243-8547ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 8 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw Detection
Lan Zhang 0008, Zhiyuan Fu, Jice Wang, Shangru Zhao, Qi Li 0002, Ruidong Li 0001, He Wang 0014, Yuqing Zhang 0001 |
NDSS | 6 |
| 2025 | Review of Defect Detection Techniques for Power Information SystemsabstractAs a critical component of industrial infrastructure, the security of power information systems is directly related to the stable operation of power dispatch and supply. However, due to insufficient security considerations during the design phase and the diversity of customized implementations, power information systems widely suffer from defect at the software, firmware, and communication protocol levels, facing a variety of complex attack threats. This paper systematically reviews the development and research progress of existing defect detection techniques, based on the typical layered architecture of power information systems. First, focusing on customized industrial control software, it summarizes various detection methods, including classical program analysis, machine learning, and large language models (LLMs). Second, for embedded firmware security, it provides an in-depth comparison of static and dynamic analysis techniques, with a focus on key technologies such as taint analysis, firmware emulation, and fuzzing. Finally, for industrial communication protocols, it comprehensively analyzes the application scenarios and limitations of detection methods such as formal verification, symbolic execution, and protocol fuzzing. Building upon this, the paper further explores future research directions, including the deep application of LLMs, AI-driven firmware and protocol defect detection, efficient detection for complex industrial control protocols, and enhanced firmware emulation. Xingwang Dou, Shanquan Yang, Ziqing Lin, Baiji Hu, Jice Wang, Fannv He, Anmin Fu, Yuqing Zhang 0001 |
TrustCom | 6 |
| 2025 | FDLLM: A Dedicated Detector for Black-Box LLMs FingerprintingabstractThe proliferation of black-box Large Language Models (LLMs) makes source attribution essential for accountability and security. Yet, progress is limited by the lack of a large multilingual benchmark and by fragile or computationally intensive methods. We introduce FD-Dataset, a bilingual benchmark of 90,000 samples from 20 major LLMs, and FDLLM, a LoRA-adapted detector that extracts persistent decoding fingerprints from a foundation model. LoRA induces intra-model clustering and inter-model separation in representation space, explaining its effectiveness for fingerprinting. On FD-Dataset, FDLLM surpasses the strongest baseline by 22.1% Macro F1, generalizes to newly released models with 95% accuracy, and remains robust to polishing, translation, and synonym substitution, reducing average attack success rate from 49.2% (LM-D) to 23.9%. Zhiyuan Fu, Lan Zhang 0008, Ruidong Li 0001, Peng Liu 0005, Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 9 |
| 2025 | OSSDetector: Towards a More Accurate Approach for C/C++ Third-Party Library DetectionabstractIn today’s software development environment, third-party libraries (TPLs) enhance productivity but also introduce security risks. Effective Software Composition Analysis (SCA) is crucial for managing these risks. Yet, existing SCA tools for C/C++ projects struggle with challenges like detecting modified and nested TPLs, precise version representation, and comprehensive TPL databases. In modern software development, third-party libraries (TPLs) are commonly used to boost functionality and save development time. However, this convenience introduces security risks. We introduce OSSDetector, a new SCA tool that addresses these issues. OSSDetector uses sliding window and fuzzy hashing techniques to generate detailed signatures, improving detection of modified TPLs. It features a "Nested TPL Function Filtering" algorithm to accurately identify and filter nested TPL functions, and a "TPL Recognition" algorithm based on import ratios and function paths to determine the TPLs used in the software. It also addresses version representation by using function weights and release times. To overcome the lack of a comprehensive TPL database, we have developed a large database with 29,416 C/C++ TPLs and 767,405 versions. Experimental results demonstrate that OSSDetector surpasses state-of-the-art tools, achieving better precision (85.52%), recall (79.82%), and F1 score (82.57%), and higher precision (84.27%) at the library version level. Xiang Hai, Zhiyuan Fu, Yansong Shi, Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 7 |
| 2025 | Beyond Likes: Unraveling the Veil of Personal Data Exposure in Mobile Application GUIsabstractMobile applications (Apps) have become indispensable to our daily routines, infiltrating every facet of modern life. However, the widespread use of these apps also poses serious risks of privacy leakage for individuals. In this paper, we uncover a critical yet overlooked security issue: the ubiquitous exposure of private data within the graphical user interfaces (GUIs) of apps. Specifically, we revealed that many apps did not adopt the anonymity principle to protect users’ privacy data, and some apps even displayed more private data than users provided, underscoring a significant oversight in data privacy practices within the app ecosystem. We designed and implemented a novel semi-automated tool, PryDroid, for detecting private data exposed in Android app GUIs. This tool employs a depth-first search strategy to explore UI interfaces and minimizes redundant page exploration through sensory processing and template matching techniques. By measuring 234 real-world apps in Chinese app markets with the help of PryDroid, we found 95.7% of apps display private data in one or more UI pages. Our evaluation confirms widespread exposure of user data across the app ecosystem, underlining the urgent need for enhanced privacy protections and user awareness regarding digital privacy. Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 1 |
| 2024 | LibGuard: Protecting Sensitive Data In Android Third-Party Libraries From XLDH AttacksabstractMobile app vendors/developers extensively integrate third-party libraries into mobile applications. While they enrich the functions of apps, third-party libraries also bring in security risks. It has been widely studied that malicious third-party libraries could collect users’ sensitive data from the host apps and the app backend servers. Recent research has reported a new attack vector — malicious libraries strategically target other vendors’ library(SDKs) integrated in the same host app to harvest private user data.In this paper, we found two new dimensions of cross library data harvesting(XLDH) attack with serious privacy impacts that start from two new attack surfaces — accessing sensitive fields and accessing sensitive storage. However, the mitigation scheme, significantly, has not been yet studied. To prevent the leaks of sensitive data due to XLDH activities, we first proposed a mitigation scheme - LibGuard, which has been proven to be effective without affecting user’s experience on real-world apps. Fannv He, Jice Wang, Xiancui Peng, Yuqing Zhang 0001 |
ICCCN | 2 |
| 2024 | Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile Apps
Fannv He, Yan Jia 0009, Jice Wang, Mengyue Feng, Peng Liu 0005, Yuqing Zhang 0001 |
NDSS | 5 |
| 2024 | Uncovering Access Token Security Flaws in Multiuser Scenario of Smart Home PlatformsabstractAccess tokens have been thoroughly researched in website and mobile application security. However, we believe that the traditional application of access tokens must fulfill new security requirements in smart home environments due to the distinct features of multiuser sharing usage. Smart home platforms allow different types of users to share access to a single IoT device through mobile apps, with varying levels of permissions that are closely tied to access tokens. One security concern is that existing security standards or literature, as well as the development and implementation by vendors, may overlook these features, thereby introducing potential security risks to the application of access tokens. In this work, we propose a novel testing framework and conduct a systematic study to test the extent to which real-world smart home platform implementations neglect these new requirements. The testing results show that seven out of the 11 real-world smart home platforms are plagued by access token management flaws, which collectively violate four security properties. We have found that these security flaws can be exploited to enable unrestricted file upload, DoS attack, remote command execution, and illegal surveillance in real-world scenarios. Finally, we conducted responsible disclosure of these flaws and attacks and obtained seven China national vulnerability database vulnerability IDs and one CVE vulnerability ID. Additionally, we also provide suggestions for mitigating the vulnerabilities. Yiyu Yang, Jice Wang, Peng Liu 0005, Anmin Fu, Yuqing Zhang 0001 |
IEEE Internet Things J. | 2 |
| 2022 | Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat Systems
Mingming Zha 0001, Jice Wang, Yuhong Nan, XiaoFeng Wang 0001, Yuqing Zhang 0001, Zelin Yang |
NDSS | 2 |
| 2022 | Understanding and Conquering the Difficulties in Identifying Third-Party Libraries From Millions of Android AppsabstractWith the thriving of the Android ecosystem, codes are widely reused in Android apps in the form of third-party libraries. Recent research shows that emerging third-party libraries may introduce a lot of privacy risks and other security threats. Nevertheless, current approaches on libraries identification are far away from the demand for accuracy and efficiency. In this paper, we present LibHawkeye, a \jice{new} clustering-based technique to identify third-party libraries in millions of Android apps. Our approach utilizes four different kinds of dependencies inside Android apps to build intra-app dependency graphs but discards package homogeny which is heavily depended upon by most previous works. What's more, we propose three steps of refinement to eliminate false positives in the initial result as much as possible. The experiment on 1,000 apps reports that compared to existing tools, LibHawkeye can precisely identify at least 26.5\% more libraries. We also evaluate it with 3,987,206 Android apps published in Google Play, and the accuracy of sampled libraries from the clustering result is 93.25\%. Results show that LibHawkeye significantly outperforms the state-of-the-art tools without loss of scalability. Yanghua Zhang, Jice Wang, Yuqing Zhang 0001, Peng Liu 0005 |
IEEE Trans. Big Data | 2 |
| 2021 | Understanding Malicious Cross-library Data Harvesting on Android
Jice Wang, Yue Xiao 0007, Xueqiang Wang, Yuhong Nan, Luyi Xing, Xiaojing Liao, Jinwei Dong, XiaoFeng Wang 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 1 |