Pinji Chen

dblp:381/1608 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0000-2907-4677ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Identifying Logical Vulnerabilities in QUIC Implementations
Kaihua Wang, Jianjun Chen 0005, Pinji Chen, Jianwei Zhuge, Jiaju Bai, Hai-Xin Duan
NDSS3
2026 LLMThief: Evaluating Configuration Leaking Risks in Commercial LLM App Stores
Pinji Chen, Jinlong Jiang, Jianjun Chen 0005, Feiran Qin, Hai-Xin Duan, Kaiwen Shen
SP1
2025 The Danger of Packet Length Leakage: Off-path TCP/IP Hijacking Attacks Against Wireless and Mobile Networks
abstract
To combat eavesdropping and injection attacks, wireless networks widely adopt encryption to provide confidentiality and integrity guarantees. In this paper, we present a novel and generic attack, termed LenOracle, which can hijack the TCP/UDP connections over encrypted wireless networks (e.g., 5G/4G/3G and Wi-Fi) via packet injections from the Internet. Due to the design nature of wireless networks and stream ciphers they used, the length of IP packets being transmitted can be acquired by radio sniffing. It thus provides a side channel for adversaries. We found that adversaries could utilize this side channel with TCP features to infer the presence of a connection, infer the protocol state (sequence number, acknowledge number) of the connection, and finally hijack TCP/IP connections over wireless networks. Through real-world experiments in commercial LTE networks and real Wi-Fi networks, we demonstrated that the LenOracle attack is practical and severe against both TCP and UDP connections. For the former, we successfully injected a fake short message into a victim TCP connection; For the latter, we were able to inject a fake DNS response into a UDP connection and poisoned the DNS cache of the victim device. Following the responsible disclosure policy, we have reported our findings and mitigation recommendations to GSMA and Wi-Fi Alliance. The GSMA acknowledged that the issue affects 5G/4G/3G, notified all its members (operators and vendors worldwide) of this issue, and highlighted the mitigation we proposed.
Guancheng Li, Jianjun Chen 0005, Ge Dai, Pinji Chen, Huiming Liu, Hai-Xin Duan, Zhiyun Qian
EuroS&P5
2025 Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP Exchange
Pinji Chen, Jianjun Chen 0005, Mingming Zhang 0010, Qi Wang 0094, Yiming Zhang 0009, Hai-Xin Duan
NDSS1
2024 More Simplicity for Trainers, More Opportunity for Attackers: Black-Box Attacks on Speaker Recognition Systems by Inferring Feature Extractor
Yunjie Ge, Pinji Chen, Qian Wang 0002, Lingchen Zhao, Ningping Mou, Peipei Jiang 0002, Cong Wang 0001, Qi Li 0002, Chao Shen 0001
USENIX Security Symposium2