Huancheng Hu

dblp:296/7645 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 4 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Beyond the Device: A Security Analysis of Children's Smartwatches and Their Ecosystem
abstract
The omnipresence of expensive high-end smartwatches has sparked demand for cheaper alternatives targeted at children. Equipped with parental control apps, they are not only a desirable product for children to own, but create an incentive for parents to buy them as they can limit what children may do or track where they go. However, these low-cost children's smartwatches are often built atop a supply chain with little regulatory scrutiny. In this paper, we present the first comprehensive security analysis covering firmware, companion apps, backend APIs, and their supply chain. We reveal previously undocumented attack vectors including command injection, passive message decryption, and unauthorized device enrollment. We validate them with proof-of-concept attacks across multiple market dominant platforms.
Huancheng Hu, Christian Doerr
AsiaCCS1
2026 LotBoNC: Novel Botnet Traffic Classification under Long-tailed Distributions
abstract
Botnets are a persistent cyber threat, leveraging global infrastructures to launch large-scale attacks. Yet, most existing classification methods are evaluated under balanced and closed-set assumptions, which fail to capture real-world conditions. In practice, botnet traffic is both long-tailed and open-world: unknown variants continually emerge, and rare threats are buried under dominant traffic, often evading detection. To reflect real-world conditions, we define a deployment-oriented setting where unlabeled traffic follows a long-tailed distribution, with dominant known classes in the head and rare novel botnet variants in the tail. We propose LotBoNC, a unified framework for encrypted traffic classification under long-tailed open-world conditions. LotBoNC first performs self-supervised pre-training to learn transferable representations, then applies entropy-regularized optimal transport to assign pseudo-labels aligned with estimated class priors. An EM-style loop iteratively refines prototypes and priors, improving class separation between frequent and rare categories. We evaluate LotBoNC on three public encrypted traffic datasets with diverse long-tailed scenarios. LotBoNC consistently outperforms prior state-of-the-art methods and accurately classifies known botnets and discovers unseen botnet variants in diverse, umbalanced open-world scenarios.
Huancheng Hu, Ziyun Li 0002, Christian Doerr
AsiaCCS1
2025 Opening a Can of Worms: A Comprehensive View into the Android Debug Bridge Malware
abstract
The proliferation of affordable Android-based IoT devices has led to their widespread integration into residential environments. However, Android Debug Bridge (ADB), the official developer tool that provides root-level access, is often misconfigured on low-end Android devices, with the port left open by default. This exposure enables remote compromise and turns devices into tools for cryptomining and botnet attacks, fueling large-scale malware campaigns. Despite years of widespread exploitation, there has been no systematic and quantitative understanding of how ADB-based worms exploit, propagate, and persist at scale. We present the first comprehensive study of ADB-targeting worms, analyzing over seven years of real-world data encompassing 1.7 million infected IPs and more than 6 billion compromise attempts. Our analysis uncovers three distinct propagation phases and shows that infections are disproportionately concentrated among residential devices. Through device firmware analysis, we reveal that ADB access is factory-enabled on several market-leading low-end Android TV boxes. We further show that infection patterns are tightly coupled with human activity cycles. To further explore the infection behavior quantitatively, we introduce a Graph Neural Network (GNN)-based simulation framework which is built and validated from real-world data. The model reveals how synchronized user behavior accelerates propagation and shows that timely mitigation can significantly reduce infection scale.
Huancheng Hu, Christian Doerr
TrustCom1
2024 Dealing with Bad Apples: Organizational Awareness and Protection for Bit-flip and Typo-Squatting Attacks
abstract
The domain name system (DNS) maps human-readable service names to IP addresses used by the network. As it exerts control over where users are directed to, domain names have been targets of abuse ever since the Internet become a success. Over the past twenty years, adversaries have repeatedly invented new strategies to trick users and our findings reveal a continuous increase in the exploitation of domain names.
Huancheng Hu, Afshin Zivi, Christian Doerr
ARES1
2021 SIP Bruteforcing in the Wild - An Assessment of Adversaries, Techniques and Tools
abstract
Over the last two decades, Voice-over-IP (VoIP) and specifically SIP have become standard solutions to realize voice telephony in residential, commercial, and telecom environments. As by now, an abundance of SIP endpoints exist, it has become financially lucrative for cybercriminals to systematically search for VoIP installations, with for example the aim to abuse them for billing fraud or to hide their criminal activities behind a legitimate connection and phone number. By now, this has made SIP one of the most scanned UDP protocols on the Internet. In this paper, we take a look at the actors behind these attacks. Using a large network telescope, we collect over 822 million SIP brute-forcing attempts from 5,691 sources over 187 countries and analyze who is searching for and attacking VoIP endpoints. As each tool and campaign exhibits specific implementation differences, we can relate individual attempts into campaigns and can thereby provide a detailed view into different actors in the ecosystem, different techniques and tooling, and how these are developing over 5 years. We show that we can fingerprint different SIP scanning tools, show that actors hardly ever change their toolkit, and identify an increase in highly distributed and coordinated scanning.
Harm Griffioen, Huancheng Hu, Christian Doerr
Networking2