Xiaofeng Liu 0013

dblp:95/6332-13 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
9since 2021 · last 2026
0009-0007-6147-7119ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Formal Analysis Framework for E2EE Protocols
abstract
In today's digital communication landscape, the security of End-to-End Encryption (E2EE) protocols is paramount, particularly in safeguarding user privacy and data integrity. Formal verification has emerged as a critical methodology to ensure these protocols' effectiveness and reliability. However, certain scenarios reveal failures in guaranteeing E2EE communication security properties, leading to potential privacy breaches. We conducted a comprehensive survey of mainstream messaging protocols, systematically categorizing their vulnerabilities and causes. By focusing on identity authentication during user registration, key agreement protocols in session establishment, and data encapsulation processes in message transmission, we developed a formal verification framework for E2EE Messaging Protocols. This framework integrates dual perspectives: cryptographic protocol verification and implementation auditing.
Xiaofeng Liu 0013, Chengyu Hu 0001, Shanqing Guo
AsiaCCS2
2026 ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu 0002, Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu 0013, Qingchuan Zhao, Shanqing Guo
NDSS7
2026 SGAFuzzer: Stateful GraphQL API fuzzing
Jingge Sun, Xiangpu Song, Xiaofeng Liu 0013, Shanqing Guo, Chengyu Hu 0001
Softw. Qual. J.3
2025 A Thorough Security Analysis of BLE Proximity Tracking Protocols
Xiaofeng Liu 0013, Chaoshun Zuo, Qinsheng Hou, Jianliang Wu 0002, Qingchuan Zhao, Shanqing Guo
USENIX Security Symposium1
2024 Security Research for Android Remote Assistance Apps
Xiaofeng Liu 0013, Wenna Song, Shanqing Guo
ACISP (3)2
2024 DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps
abstract
Mobile apps have become popular for providing artificial intelligence (AI) services via on-device machine learning (ML) techniques. Unlike accomplishing these AI services on remote servers traditionally, these on-device techniques process sensitive information required by AI services locally, which can mitigate the severe concerns of the sensitive data collection on the remote side. However, these on-device techniques have to push the core of ML expertise (e.g., models) to smartphones locally, which are still subject to similar vulnerabilities on the remote clouds and servers, especially when facing the model stealing attack. To defend against these attacks, developers have taken various protective measures. Unfortunately, we have found that these protections are still insufficient, and on-device ML models in mobile apps could be extracted and reused without limitation. To better demonstrate its inadequate protection and the feasibility of this attack, this paper presents DeMistify, which statically locates ML models within an app, slices relevant execution components, and finally generates scripts automatically to instrument mobile apps to successfully steal and reuse target ML models freely. To evaluate DeMistify and demonstrate its applicability, we apply it on 1,511 top mobile apps using on-device ML expertise for several ML services based on their install numbers from Google Play and DeMistify can successfully execute 1250 of them (82.73%). In addition, an in-depth study is conducted to understand the on-device ML ecosystem in the mobile application.
Chaoshun Zuo, Xiaofeng Liu 0013, Wenrui Diao, Qingchuan Zhao, Shanqing Guo
ICSE3
2023 ATTAA: Active Text Traffic Analysis Attacks on Secure Messaging Applications
abstract
Popular Secure Instant Messaging (SIM) applications like Telegram and WhatsApp have deployed state-of-the-art encryption schemes in recent years to protect the security of user communications. However, SIM applications are still not completely secure. Governments can surveil and censor users who participate in groups on sensitive topics based on the leaked information of their SIM clients. In this paper, we find two types of padding flaws in SIM applications where the padding length is not long enough, thereby exposing users' encrypted traffic characteristics. Furthermore, we first present an Active Text Traffic Analysis Attack (ATTAA) that enables the adversary to obtain sensitive information about target users' clients by merely monitoring their encrypted SIM traffic. Specifically, the adversary can quickly identify the participants of target SIM groups with high accuracy. Our study demonstrates a significant, real-world threat to SIM users due to increasing government regulation on social media. We demonstrate the practicality of our ATTAA through extensive experiments on real-world SIM communications. Although SIM applications have various restrictions on message sending, our results show that only ten text messages in 10 seconds are enough to successfully attack Telegram and WhatsApp with an accuracy of 99.94% and 98.66%, and a false positive rate of$4.3\times 10^{-3}$and$1.5\times 10^{-4}$.
Fengyan Lv, Xiaofeng Liu 0013, Chengyu Hu 0001, Shanqing Guo
ICC3
2023 Can We Trust the Phone Vendors? Comprehensive Security Measurements on the Android Firmware Ecosystem
abstract
Android is the most popular smartphone platform with over 85% market share. Its success is built on openness, and phone vendors can utilize the Android source code to make customized products with unique software/hardware features. On the other hand, the fragmentation and customization of Android also bring many security risks that have attracted the attention of researchers. Many efforts were put in to investigate the security of customized Android firmware. However, most of the previous works focus on designing efficient analysis tools or analyzing particular aspects of the firmware. There still lacks a panoramic view of Android firmware ecosystem security and the corresponding understandings based on large-scale firmware datasets. In this work, we made a large-scale comprehensive measurement of the Android firmware ecosystem security. Our study is based on 8,325 firmware images from 153 vendors and 813 Android-related CVEs, which is the largest Android firmware dataset ever used for security measurements. In particular, our study followed a series of research questions, covering vulnerabilities, patches, security updates, and pre-installed apps. To automate the analysis process, we designed a framework,AndScanner+, to complete firmware crawling, firmware parsing, patch analysis, and app analysis. Through massive data analysis and case explorations, several interesting findings are obtained. For example, the patch delay and missing issues are widespread in Android firmware images, say 31.4% and 5.6% of all images, respectively. The latest images of several phones still contain vulnerable pre-installed apps, and even the corresponding vulnerabilities have been publicly disclosed. In addition to data measurements, we also explore the causes behind these security threats through case studies and demonstrate that the discovered security threats can be converted into exploitable vulnerabilities. There are 46 new vulnerabilities found byAndScanner+, 36 of which have been assigned CVE/CNVD IDs. This study provides much new knowledge of the Android firmware ecosystem with a deep understanding of software engineering security practices.
Qinsheng Hou, Wenrui Diao, Chenglin Mao, Lingyun Ying, Xiaofeng Liu 0013, Yuanzhi Li, Shanqing Guo, Meining Nie, Hai-Xin Duan
IEEE Trans. Software Eng.7
2022 Large-scale Security Measurements on the Android Firmware Ecosystem
abstract
Android is the most popular smartphone platform with over 85% market share. Its success is built on openness, and phone vendors can utilize the Android source code to make products with unique software/hardware features. On the other hand, the fragmentation and customization of Android also bring many security risks that have attracted the attention of researchers. Many efforts were put in to investigate the security of customized Android firmware. However, most of the previous work focuses on designing efficient analysis tools or analyzing particular aspects of the firmware. There still lacks a panoramic view of Android firmware ecosystem security and the corresponding understandings based on large-scale firmware datasets. In this work, we made a large-scale comprehensive measurement of the Android firmware ecosystem security. Our study is based on 6,261 firmware images from 153 vendors and 602 Android-related CVEs, which is the largest Android firmware dataset ever used for security measurements. In particular, our study followed a series of research questions, covering vulnerabilities, patches, security updates, and pre-installed apps. To automate the analysis process, we designed a framework, AndScanner, to complete ROM crawling, ROM parsing, patch analysis, and app analysis. Through massive data analysis and case explorations, several interesting findings are obtained. For example, the patch delay and missing issues are widespread in Android images, say 24.2% and 6.1% of all images, respectively. The latest images of several phones still contain vulnerable pre-installed apps, and even the corresponding vulnerabilities have been publicly disclosed. In addition to data measurements, we also explore the causes behind these security threats through case studies and demonstrate that the discovered security threats can be converted into exploitable vulnerabilities via 38 newfound vulnerabilities by our framework, 32 of which have been assigned CVE/CNVD numbers. This study provides much new knowledge of the Android firmware ecosystem with deep understanding of software engineering security practices.
Qinsheng Hou, Wenrui Diao, Xiaofeng Liu 0013, Lingyun Ying, Shanqing Guo, Yuanzhi Li, Meining Nie, Hai-Xin Duan
ICSE4