I’m an assistant professor at San Diego State University (SDSU) and a member of the Cybersecurity Center. I joined SDSU in August 2025.
I received my Ph.D. in Computer Science from Indiana University Bloomington in July 2025, advised by XiaoFeng Wang and Luyi Xing, and my B.Eng. in Information Security from Xidian University in 2019. I was a research intern at Samsung Research America from February to May 2024.
My research focuses on software supply chain, mobile, and IoT security and privacy. I use program analysis, machine learning, large language models (LLMs), and formal verification to uncover new attack vectors and emerging privacy issues in these and other evolving ecosystems.
Prospective PhD students: I am accepting PhD students with interests in systems security and privacy. See the recruitment flyer or contact me.
Selected Publications
Google Scholar · * Equal contribution.
When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By in the Splash Ads Ecosystem
S. Wu, B. Wang, Y. Zhang, X. Wang, Y. Cao
ACM CCS 2026.Research impact
We helped a major advertiser uncover SDK-level ad fraud. Two leading ad networks acknowledged the behavior, and one issued a refund of 4 million CNY. Our measurement identified hundreds of affected apps and prompted vendor remediation.
LineBreaker: Finding Token-Inconsistency Bugs using Large Language Models · PDF
Y. Zhang*, H. Chen*, X. Han*, H. Rong, Y. Zhang, T. Mao, H. Zhang, X. Wang, L. Xing, X. Chen
ASE 2025.Research impact
We identified 123 new flaws across 154 Python and C GitHub repositories, each with over 1,000 stars. Of 69 submitted fixes, 27 were merged.
Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKs · PDF
Y. Zhang, Z. Hu, X. Wang, Y. Hong, Y. Nan, X. Wang, J. Cheng, L. Xing
USENIX Security 2024.Research impact
We reported privacy issues to more than 40 Android SDK vendors. Six advertising vendors acknowledged the findings, and Vungle fixed the issues.
Seeing is Not Always Believing: An Empirical Analysis of Fake Evidence Generators · PDF
Z. Hu*, J. Ye*, Y. Zhang, X. Wang
IEEE EuroS&P 2024.Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply Chain · PDF
Y. Zhang*, X. Wang*, X. Wang, Y. Jia, L. Xing
USENIX Security 2023.Research impact
The Android Studio team acknowledged our vulnerability report. We also notified hundreds of SDK vendors affected by this attack vector.
Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps · PDF
Y. Nan, X. Wang, L. Xing, X. Liao, R. Wu, J. Wu, Y. Zhang, X. Wang
USENIX Security 2023.Research impact
We sent more than 1,000 disclosure emails to app developers. Twenty-one developers acknowledged the findings and updated their privacy policies. We also reported the affected apps to Google Play.
Who’s In Control? On Security Risks of Disjointed IoT Device Management Channels · PDF
Y. Jia, B. Yan, L. Xing, D. Zhao, X. Wang, Y. Zhang, Y. Liu, K. Zheng, Y. Zhang, D. Zou, H. Jin
ACM CCS 2021.Research impact
We disclosed vulnerabilities in widely used IoT devices and systems. Vendors acknowledged the issues and adopted our security designs and patches to protect their products.
Demystifying resource management risks in emerging mobile app-in-app ecosystems · PDF
H. Lu, L. Xing, Y. Xiao, Y. Zhang, X. Liao, X. Wang, X. Wang
ACM CCS 2020.Research impact
Our security designs were implemented by Chrome, Firefox, Safari, WeChat, and Alipay.
Professional Service
- Program committees: USENIX Security 2027, HealthSec 2026, SDIoTSec 2026, SafeThings 2025, SDIoTSec 2024, SafeThings 2024.
- Artifact evaluation: USENIX Security Artifact Evaluation Committee, 2024.
- Journal reviewer: IEEE Transactions on Dependable and Secure Computing (TDSC), 2026.
- Sub-reviewer: PoPETs 2024; IEEE S&P 2022, 2020; TDSC 2022; Inscrypt 2022; WiSec 2021; NDSS 2021, 2020; CCS 2020.
Selected Awards & Recognition
- USENIX Security Travel Award, 2023.
- CSAW Best Applied Security Paper Award, Top 10 Finalist, 2022.
- DEF CON CTF finalist with team r3kapig, 2022 and 2018.
- HackIN: 2nd place in 2022; 1st place in 2019.
- Security Hall of Fame acknowledgments: Opera, 2019; Tencent, 2018.
- First Prize, National Student Information Security Competition, 2017; First Prize, National Student Cryptography Competition, 2016.
