EDBT 2026 Demo / reviewers in the wild / expert
Lei Zhang 0096
dblp:97/8704-96
· DBLP profile ↗
20ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-9298-2536ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 3 first-author · 13 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fine-Grained Detection of Java Cross-Library Vulnerability Propagation by Extracting Semantic Constraints From Security Patches
Fute Sun, Lei Zhang 0096, Zhiyu Wu, Tianyang Han, Min Yang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Exposing the Hidden Layer: Software Repositories in the Service of Seo ManipulationabstractDistinct from traditional malicious packages, this paper uncovers a novel attack vector named “blackhat Search Engine Optimization through REPositories (RepSEO)”. In this approach, attackers carefully craft packages to manipulate search engine results, exploiting the credibility of software repositories to promote illicit websites. Our research presents a systematic analysis of the underground ecosystem of RepSEO, identifying key players such as account providers, advertisers, and publishers. We developed an effective detection tool, applied to a ten-year large-scale dataset of npm, Docker Hub, and NuGet software repositories. This investigation led to the startling discovery of 3,801,682 abusive packages, highlighting the widespread nature of this attack. Our study also delves into the supply chain tactics of these attacks, revealing strategies like the use of self-hosted email services for account registration, redirection methods to obscure landing pages, and rapid deployment techniques by aggressive attackers. Additionally, we explore the profit motives behind these attacks, identifying two primary types of advertisers: survey-based advertisers and malware distribution advertisers. We reported npm, NuGet, and Docker Hub about the RepSEO packages and the related supply chain vulnerabilities of Google, and received their acknowledgments. Software repositories have started removing the abusive packages as of this paper's submission. We also opensource our code and data to facilitate future research. Mengying Wu, Geng Hong, Wuyuao Mai, Lei Zhang 0096, Yingyuan Pu, Huajun Chai, Lingyun Ying, Hai-Xin Duan, Min Yang 0002 |
ICSE | 5 |
| 2025 | DeepExploitor: LLM-Enhanced Automated Exploitation of DeepLink Attack in Hybrid AppsabstractModern mobile apps widely embed WebView to enable rich and dynamic content, making it an increasingly attractive target for attackers. It is well known that insufficient or improper input validation on WebView-loaded URLs can compromise the entire app or even the underlying system. Among these threats, one of the most critical attack vectors is the DeepLink Attack, which often requires only a single user click to exploit WebView vulnerabilities. Despite the deployment of defense such as URL allowlists, misconfigurations and inconsistent implementations continue to expose apps to exploitation.In this paper, we present DeepExploitor, the first automated exploit generation framework targeting vulnerabilities exploitable via DeepLink Attack. DeepExploitor addresses two key challenges: First, it statically models complex, app-specific routing encapsulation and customized input parsing logic by extracing constraint-related code and resolving them through large language models (LLMs), enabling scalable discovery of valid exploits. Second, it identifies and mutates trusted domains embedded in the app to bypass black-box defenses such as domain-based allowlists. We evaluated DeepExploitor on 433 of the most popular Android apps and uncovered 83 zero-day vulnerabilities, including 24 rated as high or critical severity. All findings were responsibly disclosed to affected vendors, with 35 acknowledged to date or assigned CVE/CNVD identifiers. Zhangyue Zhang, Lei Zhang 0096, Zhibo Zhang 0006, Yongheng Liu, Zhemin Yang, Yuan Zhang 0009, Min Yang 0002 |
ASE | 2 |
| 2025 | Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening Service
Zhibo Zhang 0006, Lei Zhang 0096, Zhangyue Zhang, Geng Hong, Yuan Zhang 0009, Min Yang 0002 |
NDSS | 2 |
| 2025 | Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version Identification
Mengying Wu, Geng Hong, Baichao An, Mingxuan Liu 0006, Lei Zhang 0096, Baojun Liu 0002, Hai-Xin Duan, Min Yang 0002 |
USENIX Security Symposium | 6 |
| 2025 | ChainFuzz: Exploiting Upstream Vulnerabilities in Open-Source Supply Chains
Lei Zhang 0096, Yuchuan Meng, Zhemin Yang, Yuan Zhang 0009, Min Yang 0002 |
USENIX Security Symposium | 2 |
| 2025 | Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object Manipulation
Xinyou Huang, Lei Zhang 0096, Yongheng Liu, Yinzhi Cao, Yuan Zhang 0009, Min Yang 0002 |
USENIX Security Symposium | 2 |
| 2025 | Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web Containers
Keke Lian, Lei Zhang 0096, Yinzhi Cao, Yongheng Liu, Fute Sun, Yuan Zhang 0009, Min Yang 0002 |
USENIX Security Symposium | 2 |
| 2025 | Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability Detection
Yuan Zhang 0009, Jiarun Dai, Xinyou Huang, Bocheng Xiang, Guangliang Yang 0001, Letian Yuan, Lei Zhang 0096, Min Yang 0002 |
USENIX Security Symposium | 8 |
| 2025 | XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent Fuzzing
Youkun Shi, Yuan Zhang 0009, Tianhao Bai, Jiarun Dai, Lei Zhang 0096, Xiapu Luo, Min Yang 0002 |
USENIX Security Symposium | 7 |
| 2024 | Efficient Detection of Java Deserialization Gadget Chains via Bottom-up Gadget Search and Dataflow-aided Payload ConstructionabstractJava Object Injection (JOI) is a severe type of vulnerability affecting Java deserialization, which allows adversaries to inject a well-crafted, serialized object, thus triggering a series of chained internal methods (called gadgets) and then achieving attack consequences such as Remote Code Execution (RCE). Prior works studied the problem of detecting and chaining gadgets for JOI vulnerability using static search for possible gadget chains and dynamic construction of payload via fuzzing. However, prior works face two following challenges: (i) path explosion in static gadget search and (ii) a lack of fine-grained object relations connected via object fields in dynamic payload construction.In this paper, we design and implement a novel Java deserialization gadget detection framework, called JDD. On one hand, JDD solves the static path explosion problem by a bottom-up approach, which first looks for gadget fragments and then chains gadget fragments from sinks to sources. The approach reduces maximum static search time from exponential to polynomial, i.e., from O(eMn) to O(M2n3+ enM), where n is the number of dynamic function calls in a gadget chain, M is the average number of dynamic function call candidates, and e is the number of entry points. On the other hand, JDD constructs a so-called Injection Object Construction Diagram (IOCD), which models the dataflow dependencies between injection objects’ fields to facilitate dynamic fuzzing. Our evaluation of JDD upon six real-world Java applications reveals 127 zero-day, exploitable gadget chains with six Common Vulnerabilities and Exposures (CVE) identifiers assigned. We also responsibly reported these vulnerabilities to application developers and obtained their acknowledgments and confirmations. Bofei Chen, Lei Zhang 0096, Xinyou Huang, Yinzhi Cao, Keke Lian, Yuan Zhang 0009, Min Yang 0002 |
SP | 2 |
| 2024 | RecurScan: Detecting Recurring Vulnerabilities in PHP Web ApplicationsabstractDetecting recurring vulnerabilities has become a popular means of static vulnerability detection in recent years because they do not require labor-intensive vulnerability modeling. Recently, a body of work, with HiddenCPG as a representative, has redefined the problem of statically identifying recurring vulnerabilities as the subgraph isomorphism problem. More specifically, these approaches represent known vulnerable code as graph-based structures (e.g., PDG or CPG), and then identify subgraphs within target applications that match the vulnerable graphs. However, since these methods are highly sensitive to changes in the code graph, they may miss a significant number of recurring vulnerabilities with slight code differences from known vulnerabilities. Youkun Shi, Yuan Zhang 0009, Tianhao Bai, Lei Zhang 0096, Min Yang 0002 |
WWW | 4 |
| 2024 | The Dark Forest: Understanding Security Risks of Cross-Party Delegated Resources in Mobile App-in-App EcosystemsabstractIn app-in-app ecosystems, mobile applications (i.e., host apps) often delegate their rich resources to hosted parties (i.e., sub-apps), which can be utilized to provide millions of effective services including shopping, banking, and government. These resources vary from system abilities (e.g., web socket and GPS location) to app and user data (e.g., storage and phone number). This leads to an important research question—carefully design and enforce security regulations on these cross-party delegated resources (CPDR). Real-world host apps, according to our study, adopt 11 common security regulations in protecting the integrity, confidentiality, and availability of CPDR. However, existing practice and compliance between host apps and sub-apps are vague and inconsistent, leading to violations of these security regulations. To the best of our knowledge, no prior works have studied these security regulations. In this paper, we perform the first systematic study of the security regulations and their security weaknesses in real-world app-in-app ecosystems. We propose three novel attack vectors including masquerade attack, data-driven attack, and channel hijacking. We find that violations of the common security regulations are widespread among all 9 studied app-in-app ecosystems. More importantly, such security weakness can lead to severe consequences such as manipulating sub-apps’ back-end servers and stealing sensitive user data. We responsibly report all of our findings to host app developers of affected app-in-app ecosystems and help them fix their vulnerabilities. Zhibo Zhang 0006, Lei Zhang 0096, Guangliang Yang 0001, Min Yang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | NestFuzz: Enhancing Fuzzing with Comprehensive Understanding of Input Processing LogicabstractFuzzing is one of the most popular and practical techniques for security analysis. In this work, we aim to address the critical problem of high-quality input generation with a novel input-aware fuzzing approach called NestFuzz. NestFuzz can universally and automatically model input format specifications and generate valid input. Zhemin Yang, Lei Zhang 0096, Guangliang Yang 0001, Wenzheng Hong, Yuan Zhang 0009, Min Yang 0002 |
CCS | 3 |
| 2022 | Exploit the Last Straw That Breaks Android SystemsabstractThe Android system services usually play a critical role in running multiple important tasks, and delivering seamless user experiences, e.g., conveniently storing user data. In this paper, we conduct the first systematic security study on the data storing process in Android system services, and consequently discover a novel class of design flaws (named Straw), which can lead to serious DoS (Denial-of-Service) attacks, e.g., permanently crashing the whole victim Android device.Then we propose a novel directed fuzzing based approach, called StrawFuzzer, to automatically vet all system services against the straw vulnerabilities. StrawFuzzer balances the tradeoff between path exploration and vulnerability exploitation. By applying StrawFuzzer on three Android systems with the latest security updates, we identified 35 unique straw vulnerabilities affecting 474 interfaces across 77 system services and successfully generated corresponding exploits, which can be used to conduct various permanent/temporary DoS attacks. We have reported our findings with suggestions for repairing the vulnerabilities to corresponding vendors. Up to now, Google has rated our vulnerability as high severity. Lei Zhang 0096, Keke Lian, Haoyu Xiao, Zhibo Zhang 0006, Peng Liu 0005, Yuan Zhang 0009, Min Yang 0002, Hai-Xin Duan |
SP | 1 |
| 2022 | Identity Confusion in WebView-based Mobile App-in-app Ecosystems
Lei Zhang 0096, Zhibo Zhang 0006, Ancong Liu, Yinzhi Cao, Xiaohan Zhang 0001, Yuan Zhang 0009, Guangliang Yang 0001, Min Yang 0002 |
USENIX Security Symposium | 1 |
| 2020 | TextExerciser: Feedback-driven Text Input Exercising for Android ApplicationsabstractDynamic analysis of Android apps is often used together with an exerciser to increase its code coverage. One big obstacle in designing such Android app exercisers comes from the existence of text-based inputs, which are often constrained by the nature of the input field, such as the length and character restrictions.In this paper, we propose TextExerciser, an iterative, feedback-driven text input exerciser, which generates text inputs for Android apps. Our key insight is that Android apps often provide feedback, called hints, for malformed inputs so that our system can utilize such hints to improve the input generation.We implemented a prototype of TextExerciser and evaluated it by comparing TextExerciser with state-of-the-art exercisers, such as The Monkey and DroidBot. Our evaluation shows that TextExerciser can achieve significantly higher code coverage and trigger more sensitive behaviors than these tools. We also combine TextExerciser with dynamic analysis tools and show they are able to detect more privacy leaks and vulnerabilities with TextExerciser than with existing exercisers. Particularly, existing tools, under the help of TextExerciser, find several new vulnerabilities, such as one user credential leak in a popular social app with more than 10,000,000 downloads. Yuyu He 0001, Lei Zhang 0096, Zhemin Yang, Yinzhi Cao, Keke Lian, Shuai Li 0006, Wei Yang 0013, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Hai-Xin Duan |
SP | 2 |
| 2019 | UR: A User-Based Collaborative Filtering Recommendation System Based on Trust Mechanism and Time WeightingabstractThe technology of personalized recommendation is aimed at studying the behaviors of users, analyzing what they may be interested in and recommending suitable items to them. In other words, the personalized recommendation is to better solve the contradiction between the requirements of users and the explosive information on the Internet. The userbased collaborative filtering recommendation is one of the most successful technology for recommendation system. The most significant step of user-based collaborative filtering recommendation is comprehensive user similarity calculation. However, most recommendation systems ignore the indispensability of trust mechanism of the users and the time weighted users rating attributes in user similarity calculation, which leads to the inaccurate recommendation. Based on these issues, this paper proposes an optimized user-based collaborative filtering recommendation systemcalled UR. UR not only validates the necessity of the trust mechanism of the users and the time weighted users rating in the comprehensive user similarity calculation, but also improves the recommendation accuracy Lei Zhang 0096, Jufang He |
ICPADS | 1 |
| 2018 | How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldabstractAs a new mechanism to monetize web content, cryptocurrency mining is becoming increasingly popular. The idea is simple: a webpage delivers extra workload (JavaScript) that consumes computational resources on the client machine to solve cryptographic puzzles, typically without notifying users or having explicit user consent. This new mechanism, often heavily abused and thus considered a threat termed "cryptojacking", is estimated to affect over 10 million web users every month; however, only a few anecdotal reports exist so far and little is known about its severeness, infrastructure, and technical characteristics behind the scene. This is likely due to the lack of effective approaches to detect cryptojacking at a large-scale (e.g., VirusTotal). In this paper, we take a first step towards an in-depth study over cryptojacking. By leveraging a set of inherent characteristics of cryptojacking scripts, we build CMTracker, a behavior-based detector with two runtime profilers for automatically tracking Cryptocurrency Mining scripts and their related domains. Surprisingly, our approach successfully discovered 2,770 unique cryptojacking samples from 853,936 popular web pages, including 868 among top 100K in Alexa list. Leveraging these samples, we gain a more comprehensive picture of the cryptojacking attacks, including their impact, distribution mechanisms, obfuscation, and attempts to evade detection. For instance, a diverse set of organizations benefit from cryptojacking based on the unique wallet ids. In addition, to stay under the radar, they frequently update their attack domains (fastflux) on the order of days. Many attackers also apply evasion techniques, including limiting the CPU usage, obfuscating the code, etc. Geng Hong, Zhemin Yang, Sen Yang 0011, Lei Zhang 0096, Yuhong Nan, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Zhiyun Qian, Hai-Xin Duan |
CCS | 4 |
| 2018 | Invetter: Locating Insecure Input Validations in Android ServicesabstractAndroid integrates an increasing number of features into system services to manage sensitive resources, such as location, medical and social network information. To prevent untrusted apps from abusing the services, Android implements a comprehensive set of access controls to ensure proper usage of sensitive resources. Unlike explicit permission-based access controls that are discussed extensively in the past, our paper focuses on the widespread yet undocumented input validation problem. As we show in the paper, there are in fact more input validations acting as security checks than permission checks, rendering them a critical foundation for Android framework. Unfortunately, these validations are unstructured, ill-defined, and fragmented, making it challenging to analyze. To this end, we design and implement a tool, called Invetter, that combines machine learning and static analysis to locate sensitive input validations that are problematic in system services. By applying Invetter to 4 different AOSP codebases and 4 vendor-customized images, we locate 103 candidate insecure validations. Among the true positives, we are able to confirm that at least 20 of them are truly exploitable vulnerabilities by constructing various attacks such as privilege escalation and private information leakage. Lei Zhang 0096, Zhemin Yang, Yuyu He 0001, Zhiyun Qian, Geng Hong, Yuan Zhang 0009, Min Yang 0002 |
CCS | 1 |