EDBT 2026 Demo / reviewers in the wild / expert
Jinghang Wen
dblp:301/9758
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0001-5815-4633ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Demystifying LLM API Misuses: A Lifecycle-Based Empirical Study on Real-World Android AppsabstractLarge Language Model (LLM) services are increasingly utilized by Android apps to provide advanced reasoning and generation capabilities. However, the secure integration of these LLM APIs (LlmAPIs) in real-world mobile apps remains a challenge due to the misunderstood trust boundaries between client and server. This paper presents the first systematic empirical analysis of LlmAPI misuses in Android apps from the perspective of the LLM interaction lifecycle. First, we delineate the threat models and categorize three prevalent types of LlmAPI misuses—ranging from credential leakage to prompt injection risks—through a detailed lifecycle analysis. Then, we develop an automated static analysis framework to detect these misuses in the wild. Specifically, we analyze 206,867 real-world Android apps and identify 1,207 LLM-enabled apps, among which 66.28% (800) exhibit at least one type of misuse. Specifically, 41.01% leak sensitive API credentials, 24.28% expose proprietary system prompts to local inspection, and 39.11% fail to sanitize inputs, leaving apps susceptible to Prompt Injection attacks. The consequences of such misuses are significant, including financial quota theft, intellectual property loss, and remote exploitation via indirect injection. We hope this work raises awareness and emphasizes the importance of adopting secure architectures, such as the Backend Proxy pattern, for mobile AI integration. Jinghang Wen, Qingchuan Zhao |
CODASPY | 1 |
| 2026 | PriLabel: Toward Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large ScaleabstractPrivacy labels (e.g., Data Safety section on Google Play) aim to replace lengthy privacy policies with concise and standardized summaries of in-app privacy practices. However, studies reveal widespread inaccuracies in these self-reported labels, with developers omitting or misrepresenting privacy practices, undermining user trust and regulatory compliance. Existing methods for detecting such discrepancies lack coverage or scalability and fail to address the semantic ambiguity inherent in privacy label auditing. We present Iterative Context Reconstruction (ICR), an evidence-driven workflow that reconstructs context from decompiled code to resolve the ambiguity. Based on ICR, PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale is a context-aware static auditor that comprehensively uncoversomitted disclosuresin Android privacy labels, mapping transmitted data to Google’s label taxonomy in asource-freeandontology-freemanner. Our evaluation demonstrates PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale’s high precision (91.5%) in detecting omitted disclosures in privacy labels. Applied to 4,851 top-installed Google Play apps, it revealed that 2,374 apps omitted at least one disclosure, with 210 transmitting sensitive financial data (e.g., credit card numbers) without proper labeling, exposing systemic risks of non-compliance. Jinghang Wen, Ruoqin Tang, Xichen Yu, Guowen Xu, Lei Xue 0001, Qingchuan Zhao, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Non-interactive set intersection for privacy-preserving contact tracing
Axin Wu, Yuer Yang, Jinghang Wen, Yu Zhang 0201, Qiuxia Zhao |
J. Syst. Archit. | 3 |
| 2023 | Enabling Traceable and Verifiable Multi-User Forward Secure Searchable Encryption in Hybrid CloudabstractForward secure searchable encryption (FSSE) scheme allows one data user to search on encrypted databases while resisting the file injection attack. The data utilization can be further improved by extending the single-user scenario to the multi-user scenario. However, there are some issues needed to be considered when a data owner shares data with multiple data users. First, the public cloud server can not be completely trusted as it may be dishonest returning incorrect or incomplete results. Second, authorized users may trade their private keys for financial benefit. To our knowledge, state-of-the-art searchable encryption schemes only consider part of the following desirable features: the verifiability of results, the resistance to file injection attacks, the traceability and revocation of malicious users who abuse their private keys in the multi-user setting. Based on these motivations, we first propose enabling traceable and verifiable multi-user FSSE, which achieves the above functionalities. Besides, we carry out the security proof which demonstrates that our scheme can meet the requirements of security. We also assess the performance from theoretical analysis and experimental analysis, which shows that compared with other similar schemes, our scheme has richer functionalities with comparable efficiency. Axin Wu, Anjia Yang, Weiqi Luo 0002, Jinghang Wen |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Fuzzy Identity-Based Matchmaking Encryption and Its ApplicationabstractAteniese et al. introduced the primitive of matchmaking encryption (ME) at CRYPTO 2019 and left open several important questions, which include extending ME to fuzzy cases or giving an efficient ME in the identity-based setting without relying on random oracles. The main challenge is to achieve fuzzy bilateral access control while providing identity privacy of the sender and receiver, message confidentiality and authenticity without random oracles. In this work, we resolve the question by formalizing the first fuzzy identity-based ME (IB-ME) and presenting a concrete construction. Specifically, we propose the formal syntax definition of fuzzy IB-ME. In fuzzy IB-ME, the identities of senders and receivers are characterized by attribute sets. A ciphertext can be correctly decrypted if the overlaps between the attribute set of the sender or receiver and the attribute set specified by the other party are simultaneously greater than a threshold, which can be applied to many attractive applications such as fuzzy bilateral access control in online social dating. Then, we present concrete details of fuzzy IB-ME based on fuzzy identity-based encryption, which does not rely on other cryptographic tools such as two-input functional encryption and non-interactive zero-knowledge proof systems. In this process, fuzzy bilateral access control and identity privacy are achieved through the formalism of arranged ME and the splitting technique while message authenticity is provided through the authentication and binding of the encryption key. The identity privacy of the sender and receiver, confidentiality, and authenticity of messages are reduced to the decisional bilinear Diffie-Hellman, decision linear, and computational bilinear Diffie-Hellman assumptions in the selective model without random oracles. Finally, we implement the scheme and evaluate its performance through theoretical analyses and experiments to demonstrate its efficiency. Axin Wu, Weiqi Luo 0002, Jian Weng 0001, Anjia Yang, Jinghang Wen |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Efficient and Fully Secure Lattice-Based IBE with Equality Test
Jian Weng 0001, Anjia Yang, Xiaojian Liang, Zike Jiang, Jinghang Wen |
ICICS (2) | 7 |