Lei Xue 0001

dblp:68/2052-1 · DBLP profile ↗
← Back
57ranked-venue papers
14as first author
39since 2021 · last 2026
0000-0001-5321-5740ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 6 first-author · 15 since 2021Software engineering, systems software and programming languages · 17 · 3 first-author · 14 since 2021Computer networks · 11 · 4 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
YearPublicationVenuePosition
2026 IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel Isolation
Yingjie Cao, Xiaogang Zhu 0001, Dean Sullivan, Lei Xue 0001, Chenxiong Qian, Minrui Yan, Xiapu Luo
NDSS5
2026 Automated robustness testing for LLM-based natural language processing software
Mingxuan Xiao, Yan Xiao 0002, Shunhui Ji, Hanbo Cai, Lei Xue 0001, Pengcheng Zhang 0001
Expert Syst. Appl.5
2026 DPDGPT: Using Multimodal Large Language Models for automated detection of dark patterns
Fengwei Lin, Liming Nie, Lei Xue 0001, Xiaoxi Zhang 0001, Kelei Zhang
Inf. Softw. Technol.3
2026 A class-imbalance-aware intrusion detection system based on spatiotemporal graph neural networks for software-defined vehicles
Sishan Wang, Youqun Zhao, Xin Fu 0009, Huachao Si, Lei Xue 0001
J. Inf. Secur. Appl.6
2026 Assessing the capability of android dynamic analysis tools to combat anti-runtime analysis techniques
Dewen Suo, Lei Xue 0001, Weihao Huang, Runze Tan, Guozi Sun
J. Syst. Softw.2
2026 Your Copied Data is Under Monitoring: A Study of Clipboard Usage in Android Applications
abstract
Clipboard usage is prevalent in mobile applications nowadays. However, insufficient access control on the clipboard in mobile operating systems exposes its contained data to high risks where one application can read the data, store it locally, or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile application ecosystem. Therefore, this paper proposes an automated tool, ClipboardScope+, that leverages the principled static program analysis to uncover the clipboard data usage in mobile applications at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an application. ClipboardScope+ is evaluated on over1.2 millionmobile applications available on Google Play, spanning the years 2022 and 2023. It uncovered an increase of 5.9% in behaviors of storing and transferring clipboard data over the one-year time, most of which occur automatically in background services. We also conducted a comprehensive case study to characterize different clipboard usages and reveal their privacy issues. Moreover, we uncovered a prevalent programming habit of using theSharedPreferencesobject to store historical data, which can become an unnoticeable privacy leakage channel.
Jiayimei Wang, Ruoqin Tang, Chaoshun Zuo, Lei Xue 0001, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.5
2026 Characterizing Network-Layer Vulnerabilities in LiDAR Subsystems of Autonomous Vehicles: A Mechanism-Aware Propagation Analysis
Rujun Hu, Angang Feng, Lei Xue 0001, Kelei Zhang, Wenmao Liu, Xiapu Luo
IEEE Trans. Inf. Forensics Secur.3
2026 PriLabel: Toward Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale
abstract
Privacy labels (e.g., Data Safety section on Google Play) aim to replace lengthy privacy policies with concise and standardized summaries of in-app privacy practices. However, studies reveal widespread inaccuracies in these self-reported labels, with developers omitting or misrepresenting privacy practices, undermining user trust and regulatory compliance. Existing methods for detecting such discrepancies lack coverage or scalability and fail to address the semantic ambiguity inherent in privacy label auditing. We present Iterative Context Reconstruction (ICR), an evidence-driven workflow that reconstructs context from decompiled code to resolve the ambiguity. Based on ICR, PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale is a context-aware static auditor that comprehensively uncoversomitted disclosuresin Android privacy labels, mapping transmitted data to Google’s label taxonomy in asource-freeandontology-freemanner. Our evaluation demonstrates PriLabel: Towards Comprehensively Uncovering Omitted Disclosures in Privacy Labels of Android Apps on a Large Scale’s high precision (91.5%) in detecting omitted disclosures in privacy labels. Applied to 4,851 top-installed Google Play apps, it revealed that 2,374 apps omitted at least one disclosure, with 210 transmitting sensitive financial data (e.g., credit card numbers) without proper labeling, exposing systemic risks of non-compliance.
Jinghang Wen, Ruoqin Tang, Xichen Yu, Guowen Xu, Lei Xue 0001, Qingchuan Zhao, Jian Weng 0001
IEEE Trans. Inf. Forensics Secur.6
2026 Code Language Models for Security Patch Management: How Far are We?
abstract
The rapid expansion of open-source software has also brought significant security challenges to cloud infrastructure, particularly introducing and propagating vulnerabilities. In response, effective security patch management establishes a continuous, structured pipeline by systematically identifying, testing, and deploying security patches to fix vulnerabilities. However, manually managing a large number of security patches (i.e., any update is approved and installed by hand) is time-consuming, leading to a great motivation for automating this process. Although Code Language Models (CodeLMs) have shown potential in various code-centric tasks, there remains an open question as to how well CodeLMs perform within the context of security patch management. To bridge this gap, we performed the first comprehensive empirical study on fine-tuning or prompting nine state-of-the-art CodeLMs for three security-patch-related downstream tasks, including silent patch identification (distinguishing security patches from normal commits), record-patch linking (connecting authoritative vulnerability records, e.g., CVE, to the corresponding fixing commits), and vulnerability description generation (providing a piece of text summarizing the vulnerability fixed by the patch), covering classification, ranking, and generation problems. Our findings reveal that there is no “one-size-fits-all” model that can always perform the best. Furthermore, due to the lack of task-specific knowledge, naively prompting LLMs with the basic strategies is not consistently reliable and may even underperform smaller PTMs. Additionally, existing automated evaluation metrics cannot fully reflect the capability of LLMs in considered tasks. These findings underscore the considerable gap between current capabilities and the practical requirements for deploying CodeLMs in automating security patch management.
Xingwei Lin, Sicong Cao, Le Yu 0002, Xiaobing Sun 0001, Fu Xiao 0001, Lei Xue 0001, Chunming Wu 0001, Kui Ren 0001, David Lo 0001
IEEE Trans. Serv. Comput.6
2025 Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning
abstract
The growing adoption of large pre-trained models in edge computing has made deploying model inference on mobile clients both practical and popular. These devices are inherently vulnerable to direct adversarial attacks, which pose a substantial threat to the robustness and security of deployed models. Federated adversarial training (FAT) has emerged as an effective solution to enhance model robustness while preserving client privacy. However, FAT frequently produces a generalized global model, which struggles to address the diverse and heterogeneous data distributions across clients, resulting in insufficiently personalized performance, while also encountering substantial communication challenges during the training process. In this paper, we propose Sylva, a personalized collaborative adversarial training framework designed to deliver customized defense models for each client through a two-phase process. In Phase 1, Sylva employs LoRA for local adversarial fine-tuning, enabling clients to personalize model robustness while drastically reducing communication costs by uploading only LoRA parameters during federated aggregation. In Phase 2, a game-based layer selection strategy is introduced to enhance accuracy on benign data, further refining the personalized model. This approach ensures that each client receives a tailored defense model that balances robustness and accuracy effectively. Extensive experiments on benchmark datasets demonstrate that Sylva can achieve up to 50× improvements in communication efficiency compared to state-of-the-art algorithms, while achieving up to 29.5% and 50.4% enhancements in adversarial robustness and benign accuracy, respectively.
Tianyu Qi, Lei Xue 0001, Yufeng Zhan, Xiaobo Ma 0001
CCS2
2025 SACK: Enabling Environmental Situation-Aware Access Control for Vehicles in Linux Kernel
abstract
Connected and autonomous vehicles (CAVs) operate in open and evolving environments, which require timely and adaptive permission restriction to address dynamic risks that arise from changes in environmental situations (hereinafter referred to as situations), such as emergency situations due to vehicle crashes. Enforcing situation-aware access control is an effective approach to support adaptive permission restriction. Current works mainly implement situation-aware access control in the permission framework and API monitoring in user space. They are vulnerable to being bypassed and are coarse-grained. Autonomous systems have widely adopted mandatory access control (MAC) to configure and enforce system-wide and fine-grained access control policies. However, the MA$C$supported by Linux security modules (LSM) relies on predefined security contexts (e.g., type) and relatively fixed permission transition conditions (e.g., exec syscall), which lacks consideration of environmental factors. To address these issues, we propose a Situation-aware Access Control framework in the Kernel (SACK), which enforces adaptive permission restriction based on environmental factors for CAVs. Incorporating environmental situations into the LSM framework is not straightforward. SACK introduces situation states as a new security context for abstracting environmental factors in the kernel. Subsequently, SACK utilizes a situation state machine to implement new adaptive permission transitions triggered by situation events. In addition, SACK provides a novel situation-aware policy language that links specific user space permissions to MAC rules while maintaining compatibility with other LSMs such as AppArmor. We develop two prototypes: an independent SACK with its own policies and a SACK-enhanced AppArmor that adaptively updates the corresponding policies of AppArmor. The experimental results demonstrate that SACK can efficiently enforce situation-adaptive permissions with negliaible runtime overhead.
Boyan Chen, Qingni Shen, Lei Xue 0001, Jiarui She, Xiapu Luo, Xin Zhang 0110, Wei Chen 0006, Zhonghai Wu
DATE3
2025 Accelerating personalized federated learning via dynamic gradient substitution and client selection
Ziwei Zhan, Xiaoxi Zhang 0001, Chee-Wei Tan 0001, Lei Xue 0001, Haisheng Tan, Xu Chen 0004
Comput. Networks5
2025 MalFocus: Locating Malicious Modules in Malware Based on Hybrid Deep Learning
abstract
In recent years, binary malware detection has attracted extensive attention from industry and academia. However, most of the existing work only focuses on judging whether a sample is malicious or not, rather than identifying malicious modules in malware. Few studies aiming at locating malicious code work on the function granularity and suffer from inaccuracy. In this paper, we address this problem by locating malicious code at the functional module (FM) granularity, which combines several functions to express the malicious behaviors of malware. We design a tool called MalFocus to automatically divide malware intoFMsand then identify the malicious functional module (MFM) in a multi-model hybrid manner, in which an unsupervised model and an interpretability approach based on a binary classifier are combined, eliminating the workload of labeling malware samples, determining the scope ofMFMsand ranking them according to their maliciousness. The identifiedMFMsare then passed to security analysts for verification, helping to significantly reduce the scope of manual analysis while providing a comprehensive view of the malware attack flow. Additionally, rules derived from the verifiedMFMscan be used to detect variants and new malware families with different functionalities, offering a more general and flexible detection approach. We evaluate MalFocus’s performance on 6764 real-world samples. The results show that MalFocus can correctly identify 95% ofMFMs, outperforming current state-of-the-art work.
Weihao Huang, Chaoyang Lin, Lu Xiang, Zhiyu Zhang 0017, Guozhu Meng, Lei Xue 0001, Kai Chen 0012, Zongming Zhang
IEEE Trans. Dependable Secur. Comput.6
2025 HeX: Encrypted Rich Queries With Forward and Backward Privacy Using Trusted Hardware
abstract
Dynamic searchable symmetric encryption (DSSE) schemes empower data owners to outsource their encrypted data to clouds while retaining the ability to update or search on it. Despite a lot of efforts devoted in recent years, there are still several challenges that have not been well addressed. First, the confidentiality of data might be compromised if forward privacy and backward privacy cannot be ensured. Second, only the traditional single keyword-file search has attracted tremendous attention, while other popular queries like Boolean queries and range queries are not fully investigated. Lastly, how to solve these problems on untrusted servers that may deviate from pre-defined protocols is also challenging. In this article, aiming to tackle the above problems, we propose a novel DSSE scheme named${\sf HeX}$based on Trusted Execution Environment (TEE) that supports rich queries on untrusted servers while guaranteeing forward and backward privacy. We achieve strong forward and backward security by designing a deferred obfuscating read-write technique atop the bitmap index. We further extend the basic scheme to realize Boolean queries and range queries by reducing them to basic keyword queries. Strict theoretical analysis is conducted to prove the security of${\sf HeX}$, and extensive evaluations illustrate its efficiency and practicality.
Haotian Wu 0001, Zhe Peng, Jiang Xiao 0001, Lei Xue 0001, Chenhao Lin, Sai Ho Chung
IEEE Trans. Dependable Secur. Comput.4
2025 Update If You Dare: Demystifying Bare-Metal Device Firmware Update Security of Appified IoT Systems
abstract
Due to the economy and low power consumption features, bare-metal IoT devices have been widely used in various areas of our life, and they are usually paired with companion mobile apps to configure them and view their states (a.k.a., appified IoT system). The IoT systems have already become the lucrative and profitable targets for attackers because the compromised IoT devices will pose severe threats to IoT security and reliability. This problem become worse on bare-metal IoT devices since the tradeoff among price, functionality, performance, and energy efficiency usually results in insufficient security protection. Such bare-metal IoT devices usually adopt OTA (Over-The-Air) methods to update firmware, which is managed by the companion apps running on smartphones. Despite the prevalence of these appified IoT systems, there is a lack of systematic research on the security of bare-metal IoT device firmware update (DFU), although recent studies have reported security flaws in such systems. In this article, we propose a holistic approach to investigate DFU security of these appified IoT systems through collaborative analyzing the bare-metal firmware and the companion app. Additionally, we have developed an IoT system analysis framework named$\mathsf{BareDFU}$to automate the complex and time-consuming analysis tasks and facilitate the investigation. After applying$\mathsf{BareDFU}$to analyze 1,637 companion IoT apps, we found 710 of them contained security flaws spanning all three DFU stages: authentication, firmware acquisition, and firmware verification. Furthermore, we leveraged$\mathsf{BareDFU}$to investigate the bare-metal DFU security of six commercial appified IoT systems, and discovered they all had DFU flaws, which we successfully exploited to launch proof-of-concept firmware modification attacks. The affected vendors have acknowledged our findings and addressed the security flaws.
Lei Xue 0001, Yuxiao Yan, Qiyi Tang 0003, Le Yu 0002, Xiapu Luo, Sen Nie, Shi Wu, Guofei Gu, Chenxu Wang 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Driving State-Aware Anomaly Detection for Autonomous Vehicles
abstract
With the increasing popularity of autonomous driving systems (ADS) in autonomous vehicles (AV), in recent years, there have been many attacks targeting AVs and ADSs. Meanwhile, recent studies have attempted to improve the safety and security of AVs from different perspectives, and they mainly focus on the spoofing attacks against the sensors and the injection attacks against the vehicle chassis and actuators. However, direct attacks on ADSs (i.e., communication hijacking and malicious codes) remain inadequately addressed, and even worse, such attacks can cause AVs to make unsafe driving decisions rapidly. In this paper, we introduceDSAD, a driving state-aware anomaly detection framework designed to enhance AV safety and security by identifying ADS attacks, such as communication hijacking and malicious codes, through chassis states. First,DSADmodels ADS operations (i.e., driving states) as a two-layer state machine, utilizing real-time chassis data to infer driving states and detect anomalies in ADS outputs. This reduces false positives and negatives by aligning detection with the diverse operational modes of AVs. To achieve this, we develop a prototype system,DSAD, incorporating a Detection Policy Update mechanism that dynamically adjusts detection policies based on the vehicle’s driving states, such as lane changing and obstacle avoidance. Second,DSADconsiders both collision avoidance and control stability, addressing potential conflicts through hard and soft requirements. Furthermore,DSADintegrates a fault handling module compatible with existing autonomous driving fault handling mechanisms, ensuring timely response to detected anomalies. We develop a prototype anomaly detection system calledDSADand deploy it on four ADSs. We evaluateDSADusing various attack scenarios, and the results show thatDSADcan identify over 90% of attacks on ADSs.
Lei Xue 0001, Xiapu Luo, Xiaobo Ma 0001, Guofei Gu
IEEE Trans. Inf. Forensics Secur.2
2025 Vehicular Intrusion Detection System for Controller Area Network: A Comprehensive Survey and Evaluation
abstract
The progress of automotive technologies has made cybersecurity a crucial focus, leading to various cyber attacks. These attacks primarily target the Controller Area Network (CAN) and specialized Electronic Control Units (ECUs). In order to mitigate these attacks and bolster the security of vehicular systems, numerous defense solutions have been proposed. These solutions aim to detect diverse forms of vehicular attacks. However, the practical implementation of these solutions still presents certain limitations and challenges. In light of these circumstances, this paper undertakes a thorough examination of existing vehicular attacks and defense strategies employed against the CAN and ECUs. The objective is to provide valuable insights and inform the future design of Vehicular Intrusion Detection Systems (VIDS). The findings of our investigation reveal that the examined VIDS primarily concentrate on particular categories of attacks, neglecting the broader spectrum of potential threats. Moreover, we provide a comprehensive overview of the significant challenges encountered in implementing a robust and feasible VIDS. Additionally, we put forth several defense recommendations based on our study findings, aiming to inform and guide the future design of VIDS in the context of vehicular security.
Lei Xue 0001, Sishan Wang, Xiapu Luo, Kaifa Zhao, Pengfei Jing, Xiaobo Ma 0001, Yajuan Tang, Haiying Zhou
IEEE Trans. Intell. Transp. Syst.2
2025 Autonomous Driving System Testing via Diversity-Oriented Driving Scenario Exploration
abstract
Testing Autonomous Driving Systems (ADS) is critical for validating their safety in operational environments. High-fidelity simulators enable the testing of ADS through virtual driving scenarios, especially those that are hazardous to replicate in real-world settings. However, existing testing approaches suffer from inadequate coverage of real-world traffic situations due to over-simplified modeling of vehicle movements (e.g., insufficient diversity in driving styles), resulting in undetected critical ADS failures. In this article, we propose a testing framework to discover diverse failures of ADS in driving scenarios that embody real-world traffic complexity. The framework leverages advanced traffic simulation methods to encode vehicle movements and generates realistic yet safety-critical driving scenarios for ADS by mutating vehicle movements. To efficiently explore driving scenarios that pose different challenges for ADS and expose diverse ADS failures, this framework further leverages a dynamic prioritization mechanism that prioritizes vehicle movements likely to trigger unique ADS behaviors. Specifically, we propose a method to estimate the possibility based on encoded vehicle movements. We implement this framework and evaluate it with three representative ADS from the famous CARLA Leaderboard. Empirical evaluation demonstrates that the proposed approach discovers more unique failures of ADS than existing testing frameworks.
Xinyu Ji, Lei Xue 0001, Zhijian He, Xiapu Luo
ACM Trans. Softw. Eng. Methodol.2
2025 ARAP: Demystifying Anti Runtime Analysis Code in Android Apps
abstract
With the continuous growth in the usage of Android apps, ensuring their security has become critically important. An increasing number of malicious apps adopt anti-analysis techniques to evade security measures. Although some research has started to consider anti-runtime analysis (ARA), it is unfortunate that they have not systematically examined ARA techniques. Furthermore, the rapid evolution of ARA technology exacerbates the issue, leading to increasingly inaccurate analysis results. To effectively analyze Android apps, understanding their adopted ARA techniques is necessary. However, no systematic investigation has been conducted thus far.In this paper, we conduct the first systematic study of the ARA implementations in a wide range of 117,270 Android apps (including both malicious and benign ones) collected between 2016 and 2023. Additionally, we propose a specific investigation tool namedARAPto assist this study by leveraging both static and dynamic analysis. According to the evaluation results,ARAPnot only effectively identifies the ARA implementations in Android apps but also reveals many important findings. For instance, almost all apps have implemented at least one category of ARA technology (99.6% for benign apps and 97.0% for malicious apps).
Dewen Suo, Lei Xue 0001, Le Yu 0002, Runze Tan, Weihao Huang, Guozi Sun
IEEE Trans. Software Eng.2
2024 How Good Are LLMs at Out-of-Distribution Detection?
abstract
Out-of-distribution (OOD) detection plays a vital role in enhancing the reliability of machine learning models. As large language models (LLMs) become more prevalent, the applicability of prior research on OOD detection that utilized smaller-scale Transformers such as BERT, RoBERTa, and GPT-2 may be challenged, due to the significant differences in the scale of these models, their pre-training objectives, and the paradigms used for inference. This paper initiates a pioneering empirical investigation into the OOD detection capabilities of LLMs, focusing on the LLaMA series ranging from 7B to 65B in size. We thoroughly evaluate commonly used OOD detectors, examining their performance in both zero-grad and fine-tuning scenarios. Notably, we alter previous discriminative in-distribution fine-tuning into generative fine-tuning, aligning the pre-training objective of LLMs with downstream tasks. Our findings unveil that a simple cosine distance OOD detector demonstrates superior efficacy, outperforming other OOD detectors. We provide an intriguing explanation for this phenomenon by highlighting the isotropic nature of the embedding spaces of LLMs, which distinctly contrasts with the anisotropic property observed in smaller BERT family models. The new insight enhances our understanding of how LLMs detect OOD data, thereby enhancing their adaptability and reliability in dynamic environments. We have released the source code at https://github.com/Awenbocc/LLM-OOD for other researchers to reproduce our results.
Bo Liu 0049, Li-Ming Zhan, Lei Xue 0001, Xiao-Ming Wu 0003
LREC/COLING5
2024 Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android Apps
abstract
Recently, clipboard usage has become prevalent in mobile apps allowing users to copy and paste text within the same app or across different apps. However, insufficient access control on the clipboard in the mobile operating systems exposes its contained data to high risks where one app can read the data copied in other apps and store it locally or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile app ecosystem. To establish the missing links, this paper proposes an automated tool, ClipboardScope, that leverages the principled static program analysis to uncover the clipboard data usage in mobile apps at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an app. ClipboardScope is evaluated on 26,201 out of a total of 2.2 million mobile apps available on Google Play as of June 2022 that access and process the clipboard text. It identifies 23,948, 848, 1,075, and 330 apps that are recognized as the four designated categories, respectively. In addition, we uncovered a prevalent programming habit of using the SharedPreferences object to store historical data, which can become an unnoticeable privacy leakage channel.
Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang, Lei Xue 0001, Xiapu Luo, Qingchuan Zhao
ICSE5
2024 Understanding Privacy Risks of Intelligent Connected Vehicles Through Their Companion Mobile Apps
abstract
The rapid advancement of intelligent connected vehicles (ICVs) in the automotive sector has significantly intensified security and privacy issues. Particularly, the previous studies have indicated that the ICV users (owners) are deeply concerned about the extensive data gathered by these vehicles. However, current research into vehicle security predominantly concentrates on the analysis and discussion of sensitive data from ICVs of specific brands or models. There is a notable lack of studies that conduct a comprehensive, large-scale investigation into the sensitive data collected by ICVs and assess the privacy implications of such data collection. In this article, we undertake an extensive investigation to comprehend the privacy risks associated with Internet-connected vehicles (ICVs) through their companion mobile apps. To accomplish this, we have devised a semi-automatic pipeline leveraging program analysis and large language model (LLM) to identify and track sensitive data across these apps. Specifically, we begin by constructing a detailed knowledge base of ICV sensitive data extracted from the privacy policies of companion apps. Subsequently, we conduct static analysis on the car companion apps, pinpointing instances of sensitive data usage within the app code and analysing their potential privacy risks. Our analysis, covering 401 car companion apps spanning 271 unique vehicle brands, unveils several noteworthy findings concerning the usage of user sensitive data in the ICV ecosystem. For instance, various entities within the ICV ecosystem collect a wide array of sensitive data, including brake status, passenger occupancy, and insurance details. Alarmingly, we discover that 37.91% of car companion apps fail to adequately disclose their data usage practices. Moreover, we observe extensive involvement of entities beyond vehicle manufacturers in the handling of vehicle sensitive data, including data analytics companies, charging service providers, and cloud service vendors.
Peifu Yang, Yuhong Nan, Lei Xue 0001, Juan Zhai, Zibin Zheng
IEEE Internet Things J.3
2024 On Smartly Scanning of the Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and real-world experiments demonstrate that our system can scan up to around 40 times as many IP-device mapping mutations as random/sequential scanning.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.6
2023 State-Aware Unsafe Driving Action Detection and Defense
abstract
Considering most driving accidents are caused by unsafe driving actions, this paper focuses on improving driving safety by proposing a novel state-aware unsafe driving action detection and defense method. By combining three indicators of the vehicle's physical models using fuzzy logic, our approach improves the prediction stability and warning time without sacrificing false alarm rates. This research enhances vehicle cybersecurity and contributes to safer and more secure transportation systems.
Rujun Hu, Lei Xue 0001, Xiapu Luo
ICDCS3
2023 XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice Injection
abstract
Multi-port chargers, capable of simultaneously charging multiple mobile devices such as smartphones, have gained immense popularity and sold millions of units in recent years. However, this charging-targeted feature can also pose security and privacy risks by allowing one of the simultaneously charging devices to communicate with another one if not properly designed and implemented as these devices are actually interconnected. Unfortunately, such risks have not been thoroughly investigated and we have identified a novel attack surface in the circuit design of multi-port chargers, which allows an adversary to exploit one port to (i) eavesdrop on the activities of other devices being charged and (ii) inaudibly inject malicious audio commands if the charging device supports voice assistants and USB-C interface.
Tao Ni 0003, Weitao Xu, Lei Xue 0001, Qingchuan Zhao
MobiCom4
2023 An Input-Agnostic Hierarchical Deep Learning Framework for Traffic Fingerprinting
Jian Qu, Xiaobo Ma 0001, Jianfeng Li 0006, Xiapu Luo, Lei Xue 0001, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan
USENIX Security Symposium5
2023 Extended Abstract of Graph4Web: A Relation-Aware Graph Attention Network for Web Service Classification
abstract
Software reuse, as a means to develop new software products with similar functions by virtue of existing software components, has become a popular way during the software development process. In particular, as the service-oriented architecture became popular, web services turned into an indispensable part in modem software development Web services provide a basic composition with high cohesion and loose coupling to support responses among heterogeneous software components, which is the valuable resources for software reuse. The popular web service repositories, such as Programmable Web, contain a mass of web services for beginners and developers to choose from. Nevertheless, the large number of web services also makes it difficult to select the suitable services. Thus, the key to reuse software components lies in how to find appropriate web services from repositories to meet developers requirements in specific application scenarios.
Kunsong Zhao, Jin Liu 0016, Zhou Xu 0003, Xiao Liu 0004, Lei Xue 0001, Zhiwen Xie, Xin Wang 0114
SANER5
2023 Ensemble Framework Combining Family Information for Android Malware Detection
abstract
Abstract Each malware application belongs to a specific malware family, and each family has unique characteristics. However, existing Android malware detection schemes do not pay attention to the use of malware family information. If the family information is exploited well, it could improve the accuracy of malware detection. In this paper, we propose a general Ensemble framework combining Family Information for Android Malware Detector, called EFIMDetector. First, eight categories of features are extracted from Android application packages. Then, we define the malware family with a large sample size as a prosperous family and construct a classifier for each prosperous family as a conspicuousness evaluator for the family characteristics. These conspicuousness evaluators are combined with a general classifier (which can be a base or ensemble classifier in itself), called the final classifier, to form a two-layer ensemble framework. For the samples of prosperous families with conspicuous family characteristics, the conspicuousness evaluators directly provide detection results. For other samples (including the samples of prosperous families with nonconspicuous family characteristics and the samples of nonprosperous families), the final classifier is responsible for detection. Seven common base classifiers and three common ensemble classifiers are used to detect malware in the experiment. The results show that the proposed ensemble framework can effectively improve the detection accuracy of these classifiers.
Yao Li 0017, Zhi Xiong 0001, Tao Zhang 0001, Qinkun Zhang, Ming Fan 0002, Lei Xue 0001
Comput. J.6
2023 The impact of class imbalance techniques on crashing fault residence prediction models
Kunsong Zhao, Zhou Xu 0003, Meng Yan 0001, Tao Zhang 0001, Lei Xue 0001, Ming Fan 0002, Jacky W. Keung
Empir. Softw. Eng.5
2022 Landing Reinforcement Learning onto Smart Scanning of The Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and find that our system would achieve growing advantages with the proliferation of IoT devices.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
INFOCOM6
2022 SAID: State-aware Defense Against Injection Attacks on In-vehicle Network
Lei Xue 0001, Kaifa Zhao, Jianfeng Li 0006, Le Yu 0002, Xiapu Luo, Yajin Zhou, Guofei Gu
USENIX Security Symposium1
2022 Towards Automatically Reverse Engineering Vehicle Diagnostic Protocols
Le Yu 0002, Pengfei Jing, Xiapu Luo, Lei Xue 0001, Kaifa Zhao, Yajin Zhou, Ting Wang 0006, Guofei Gu, Sen Nie, Shi Wu
USENIX Security Symposium5
2022 An unsupervised cross project model for crashing fault residence identification
abstract
Abstract It is a critical quality assurance activity to effectively detect the root cause of faults causing the software crashes (i.e. crashing faults). Previous studies extracted features to characterise crash instances and built models to identify whether the residences of crashing faults locate inside the stack traces. These models all belong to supervised learning methods which require labelled crash data to be involved. In this study, the introduction of an unsupervised model, called T ransfer S pectral C lustering ( TSC ), for the task of crashing fault residence identification under the unlabelled data scenario is proposed. Unlike traditional unsupervised methods which are applied to individual project data, TSC transfers the knowledge of auxiliary unlabelled data from the source project to assist the clustering task on the unlabelled data from the target project. TSC is an unsupervised transfer learning method, and simultaneously considers the data manifold information of the individual project and feature manifold information across projects to facilitate the clustering effect. Extensive experiments are conducted on a benchmark dataset containing seven software projects. Five indicators were chosen for performance evaluation. The results show that TSC achieves better performance than four clustering based unsupervised methods, and competitive performance compared with eight supervised cross‐project methods.
Xiao Liu 0004, Zhou Xu 0003, Dan Yang 0001, Meng Yan 0001, Weihan Zhang, Haohan Zhao, Lei Xue 0001, Ming Fan 0002
IET Softw.7
2022 A compositional model for effort-aware Just-In-Time defect prediction on android apps
abstract
Abstract Android apps have played important roles in daily life and work. To meet the new requirements from users, the apps encounter frequent updates, which involves a large quantity of code commits. Previous studies proposed to apply Just‐in‐Time (JIT) defect prediction for apps to timely identify whether the new code commits can introduce defects into apps, aiming to assure their quality. In general, high‐quality features are benefits for improving the classification performance. In addition, the number of defective commit instances is much fewer than that of clean ones, that is the defect data is class imbalanced. In this study, a novel compositional model, called KPIDL, is proposed to conduct the JIT defect prediction task for Android apps. More specifically, KPIDL first exploits a feature learning technique to preprocess original data for obtaining better feature representation, and then introduces a state‐of‐the‐art cost‐sensitive cross‐entropy loss function into the deep neural network to alleviate the class imbalance issue by considering the prior probability of the two types of classes. The experiments were conducted on a benchmark defect data consisting of 15 Android apps. The experimental results show that the proposed KPIDL model performs significantly better than 25 comparative methods in terms of two effort‐aware performance indicators in most cases.
Kunsong Zhao, Zhou Xu 0003, Meng Yan 0001, Lei Xue 0001, Wei Li 0121, Gemma Catolino
IET Softw.4
2022 Graph4Web: A relation-aware graph attention network for web service classification
Kunsong Zhao, Jin Liu 0016, Zhou Xu 0003, Xiao Liu 0004, Lei Xue 0001, Zhiwen Xie, Xin Wang 0114
J. Syst. Softw.5
2022 PackerGrind: An Adaptive Unpacking System for Android Apps
abstract
App developers are increasingly using packing services (or packers) to protect their code against being reverse engineered or modified. However, such packing techniques are also leveraged by the malicious developers to prevent the malware from being analyzed and detected by the static malware analysis and detection systems. Though there are already studies on unpacking packed Android apps, they usually leverage the manual reverse engineered packing behaviors to unpack apps packed by the specific packers and cannot be appified to the evolved and new packers. In this paper, we propose a novel unpacking approach with the capacity of adaptively unpacking the evolved and newly encountered packers. Also, we develop a new system, namedPackerGrind, based on this adaptive approach for unpacking Android packers. The evaluation with real packed apps demonstrates thatPackerGrindcan successfully reveal packers protection mechanisms, effectively handle their evolution and recover Dex files with low overhead.
Lei Xue 0001, Hao Zhou 0043, Xiapu Luo, Le Yu 0002, Dinghao Wu, Yajin Zhou, Xiaobo Ma 0001
IEEE Trans. Software Eng.1
2021 Parema: an unpacking framework for demystifying VM-based Android packers
abstract
Android packers have been widely adopted by developers to protect apps from being plagiarized. Meanwhile, various unpacking tools unpack the apps through direct memory dumping. To defend against these off-the-shelf unpacking tools, packers start to adopt virtual machine (VM) based protection techniques, which replace the original Dalvik bytecode (DCode) with customized bytecode (PCode) in memory. This defeats the unpackers using memory dumping mechanisms. However, little is known about whether such packers can provide enough protection to Android apps. In this paper, we aim to shed light on these questions and take the first step towards demystifying the protections provided to the apps by the VM-based packers. We proposed novel program analysis techniques to investigate existing commercial VM-based packers including a learning phase and a deobfuscation phase.We aim at deobfuscating the VM-protection DCode in three scenarios, recovering original DCode or its semantics with training apps, and restoring the semantics without training apps. We also develop a prototype named Parema to automate much work of the deobfuscation procedure. By applying it to the online VM-based Android packers, we reveal that all evaluated packers do not provide adequate protection and could be compromised.
Lei Xue 0001, Yuxiao Yan, Luyi Yan, Muhui Jiang, Xiapu Luo, Dinghao Wu, Yajin Zhou
ISSTA1
2021 Happer: Unpacking Android Apps via a Hardware-Assisted Approach
abstract
Malware authors are abusing packers (or runtime-based obfuscators) to protect malicious apps from being analyzed. Although many unpacking tools have been proposed, they can be easily impeded by the anti-analysis methods adopted by the packers, and they fail to effectively collect the hidden Dex data due to the evolving protection strategies of packers. Consequently, many packing behaviors are unknown to analysts and packed malware can circumvent the inspection. To fill the gap, in this paper, we propose a novel hardware-assisted approach that first monitors the packing behaviors and then selects the proper approach to unpack the packed apps. Moreover, we develop a prototype named Happerwith a domain-specific language named behavior description language (BDL) for the ease of extending Happerafter tackling several technical challenges. We conduct extensive experiments with 12 commercial Android packers and more than 24k Android apps to evaluate Happer. The results show that Happerobserved 27 packing behaviors, 17 of which have not been elaborated by previous studies. Based on the observed packing behaviors, Happeradopted proper approaches to collect all the hidden Dex data and assembled them to valid Dex files.
Lei Xue 0001, Hao Zhou 0043, Xiapu Luo, Yajin Zhou, Yang Shi 0002, Guofei Gu, Fengwei Zhang, Man Ho Au
SP1
2021 Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted Perturbations
Pengfei Jing, Qiyi Tang 0003, Yuefeng Du 0006, Lei Xue 0001, Xiapu Luo, Ting Wang 0006, Sen Nie, Shi Wu
USENIX Security Symposium4
2020 Demystifying Diehard Android Apps
abstract
Smartphone vendors are using multiple methods to kill processes of Android apps to reduce the battery consumption. This motivates developers to find ways to extend the liveness time of their apps, hence the name diehard apps in this paper. Although there are blogs and articles illustrating methods to achieve this purpose, there is no systematic research about them. What's more important, little is known about the prevalence of diehard apps in the wild.
Hao Zhou 0043, Haoyu Wang 0001, Yajin Zhou, Xiapu Luo, Yutian Tang, Lei Xue 0001, Ting Wang 0006
ASE6
2020 Programmable In-Network Security for Context-aware BYOD Policies
Qiao Kang, Lei Xue 0001, Adam Morrison 0003, Ang Chen 0001, Xiapu Luo
USENIX Security Symposium2
2020 Randomized Security Patrolling for Link Flooding Attack Detection
abstract
With the advancement of large-scale coordinated attacks, the adversary is shifting away from traditional distributed denial of service (DDoS) attacks against servers to sophisticated DDoS attacks against Internet infrastructures. Link flooding attacks (LFAs) are such powerful attacks against Internet links. Employing network measurement techniques, the defender could detect the link under attack. However, given the large number of Internet links, the defender can only monitor a subset of the links simultaneously, whereas any link might be attacked. Therefore, it remains challenging to practically deploy detection methods. This paper addresses this challenge from a game-theoretic perspective, and proposes a randomized approach (like security patrolling) to optimize LFA detection strategies. Specifically, we formulate the LFA detection problem as a Stackelberg security game, and design randomized detection strategies in consideration of the adversary's behavior, where best and quantal response models are leveraged to characterize the adversary's behavior. We employ a series of techniques to solve the nonlinear and nonconvex NP-hard optimization problems for finding the equilibrium. The experimental results demonstrate the necessity of handling LFAs from a game-theoretic perspective and the effectiveness of our solutions. We believe our study is a significant step forward in formally understanding LFA detection strategies.
Xiaobo Ma 0001, Bo An 0001, Mengchen Zhao, Xiapu Luo, Lei Xue 0001, Zhenhua Li 0001, Tony T. N. Miu, Xiaohong Guan
IEEE Trans. Dependable Secur. Comput.5
2019 Cross Project Defect Prediction via Balanced Distribution Adaptation Based Transfer Learning
Zhou Xu 0003, Shuai Pang, Tao Zhang 0001, Xiapu Luo, Jin Liu 0016, Yutian Tang, Xiao Yu 0008, Lei Xue 0001
J. Comput. Sci. Technol.8
2019 NDroid: Toward Tracking Information Flows Across Multiple Android Contexts
abstract
For performance and compatibility reasons, developers tend to use native code in their applications (or simply apps). This makes a bidirectional data flow through multiple contexts, i.e., the Java context and the native context, in Android apps. Unfortunately, this interaction brings serious challenges to existing dynamic analysis systems, which fail to capture the data flow across different contexts. In this paper, we first performed a large-scale study on apps using native code and reported some observations. Then, we identified several scenarios where data flow cannot be tracked by existing systems, leading to uncaught information leakage. Based on these insights, we designed and implemented NDroid, an efficient dynamic taint analysis system that could track the data flow between both Java context and native context. The evaluation of real apps demonstrated the effectiveness of NDroid in identifying information leakage with reasonable performance overhead.
Lei Xue 0001, Chenxiong Qian, Hao Zhou 0043, Xiapu Luo, Yajin Zhou, Yuru Shao, Alvin Chan Toong Shoon
IEEE Trans. Inf. Forensics Secur.1
2018 PERDICE: Towards Discovering Software Inefficiencies Leading to Cache Misses and Branch Mispredictions
abstract
CPU cache misses and branch mispredictions waste CPU cycles and affect program performance. Such software inefficiencies could be neither eliminated by existing compilers nor avoided by developers. In this paper, we propose a novel approach, named PERDICE, to automatically discover such performance bugs by leveraging concolic execution. PERDICE adopts a new path exploration algorithm to discover such software inefficiencies. In particular, we measure performance losses in the granularity of program locations (e.g., instructions, source code lines) instead of paths to avoid getting stuck into the code without software inefficiencies. Moreover, when scoring test inputs, our new approach prefers the test inputs incurring increments in performance losses. This strategy allows PERDICE to avoid getting stuck into the software inefficiencies that have been found. We have implemented PERDICE for both PC (X86 instructions) and Android smartphones (ARM instructions). The experimental results with real-world desktop software and Android native code show that PERDICE outperforms the other four popular algorithms and PROFs (a multi-path performance profiler) in terms of the speed to discover software inefficiencies and the severity (i.e, amount of wasted CPU cycles) of inefficiencies.
Ting Chen 0002, Wanyu Huang, Muhui Jiang, Xiapu Luo, Lei Xue 0001, Ying Wang 0038, Xiaosong Zhang 0001
COMPSAC (1)5
2018 Shoot at a Pigeon and Kill a Crow: On Strike Precision of Link Flooding Attacks
Xiaobo Ma 0001, Jianfeng Li 0006, Lei Xue 0001
NSS4
2018 LinkScope: Toward Detecting Target Link Flooding Attacks
abstract
A new class of target link flooding attacks (LFAs) can cut off the Internet connections of a target area without being detected, because they employ legitimate flows to congest selected links. Although new mechanisms for defending against LFA have been proposed, the deployment issues limit their usage, since they require either additional modules to enhance routers or using the software-defined network to replace the traditional routers. In this paper, we propose a novel framework that employs both the end-to-end and hop-by-hop network measurement techniques to capture the abnormal path performance degradation for detecting LFA and then locate the target links or areas whenever possible, and develop a prototype of the framework named LinkScope. Although using network measurement to capture network anomaly is not new, we tackle a number of challenging issues, such as conducting large-scale Internet path monitoring via non-cooperative measurement so that users do not need to install LinkScope on every host, profiling the performance of asymmetric Internet paths and detecting LFA. The extensive evaluation in a testbed and the Internet shows that with limited bandwidth and computational overhead, LinkScope can achieve timely detection and diagnosis of LFA with high detection rate and low false positive rate.
Lei Xue 0001, Xiaobo Ma 0001, Xiapu Luo, Edmond W. W. Chan, TungNgai Miu, Guofei Gu
IEEE Trans. Inf. Forensics Secur.1
2017 Adaptive unpacking of Android apps
abstract
More and more app developers use the packing services (or packers) to prevent attackers from reverse engineering and modifying the executable (or Dex files) of their apps. At the same time, malware authors also use the packers to hide the malicious component and evade the signature-based detection. Although there are a few recent studies on unpacking Android apps, it has been shown that the evolving packers can easily circumvent them because they are not adaptive to the changes of packers. In this paper, we propose a novel adaptive approach and develop a new system, named PackerGrind, to unpack Android apps. We also evaluate PackerGrind with real packed apps, and the results show that PackerGrind can successfully reveal the packers' protection mechanisms and recover the Dex files with low overhead, showing that our approach can effectively handle the evolution of packers.
Lei Xue 0001, Xiapu Luo, Le Yu 0002, Shuai Wang 0012, Dinghao Wu
ICSE1
2017 Is what you measure what you expect? Factors affecting smartphone-based mobile network measurement
abstract
Many apps have been developed to measure the performance of mobile networks. Unfortunately, their measurement results may not be what users expect, because the results could be biased by various factors and the apps' descriptions may confuse users. Although a few recent studies pointed out several factors, they missed other important factors and lacked of finegrained analysis on the factors and measurement apps. Moreover, none has studied whether or not the descriptions of such apps will mislead users. In this paper, we conduct the first systematic study of the factors that could bias the result from measurement apps and their descriptions. We identify new factors, revisit known factors, and propose a novel approach with new tools to discover these factors in proprietary apps. We also develop a new measurement app named MobiScope for demonstrating how to mitigate the negative effects of these factors. Furthermore, we construct enhanced descriptions for measurement apps to provide users more information about what is measured. The extensive experimental results illustrate the negative effects of various factors, the improvement in performance measurement brought by MobiScope, and the clarity of the enhanced descriptions.
Lei Xue 0001, Xiaobo Ma 0001, Xiapu Luo, Le Yu 0002, Shuai Wang 0012, Ting Chen 0002
INFOCOM1
2017 Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ART
Lei Xue 0001, Yajin Zhou, Ting Chen 0002, Xiapu Luo, Guofei Gu
USENIX Security Symposium1
2017 Toward Automatically Generating Privacy Policy for Android Apps
abstract
A privacy policy is a statement informing users how their information will be collected, used, and disclosed. Failing to provide a correct privacy policy may result in a fine. However, writing privacy policy is tedious and error-prone, because the author may not understand the source code well as it could have been written by others (e.g., outsourcing), or the author does not know the internal working of third-party libraries used. In this paper, we propose and develop a novel system named AutoPPG to automatically construct correct and readable descriptions to facilitate the generation of privacy policy for Android applications (i.e., apps). Given an app, AutoPPG first conducts static code analysis to characterize its behaviors related to users' personal information, and then applies natural language processing techniques to generating correct and accessible sentences for describing these behaviors. The experimental results using real apps and crowdsourcing indicate that: 1) AutoPPG creates correct and easy-to-understand descriptions for privacy policies; 2) the privacy policies constructed by AutoPPG usually reveal more operations related to users' personal information than existing privacy policies; and 3) most developers, who reply us, would like to use AutoPPG to facilitate them.
Le Yu 0002, Tao Zhang 0001, Xiapu Luo, Lei Xue 0001, Henry Chang
IEEE Trans. Inf. Forensics Secur.4
2016 Characterizing mobile *-box applications
Xiapu Luo, Haocheng Zhou, Le Yu 0002, Lei Xue 0001, Yi Xie 0004
Comput. Networks4
2015 AndroidPerf: A cross-layer profiling system for Android applications
abstract
Profiling Android applications (or simply apps) is an important way to discover and locate various problems in apps, such as performance bottleneck, security loopholes, etc. Although many dynamic profiling systems for apps have been proposed, they are limited in dealing with the multiple-layer nature of Android and thus cannot reveal issues due to the underlying platform or poor interactions between different layers. Note that since apps usually run in Dalvik virtual machine (DVM) and each DVM is a process in Android's customized Linux kernel, a simple operation in DVM will lead to many function calls in different layers. In this paper, we propose AndroidPerf, a cross-layer profiling system, including the DVM layer, the system layer, and the kernel layer, for Android apps. It consists of one sub-system that performs cross-layer dynamic taint analysis to collect control flow and data flow information, and another subsystem that conducts instrumentation on all layers for collecting performance information. We have implemented AndroidPerf in 9,125 lines of C/C++ and 1,016 lines of Python scripts along with some modifications to Android's framework. Besides evaluating its functionality and overhead, we have applied AndroidPerf to reveal real performance issues through case studies.
Lei Xue 0001, Chenxiong Qian, Xiapu Luo
IWQoS1
2014 On Measuring One-Way Path Metrics from a Web Server
abstract
Measuring one-way path metrics can facilitate adaptive online services (e.g., Video streaming and CDN) tuning to improve quality of experience (QoE) of their clients. However, existing server-side measurement systems suffer from (i) measuring only few one-way path metrics, (ii) limited client-side support, and (iii) heavy overheads. In this paper, we propose and implement OWPScope, a novel system that can be deployed to any web server to measure four important one-way path metrics-packet loss, packet reordering, jitter, and capacity-without requiring software or plug in installation at their web clients. Moreover, OWPScope performs representative measurement by correlating only information gleaned from standard features in HTML5 (e.g., Navigation timing, resource timing), HTTP, and TCP. Our extensive evaluations in both a test bed and the Internet show that OWPScope can effectively measure one-way path metrics with low overhead.
Xiapu Luo, Lei Xue 0001, Yuru Shao, Chenxiong Qian, Edmond W. W. Chan
ICNP2
2014 kTRxer: A portable toolkit for reliable internet probing
abstract
Being one of the primitives of Internet measurement and security scanning, active probing has numerous applications. While the majority of existing probing tools were designed for PCs/servers, the wide adoption of mobile devices and embedded systems bring new requirements and challenges to active probing, for example, the limited resources in those devices may affect active probing's accuracy and efficiency. However, few research studies examine such impact. In this paper, we fill the gap by investigating the effect of resource-limited devices on common packet sending/receiving techniques used by probing tools and proposing kTRxer, a toolkit that can be run in many devices to help probing tools achieve better accuracy and efficiency. kTRxer mitigates the negative effect from devices by keeping away from noise sources and achieves portability by avoiding modifying specific device drivers. We have implemented kTRxer with 5489 lines of C codes and conducted extensive evaluation on three platforms, including PC, broadband router, and smartphone. The experimental results show that kTRxer can achieve up to 10 times transmission rate and introduce much less delay noise than existing approaches.
Lei Xue 0001, Xiapu Luo, Yuru Shao
IWQoS1
2014 Towards Detecting Target Link Flooding Attack
Lei Xue 0001, Xiapu Luo, Edmond W. W. Chan, Xian Zhan
LISA1
2013 OMware: an open measurement ware for stable residential broadband measurement
abstract
A number of home-installed middleboxes, e.g., BISMark and SamKnows, and web-based tools, e.g., Netalyzr and Ookla's speedtest service, have been developed recently to enable residential broadband users to gauge their network service quality. One challenge to designing these systems is to provide stable network measurement. That is, the measurement results will not be fluctuated by sporadic overheads incurred inside the middlebox or web browser. In this poster, we propose a network measurement ware, OMware, to increase the stability of residential broadband measurement. The key feature is to implement the send and receive functions for measurement packets in the kernel. Our preliminary evaluation for an OpenWrt implementation shows that OMware provides very stable throughput and delay measurement, compared with typical socket-based measurement at the user level.
Lei Xue 0001, Ricky K. P. Mok, Rocky K. C. Chang
SIGCOMM1