Selected Publications
Research overview · Google Scholar
* denotes equal contribution. Expand Research impact for outcomes and vendor responses.
2026
When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By in the Splash Ads Ecosystem
S. Wu, B. Wang, Y. Zhang, X. Wang, Y. Cao
ACM CCS 2026
Research impact
We helped a major advertiser uncover SDK-level ad fraud. Two leading ad networks acknowledged the behavior, and one issued a refund of 4 million CNY. Our large-scale measurement identified hundreds of affected apps and prompted vendor remediation.
2025
LineBreaker: Finding Token-Inconsistency Bugs using Large Language Models
Y. Zhang*, H. Chen*, X. Han*, H. Rong, Y. Zhang, T. Mao, H. Zhang, X. Wang, L. Xing, X. Chen
ASE 2025 · PDF
Research impact
We identified 123 new flaws across 154 Python and C GitHub repositories, each with over 1,000 stars. Of 69 submitted fixes, 27 were merged.
2024
Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKs
Y. Zhang, Z. Hu, X. Wang, Y. Hong, Y. Nan, X. Wang, J. Cheng, L. Xing
USENIX Security 2024 · PDF
Research impact
We reported privacy issues to more than 40 Android SDK vendors. Six advertising vendors acknowledged the findings, and Vungle fixed the issues.
Seeing is Not Always Believing: An Empirical Analysis of Fake Evidence Generators
Z. Hu*, J. Ye*, Y. Zhang, X. Wang
IEEE EuroS&P 2024 · PDF
2023
Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply Chain
Y. Zhang*, X. Wang*, X. Wang, Y. Jia, L. Xing
USENIX Security 2023 · PDF
Research impact
The Android Studio team acknowledged our vulnerability report. We also notified hundreds of SDK vendors affected by this attack vector.
Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps
Y. Nan, X. Wang, L. Xing, X. Liao, R. Wu, J. Wu, Y. Zhang, X. Wang
USENIX Security 2023 · PDF
Research impact
We sent more than 1,000 disclosure emails to app developers whose apps did not disclose certain IoT data items. Twenty-one developers acknowledged the findings and updated their privacy policies. We also reported the affected apps to Google Play.
2021
Who’s In Control? On Security Risks of Disjointed IoT Device Management Channels
Y. Jia, B. Yan, L. Xing, D. Zhao, X. Wang, Y. Zhang, Y. Liu, K. Zheng, Y. Zhang, D. Zou, H. Jin
ACM CCS 2021 · PDF
Research impact
We disclosed vulnerabilities in widely used IoT devices and systems that could let attackers control other users' devices and steal personal data. Affected manufacturers included iRobot, August, Yale, Philips Hue, Tuya, Amazon Alexa, Belkin, and Dyson. Vendors acknowledged the issues and adopted our security designs and patches to protect their products.
2020
Demystifying resource management risks in emerging mobile app-in-app ecosystems
H. Lu, L. Xing, Y. Xiao, Y. Zhang, X. Liao, X. Wang, X. Wang
ACM CCS 2020 · PDF
Research impact
Our security designs were implemented by Chrome, Firefox, Safari, WeChat, and Alipay.
