EDBT 2026 Demo / reviewers in the wild / expert
Song Liao
dblp:271/4608
· DBLP profile ↗
13ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-5264-7573ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial Attacks on Differentially Private Factorization Machines in Recommendation SystemsabstractRecommendation systems based on Factorization Machines (FM) play a critical role in personalizing user experiences across domains such as e-commerce, social networks, and streaming services. These models rely on large volumes of user data, raising significant privacy concerns. Differential Privacy (DP) has emerged as a principled approach for mitigating these risks by injecting controlled noise into model computations and providing formal privacy guarantees. Felix Sarpong, Song Liao |
SACMAT | 2 |
| 2025 | SKILLPoV: Towards Accessible and Effective Privacy Notice for Amazon Alexa Skills
Song Liao, Mohammed Aldeen, Luyi Xing, Danfeng Yao, Long Cheng 0005 |
NDSS | 2 |
| 2025 | No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements
Song Liao, Mohammed Aldeen, Salish Kumar, Long Cheng 0005 |
USENIX Security Symposium | 2 |
| 2024 | Command Hijacking on Voice-Controlled IoT in Amazon Alexa PlatformabstractVoice Personal Assistants (VPA) are becoming popular entry points to control connected devices in an IoT environment, e.g., by invoking Amazon Alexa voice-apps (called skills) to turn on/off lights through voice commands. Amazon Alexa platform allows third-party developers to build skills and publish them to marketplaces, which greatly extends the functionalities of VPA. Despite the many convenient features, there are increasing security and safety concerns about VPA-controlled IoT systems. Previous research demonstrated the prevalence of potentially malicious or problematic skills in the marketplace. However, existing works mainly focus on non-IoT skills (e.g., skills under the Kids and Health categories). The security and safety risks of IoT skills are largely under-explored. Wenbo Ding 0003, Song Liao, Long Cheng 0005, Xianghang Mi, Ziming Zhao 0001, Hongxin Hu |
AsiaCCS | 2 |
| 2024 | A First Look at Security and Privacy Risks in the RapidAPI EcosystemabstractWith the emergence of the open API ecosystem, third-party developers can publish their APIs on the API marketplace, significantly facilitating the development of cutting-edge features and services. The RapidAPI platform is currently the largest API marketplace and it provides over 40,000 APIs, which have been used by more than 4 million developers. However, such open API also raises security and privacy concerns associated with APIs hosted on the platform. In this work, we perform the first large-scale analysis of 32,089 APIs on the RapidAPI platform. By searching in the GitHub code and Android apps, we find that 3,533 RapidAPI keys, which are important and used in API request authorization, have been leaked in the wild. These keys can be exploited to launch various attacks, such as Resource Exhaustion Running, Theft of Service, Data Manipulation, and User Data Breach attacks. We also explore risks in API metadata that can be abused by adversaries. Due to the lack of a strict certification system, adversaries can manipulate the API metadata to perform typosquatting attacks on API URLs, impersonate other developers or renowned companies, and publish spamming APIs on the platform. Lastly, we analyze the privacy non-compliance of APIs and applications, e.g., Android apps, that call these APIs with data collection. We find that 1,709 APIs collect sensitive data and 94% of them dont provide a complete privacy policy. For the Android apps that call these APIs, 50% of them in our study have privacy non-compliance issues. Song Liao, Long Cheng 0005, Xiapu Luo, Zheng Song 0001, Haipeng Cai, Danfeng Yao, Hongxin Hu |
CCS | 1 |
| 2024 | Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesabstractAmazon Alexa is one of the largest Voice Personal Assistant (VPA) platforms and it allows third-party developers to publish their voice apps, named skills, to the Alexa skill store. To satisfy the needs of European users, Amazon Alexa has established multiple skill marketplaces in Europe and allows developers to publish skills in their native languages. Skills in European marketplaces are required to comply with GDPR (General Data Protection Regulation), which imposes strict obligations on data collection and processing. Skills that involve data collection should provide a privacy policy to disclose the data practice to users and meet GDPR requirements. Song Liao, Mohammed Aldeen, Long Cheng 0005, Xiapu Luo, Haipeng Cai, Hongxin Hu |
WWW | 1 |
| 2023 | Understanding and Analyzing COVID-19-related Online Hate Propagation Through Hateful Memes Shared on TwitterabstractRecent studies regarding the COVID-19 pandemic have revealed the widespread propagation of hateful content during this period. While significant research has focused on COVID-19-related online hate in text (e.g., text-based tweets), the role of memes in propagating online hate during the pandemic has been largely overlooked. Memes are a popular mechanism used by Internet users to convey their thoughts and opinions on a variety of topics. However, memes have emerged as an important mechanism through which ideologically potent and hateful content spreads on social media platforms. In this work, we focus on investigating the role of memes in the propagation of online hate during the COVID-19 pandemic. We first collect a novel dataset of 4,001 COVID-19-related hateful memes and their replies over a 3-year period from Twitter. Then, we carry out the first large-scale investigation into the impact of these memes on Twitter users, by studying the psychological reactions of Twitter users to these memes using various text analysis methods. We find that COVID-19-related hateful memes have a significantly greater negative impact on Twitter users in comparison to text-based hateful tweets, and increasing negativity towards such memes over the 3-year period. Our new dataset of COVID-19-related hateful memes and findings from our work pave the way for studying the dissemination and moderation of COVID-19-related online hate through the medium of memes. Nishant Vishwamitra, Keyan Guo, Song Liao, Jaden Mu, Zheyuan Ma, Long Cheng 0005, Ziming Zhao 0001, Hongxin Hu |
ASONAM | 3 |
| 2023 | SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseabstractThe Amazon Alexa marketplace is the largest Voice Personal Assistant (VPA) platform with over 100,000 voice applications (i.e., skills) published to the skills store. In an effort to maintain the quality and trustworthiness of voice-apps, Amazon Alexa has implemented a set of policy requirements to be adhered to by third-party skill developers. However, recent works reveal the prevalence of policy-violating skills in the current skills store. To understand the causes of policy violations in skills, we first conduct a user study with 34 third-party skill developers focusing on whether they are aware of the various policy requirements defined by the Amazon Alexa platform. Our user study results show that there is a notable gap between VPA's policy requirements and skill developers' practices. As a result, it is inevitable that policy-violating skills will be published. Song Liao, Long Cheng 0005, Haipeng Cai, Linke Guo, Hongxin Hu |
CCS | 1 |
| 2023 | Analysis of COVID-19 Offensive Tweets and Their TargetsabstractDuring the global COVID-19 pandemic, people utilized social media platforms, especially Twitter, to spread and express opinions about the pandemic. Such discussions also drove the rise in COVID-related offensive speech. In this work, focusing on Twitter, we present a comprehensive analysis of COVID-related offensive tweets and their targets. We collected a COVID-19 dataset with over 747 million tweets for 30 months and fine-tuned a BERT classifier to detect offensive tweets. Our offensive tweets analysis shows that the ebb and flow of COVID-related offensive tweets potentially reflect events in the physical world. We then studied the targets of these offensive tweets. There was a large number of offensive tweets with abusive words, which could negatively affect the targeted groups or individuals. We also conducted a user network analysis, and found that offensive users interact more with other offensive users and that the pandemic had a lasting impact on some offensive users. Our study offers novel insights into the persistence and evolution of COVID-related offensive tweets during the pandemic Song Liao, Ebuka Okpala, Long Cheng 0005, Nishant Vishwamitra, Hongxin Hu, Feng Luo 0001, Matthew Costello |
KDD | 1 |
| 2022 | SkillDetective: Automated Policy-Violation Detection of Voice Assistant Applications in the Wild
Song Liao, Long Cheng 0005, Hongxin Hu, Huixing Deng |
USENIX Security Symposium | 2 |
| 2021 | COVID-HateBERT: a Pre-trained Language Model for COVID-19 related Hate Speech DetectionabstractWith the dramatic growth of hate speech on social media during the COVID-19 pandemic, there is an urgent need to detect various hate speech effectively. Existing methods only achieve high performance when the training and testing data come from the same data distribution. The models trained on the traditional hateful dataset cannot fit well on COVID-19 related dataset. Meanwhile, manually annotating the hate speech dataset for supervised learning is time-consuming. Here, we propose COVID-HateBERT, a pre-trained language model to detect hate speech on English Tweets to address this problem. We collect 200M English tweets based on COVID-19 related hateful keywords and hashtags. Then, we use a classifier to extract the 1.27M potential hateful tweets to re-train BERT-base. We evaluate our COVID-HateBERT on four benchmark datasets. The COVID-HateBERT achieves a 14.8%-23.8% higher macro average F1 score on traditional hate speech detection comparing to baseline methods and a 2.6%-6.73% higher macro average F1 score on COVID-19 related hate speech detection comparing to classifiers using BERT and BERTweet, which shows that COVID-HateBERT can generalize well on different datasets. Song Liao, Ebuka Okpala, Max Tong, Matthew Costello, Long Cheng 0005, Hongxin Hu, Feng Luo 0001 |
ICMLA | 2 |
| 2020 | Measuring the Effectiveness of Privacy Policies for Voice Assistant ApplicationsabstractVoice Assistants (VA) such as Amazon Alexa and Google Assistant are quickly and seamlessly integrating into people’s daily lives. The increased reliance on VA services raises privacy concerns such as the leakage of private conversations and sensitive information. Privacy policies play an important role in addressing users’ privacy concerns and informing them about the data collection, storage, and sharing practices. VA platforms (both Amazon Alexa and Google Assistant) allow third-party developers to build new voice-apps and publish them to app stores. Voice-app developers are required to provide privacy policies to disclose their apps’ data practices. However, little is known whether these privacy policies are informative and trustworthy or not on emerging VA platforms. On the other hand, many users invoke voice-apps through voice and thus there exists a usability challenge for users to access these privacy policies. Song Liao, Christin Wilson, Long Cheng 0005, Hongxin Hu, Huixing Deng |
ACSAC | 1 |
| 2020 | Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsabstractWith the emergence of the voice personal assistant (VPA) ecosystem, third-party developers are allowed to build new voice-apps are called skills in the Amazon Alexa platform and actions in the Google Assistant platform, respectively. For the sake of brevity, we use the term skills to describe voice-apps including Amazon skills and Google actions, unless we need to distinguish them for different VPA platforms. and publish them to the skills store, which greatly extends the functionalities of VPAs. Before a new skill becomes publicly available, that skill must pass a certification process, which verifies that it meets the necessary content and privacy policies. The trustworthiness of skill certification is of significant importance to platform providers, developers, and end users. Yet, little is known about how difficult it is for a policy-violating skill to get certified and published in VPA platforms. In this work, we study the trustworthiness of the skill certification in Amazon Alexa and Google Assistant platforms to answer three key questions: 1) Whether the skill certification process is trustworthy in terms of catching policy violations in third-party skills. 2) Whether there exist policy-violating skills published in their skills stores. 3) What are VPA users' perspectives on the skill certification and their vulnerable usage behavior when interacting with VPA devices? Over a span of 15 months, we crafted and submitted for certification 234 Amazon Alexa skills and 381 Google Assistant actions that intentionally violate content and privacy policies specified by VPA platforms. Surprisingly, we successfully got 234 (100%) policy-violating Alexa skills certified and 148 (39%) policy-violating Google actions certified. Our analysis demonstrates that policy-violating skills exist in the current skills stores, and thus users (children, in particular) are at risk when using VPA services. We conducted a user study with 203 participants to understand users' misplaced trust on VPA platforms. Unfortunately, user expectations are not being met by the skill certification in leading VPA platforms. Long Cheng 0005, Christin Wilson, Song Liao, Daniel Dong, Hongxin Hu |
CCS | 3 |