EDBT 2026 Demo / reviewers in the wild / expert
Duc Cuong Nguyen 0001
dblp:45/1042-1
· DBLP profile ↗
4ranked-venue papers
3as first author
1since 2021 · last 2021
0000-0001-8128-2174ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Web and mobile security · 41% Privacy and data protection · 34% Systems and software security · 25% | |
| Software engineering, system software, and programming languages
1 paper |
Empirical software engineering · 67% Software maintenance and evolution · 33% |
Topics — the 5 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Privacy and data protection
mobile app privacy |
0.4 | 1 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 |
Systems and software security › secure software development
secure coding |
0.3 | 1 | 2017 | A Stitch in Time: Supporting Android Developers in WritingSecure Code · CCS 2017 |
Empirical software engineering › mining software repositories
app store mining |
0.1 | 1 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 |
Empirical software engineering
mining software repositories |
0.1 | 1 | 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy · IEEE Symposium on Security and Privacy 2019 |
Web and mobile security › mobile security
android application security |
0.1 | 1 | 2017 | A Stitch in Time: Supporting Android Developers in WritingSecure Code · CCS 2017 |
Methods — techniques the papers use, named apart from their topics
static code analysis · 0.8regression analysis · 0.8natural language processing · 0.8security linting · 0.3IDE plugin · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Measuring User Perception for Detecting Unexpected Access to Sensitive Resource in Mobile AppsabstractUnderstanding users' perception of app behaviors is an important step to detect data access that violates user expectations. While existing works have used various proxies to infer user expectations (e.g., by analyzing app descriptions), how real-world users perceive an app's data access when they interact with graphical user interfaces (UI) has not been fully explored. Trung Tin Nguyen, Duc Cuong Nguyen 0001, Michael Schilling 0001, Gang Wang 0011, Michael Backes 0001 |
AsiaCCS | 2 |
| 2020 | Up2Dep: Android Tool Support to Fix Insecure Code DependenciesabstractThird-party libraries, especially outdated versions, can introduce and multiply security & privacy related issues to Android applications. While prior work has shown the need for tool support for developers to avoid libraries with security problems, no such a solution has yet been brought forward to Android. It is unclear how such a solution would work and which challenges need to be solved in realizing it. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
ACSAC | 1 |
| 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & PrivacyabstractApplication markets streamline the end-users' task of finding and installing applications. They also form an immediate communication channel between app developers and their end-users in form of app reviews, which allow users to provide developers feedback on their apps. However, it is unclear to which extent users employ this channel to point out their security and privacy concerns about apps, about which aspects of apps users express concerns, and how developers react to such security- and privacy-related reviews. In this paper, we present the first study of the relationship between end-user reviews and security- & privacy-related changes in apps. Using natural language processing on 4.5M user reviews for the top 2,583 apps in Google Play, we identified 5,527 security and privacy relevant reviews (SPR). For each app version mentioned in the SPR, we use static code analysis to extract permission-protected features mentioned in the reviews. We successfully mapped SPRs to privacy-related changes in app updates in 60.77% of all cases. Using exploratory data analysis and regression analysis we are able to show that preceding SPR are a significant factor for predicting privacy-related app updates, indicating that user reviews in fact lead to privacy improvements of apps. Our results further show that apps that adopt runtime permissions receive a significantly higher number of SPR, showing that runtime permissions put privacy-jeopardizing actions better into users' minds. Further, we can attribute about half of all privacy-relevant app changes exclusively to third-party library code. This hints at larger problems for app developers to adhere to users' privacy expectations and markets' privacy regulations. Our results make a call for action to make app behavior more transparent to users in order to leverage their reviews in creating incentives for developers to adhere to security and privacy best practices, while our results call at the same time for better tools to support app developers in this endeavor. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | A Stitch in Time: Supporting Android Developers in WritingSecure CodeabstractDespite security advice in the official documentation and an extensive body of security research about vulnerabilities and exploits, many developers still fail to write secure Android applications. Frequently, Android developers fail to adhere to security best practices, leaving applications vulnerable to a multitude of attacks. We point out the advantage of a low-time-cost tool both to teach better secure coding and to improve app security. Using the FixDroid IDE plug-in, we show that professional and hobby app developers can work with and learn from an in-environment tool without it impacting their normal work; and by performing studies with both students and professional developers, we identify key UI requirements and demonstrate that code delivered with such a tool by developers previously inexperienced in security contains significantly less security problems. Perfecting and adding such tools to the Android development environment is an essential step in getting both security and privacy for the next generation of apps. Duc Cuong Nguyen 0001, Dominik Wermke, Yasemin Acar, Michael Backes 0001, Charles Weir, Sascha Fahl |
CCS | 1 |