Selected Publications

Research overview · Google Scholar

* denotes equal contribution. Expand Research impact for outcomes and vendor responses.

2026

When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By in the Splash Ads Ecosystem

S. Wu, B. Wang, Y. Zhang, X. Wang, Y. Cao

ACM CCS 2026

Research impact

We helped a major advertiser uncover SDK-level ad fraud. Two leading ad networks acknowledged the behavior, and one issued a refund of 4 million CNY. Our large-scale measurement identified hundreds of affected apps and prompted vendor remediation.

2025

LineBreaker: Finding Token-Inconsistency Bugs using Large Language Models

Y. Zhang*, H. Chen*, X. Han*, H. Rong, Y. Zhang, T. Mao, H. Zhang, X. Wang, L. Xing, X. Chen

ASE 2025 · PDF

Research impact

We identified 123 new flaws across 154 Python and C GitHub repositories, each with over 1,000 stars. Of 69 submitted fixes, 27 were merged.

2024

Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKs

Y. Zhang, Z. Hu, X. Wang, Y. Hong, Y. Nan, X. Wang, J. Cheng, L. Xing

USENIX Security 2024 · PDF

Research impact

We reported privacy issues to more than 40 Android SDK vendors. Six advertising vendors acknowledged the findings, and Vungle fixed the issues.

Seeing is Not Always Believing: An Empirical Analysis of Fake Evidence Generators

Z. Hu*, J. Ye*, Y. Zhang, X. Wang

IEEE EuroS&P 2024 · PDF

2023

Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply Chain

Y. Zhang*, X. Wang*, X. Wang, Y. Jia, L. Xing

USENIX Security 2023 · PDF

Research impact

The Android Studio team acknowledged our vulnerability report. We also notified hundreds of SDK vendors affected by this attack vector.

Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps

Y. Nan, X. Wang, L. Xing, X. Liao, R. Wu, J. Wu, Y. Zhang, X. Wang

USENIX Security 2023 · PDF

Research impact

We sent more than 1,000 disclosure emails to app developers whose apps did not disclose certain IoT data items. Twenty-one developers acknowledged the findings and updated their privacy policies. We also reported the affected apps to Google Play.

2021

Who’s In Control? On Security Risks of Disjointed IoT Device Management Channels

Y. Jia, B. Yan, L. Xing, D. Zhao, X. Wang, Y. Zhang, Y. Liu, K. Zheng, Y. Zhang, D. Zou, H. Jin

ACM CCS 2021 · PDF

Research impact

We disclosed vulnerabilities in widely used IoT devices and systems that could let attackers control other users' devices and steal personal data. Affected manufacturers included iRobot, August, Yale, Philips Hue, Tuya, Amazon Alexa, Belkin, and Dyson. Vendors acknowledged the issues and adopted our security designs and patches to protect their products.

2020

Demystifying resource management risks in emerging mobile app-in-app ecosystems

H. Lu, L. Xing, Y. Xiao, Y. Zhang, X. Liao, X. Wang, X. Wang

ACM CCS 2020 · PDF

Research impact

Our security designs were implemented by Chrome, Firefox, Safari, WeChat, and Alipay.