EDBT 2026 Demo / reviewers in the wild / expert
Xiaohan Zhang 0001
dblp:96/6053-1
· DBLP profile ↗
17ranked-venue papers
4as first author
11since 2021 · last 2026
0000-0002-1118-7582ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 3D-ANC: Adaptive Neural Collapse for Robust 3D Point Cloud RecognitionabstractDeep neural networks have recently achieved notable progress in 3D point cloud recognition, yet their vulnerability to adversarial perturbations poses critical security challenges in practical deployments. Conventional defense mechanisms struggle to address the evolving landscape of multifaceted attack patterns. Through systematic analysis of existing defenses, we identify that their unsatisfactory performance primarily originates from an entangled feature space, where adversarial attacks can be performed easily. To this end, we present 3D-ANC, a novel approach that capitalizes on the Neural Collapse (NC) mechanism to orchestrate discriminative feature learning. In particular, NC depicts where last-layer features and classifier weights jointly evolve into a simplex equiangular tight frame (ETF) arrangement, establishing maximally separable class prototypes. However, leveraging this advantage in 3D recognition confronts two substantial challenges: (1) prevalent class imbalance in point cloud datasets, and (2) complex geometric similarities between object categories. To tackle these obstacles, our solution combines an ETF-aligned classification module with an adaptive training framework consisting of representation-balanced learning (RBL) and dynamic feature direction loss (FDL). 3D-ANC seamlessly empowers existing models to develop disentangled feature spaces despite the complexity in 3D data distribution. Comprehensive evaluations state that 3D-ANC significantly improves the robustness of models with various structures on two datasets. For instance, DGCNN's classification accuracy is elevated from 27.2% to 80.9% on ModelNet40 -- a 53.7% absolute gain that surpasses leading baselines by 34.0%. Yuanmin Huang 0001, Mi Zhang 0001, Xiaohan Zhang 0001, Xiaoyu You, Min Yang 0002 |
AAAI | 4 |
| 2026 | SEW: Strengthening Robustness of Black-box DNN Watermarking via Specificity Enhancement
Huming Qiu, Mi Zhang 0001, Junjie Sun, Peiyi Chen, Xiaohan Zhang 0001, Min Yang 0002 |
KDD (1) | 5 |
| 2026 | Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication
Xin Zhang 0146, Xiaohan Zhang 0001, Huijun Zhou |
NDSS | 2 |
| 2025 | The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps
Yizhe Shi, Zhemin Yang, Kangwei Zhong, Guangliang Yang 0001, Xiaohan Zhang 0001, Min Yang 0002 |
NDSS | 6 |
| 2025 | An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android Apps
Xin Zhang 0146, Xiaohan Zhang 0001, Zhichen Liu, Zhemin Yang, Min Yang 0002 |
NDSS | 2 |
| 2025 | The Future Unmarked: Watermark Removal in AI-Generated Images via Next-Frame PredictionabstractImage watermarking embeds imperceptible signals into AI-generated images for deepfake detection and provenance verification. Although recent semantic-level watermarking methods demonstrate strong resistance against conventional pixel-level removal attacks, their robustness against more advanced removal strategies remains underexplored, raising concerns about their reliability in practical scenarios. Existing removal attacks primarily operate in the pixel domain without altering image semantics, which limits their effectiveness against semantic-level watermarks.
In this paper, we propose Next Frame Prediction Attack (NFPA), the first semantic-level removal attack. Unlike pixel-level attacks, NFPA formulates watermark removal as a video generation task: it treats the watermarked image as the initial frame and aims to subtly manipulate the image semantics to generate the next-frame image, i.e., the unwatermarked image.
We conduct a comprehensive evaluation on eight state-of-the-art image watermarking schemes, demonstrating that NFPA consistently outperforms thirteen removal attack baselines in terms of the trade-off between watermark removal and image quality. Our results reveal the vulnerabilities of current image watermarking methods and highlight the urgent need for more robust watermarks. Huming Qiu, Zhaoxiang Wang, Mi Zhang 0001, Xiaohan Zhang 0001, Xiaoyu You, Min Yang 0002 |
NeurIPS | 4 |
| 2025 | Demystifying the (In)Security of QR Code-based Login in Real-world Deployments
Xin Zhang 0146, Xiaohan Zhang 0001, Yuhong Nan, Zhichen Liu, Jianzhou Chen, Huijun Zhou, Min Yang 0002 |
USENIX Security Symposium | 2 |
| 2023 | Understanding the (In)Security of Cross-side Face Verification Systems in Mobile Apps: A System PerspectiveabstractFace Verification Systems (FVSes) are more and more deployed by real-world mobile applications (apps) to verify a human’s claimed identity. One popular type of FVSes is called cross-side FVS (XFVS), which splits the FVS functionality into two sides: one at a mobile phone to take pictures or videos and the other at a trusted server for verification. Prior works have studied the security of XFVSes from the machine learning perspective, i.e., whether the learning models used by XFVSes are robust to adversarial attacks. However, the security of other parts of XFVSes, especially the design and implementation of the verification procedure used by XFVSes, is not well understood.In this paper, we conduct the first measurement study on the security of real-world XFVSes used by popular mobile apps from a system perspective. More specifically, we design and implement a semi-automated system, called XFVSChecker, to detect XFVSes in mobile apps and then inspect their compliance with four security properties. Our evaluation reveals that most of existing XFVS apps, including those with billions of downloads, are vulnerable to at least one of four types of attacks. These attacks require only easily available attack prerequisites, such as one photo of the victim, to pose significant security risks, including complete account takeover, identity fraud and financial loss. Our findings result in 14 Chinese National Vulnerability Database (CNVD) IDs and one of them, particularly CNVD-2021-86899, is awarded the most valuable vulnerability in 2021 among all the reported vulnerabilities to CNVD. Xiaohan Zhang 0001, Haoqi Ye, Yinzhi Cao, Yuan Zhang 0009, Min Yang 0002 |
SP | 1 |
| 2023 | Slowing Down the Aging of Learning-Based Malware Detectors With API KnowledgeabstractLearning-based malware detectors are widely used in practice to safeguard real-world computers. One major challenge is known as model aging, where the effectiveness of these models drops drastically as malware variants keep evolving. To tackle model aging, most existing works choose to label new samples to retrain the aged models. However, such data-perspective methods often require excessive costs in labeling and retraining. In this article, we observe that during evolution, malware samples often preserve similar malicious semantics while switching to new implementations with semantically equivalent APIs. Such observation enables us to look into the problem from a different perspective: feature space. More specifically, if the models can capture the intrinsic semantics of malware variants from feature space, it will help slow down the aging of learning-based detectors. Based on this insight, we designAPIGraphto automatically extract API knowledge from API documentation and incorporate these knowledge into the training of malware detection models. We useAPIGraphto enhance 5 state-of-the-art malware detectors, covering both Android and Windows platforms and various learning algorithms. Experiments on large-scale, evolutionary datasets with nearly 340K samples show thatAPIGraphcan help slow down the aging of these models by 5.9% to 19.6%, as well as reduce labeling efforts from 33.07% to 96.30% on top of data-perspective methods. Xiaohan Zhang 0001, Mi Zhang 0001, Yuan Zhang 0009, Ming Zhong 0011, Xin Zhang 0146, Yinzhi Cao, Min Yang 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile AppsabstractRecent years have witnessed the interesting trend that modern mobile apps perform more and more likely as user-to-user platforms, where app users can be freely and conveniently connected. Upon these platforms, rich and diverse data is often delivered across users, which brings users great conveniences and plentiful services, but also introduces privacy security concerns. While prior work has primarily studied illegitimate personal data collection problems in mobile apps, few paid little attention to the security of this emerging user-to-user platform feature, thus providing a rather limited understanding of the privacy risks in this aspect. Shuai Li 0006, Zhemin Yang, Nan Hua, Peng Liu 0005, Xiaohan Zhang 0001, Guangliang Yang 0001, Min Yang 0002 |
CCS | 5 |
| 2022 | Identity Confusion in WebView-based Mobile App-in-app Ecosystems
Lei Zhang 0096, Zhibo Zhang 0006, Ancong Liu, Yinzhi Cao, Xiaohan Zhang 0001, Yuan Zhang 0009, Guangliang Yang 0001, Min Yang 0002 |
USENIX Security Symposium | 5 |
| 2020 | PDiff: Semantic-based Patch Presence Testing for Downstream KernelsabstractOpen-source kernels have been adopted by massive downstream vendors on billions of devices. However, these vendors often omit or delay the adoption of patches released in the mainstream version. Even worse, many vendors are not publicizing the patching progress or even disclosing misleading information. However, patching status is critical for groups (e.g., governments and enterprise users) that are keen to security threats. Such a practice motivates the need for reliable patch presence testing for downstream kernels. Currently, the best means of patch presence testing is to examine the existence of a patch in the target kernel by using the code signature match. However, such an approach cannot address the key challenges in practice. Specifically, downstream vendors widely customize the mainstream code and use non-standard building configurations, which often change the code around the patching sites such that the code signatures are ineffective. Zheyue Jiang, Yuan Zhang 0009, Jun Xu 0024, Zhenghe Wang, Xiaohan Zhang 0001, Xinyu Xing 0001, Min Yang 0002, Zhemin Yang |
CCS | 6 |
| 2020 | Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareabstractMachine learning (ML) classifiers have been widely deployed to detect Android malware, but at the same time the application of ML classifiers also faces an emerging problem. The performance of such classifiers degrades---or called ages---significantly over time given the malware evolution. Prior works have proposed to use retraining or active learning to reverse and improve aged models. However, the underlying classifier itself is still blind, unaware of malware evolution. Unsurprisingly, such evolution-insensitive retraining or active learning comes at a price, i.e., the labeling of tens of thousands of malware samples and the cost of significant human efforts. In this paper, we propose the first framework, called APIGraph, to enhance state-of-the-art malware classifiers with the similarity information among evolved Android malware in terms of semantically-equivalent or similar API usages, thus naturally slowing down classifier aging. Our evaluation shows that because of the slow-down of classifier aging, APIGraph saves significant amounts of human efforts required by active learning in labeling new malware samples. Xiaohan Zhang 0001, Yuan Zhang 0009, Ming Zhong 0011, Daizong Ding, Yinzhi Cao, Mi Zhang 0001, Min Yang 0002 |
CCS | 1 |
| 2020 | How Android developers handle evolution-induced API compatibility issues: a large-scale studyabstractAs Android platform evolves in a fast pace, API-related compatibility issues become a significant challenge for developers. To handle an incompatible API invocation, developers mainly have two choices: merely performing sufficient checks to avoid invoking incompatible APIs on platforms that do not support them, or gracefully providing replacement implementations on those incompatible platforms. As providing more consistent app behaviors, the latter one is more recommended and more challenging to adopt. However, it is still unknown how these issues are handled in the real world, do developers meet difficulties and what can we do to help them. Yuan Zhang 0009, Yingtian Zhou, Yang Wang 0167, Xiangyu Zhang 0001, Shuaishuai Cui, Geng Hong, Xiaohan Zhang 0001, Min Yang 0002, Zhemin Yang |
ICSE | 9 |
| 2020 | BScout: Direct Whole Patch Presence Test for Java Executables
Jiarun Dai, Yuan Zhang 0009, Zheyue Jiang, Yingtian Zhou, Xinyu Xing 0001, Xiaohan Zhang 0001, Min Yang 0002, Zhemin Yang |
USENIX Security Symposium | 7 |
| 2018 | An Empirical Study of Web Resource Manipulation in Real-world Mobile Applications
Xiaohan Zhang 0001, Yuan Zhang 0009, Qianqian Mo, Zhemin Yang, Min Yang 0002, XiaoFeng Wang 0001, Long Lu, Hai-Xin Duan |
USENIX Security Symposium | 1 |
| 2018 | Detecting third-party libraries in Android applications with high precision and recallabstractThird-party libraries are widely used in Android applications to ease development and enhance functionalities. However, the incorporated libraries also bring new security & privacy issues to the host application, and blur the accounting between application code and library code. Under this situation, a precise and reliable library detector is highly desirable. In fact, library code may be customized by developers during integration and dead library code may be eliminated by code obfuscators during application build process. However, existing research on library detection has not gracefully handled these problems, thus facing severe limitations in practice. In this paper, we propose LibPecker, an obfuscation-resilient, highly precise and reliable library detector for Android applications. LibPecker adopts signature matching to give a similarity score between a given library and an application. By fully utilizing the internal class dependencies inside a library, LibPecker generates a strict signature for each class. To tolerate library code customization and elimination as much as possible, LibPecker introduces adaptive class similarity threshold and weighted class similarity score when calculating library similarity. To quantitatively evaluate the precision and the recall of LibPecker, we perform the first such experiment (to the best of our knowledge) with a large number of libraries and applications. Results show that LibPecker significantly outperforms the state-of-the-art tools in both recall and precision (91% and 98.1% respectively). Yuan Zhang 0009, Jiarun Dai, Xiaohan Zhang 0001, Sirong Huang, Zhemin Yang, Min Yang 0002, Hao Chen 0003 |
SANER | 3 |