📝 Publications
(* Equal contribution)
2026
-
[C18] Demystifying LLM Supply Chain Vulnerabilities in the Wild: Distribution, Root Cause, and Real-World Impact CCF-CThe 17th Asia-Pacific Symposium on Internetware (Internetware'26) PDF
-
[C17] Unveiling Large Language Model Supply Chain: Structure, Domain, and Vulnerabilities CCF-CThe 17th Asia-Pacific Symposium on Internetware (Internetware'26) PDF
-
[C16] Understanding Bugs in Vector Database Management Systems CCF-CThe 17th Asia-Pacific Symposium on Internetware (Internetware'26) PDF
-
[C15] YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group CCF-A CORE-A*
-
[C14] Mapping the Landscape of LLM Deployment in the Wild: Prevalence, Patterns, and Perils CCF-B CORE-A*Proceedings of the ACM on Measurement and Analysis of Computer Systems (POMACS)
-
[C13] VDBFuzz: Understanding and Detecting Crash Bugs in Vector Database Management Systems CCF-A CORE-A*
-
[C12] TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated Applications CCF-A CORE-A*
-
[J6] Survey of Storage Mechanism Security Threats for Large Language Models CCF-T1Journal of Computer Research and Development, in Chinese PDF
-
[J5] Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions CCF-AACM Transactions on Software Engineering and Methodology (TOSEM) PDF
2025
-
[C11] Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems CCF-A CORE-A*The 40th IEEE/ACM International Conference on Automated Software Engineering (ASE'25) PDF
-
[C10] A Characterization Study of Bugs in LLM Agent Workflow Orchestration Frameworks CCF-A CORE-A*The 40th IEEE/ACM International Conference on Automated Software Engineering, Industry Showcase (ASE'25)
-
[J4] Large Language Models for Cyber Security: A Systematic Literature Review CCF-AACM Transactions on Software Engineering and Methodology (TOSEM) PDF
-
[J3] MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis CCF-AAlso accepted by FSE 2025 Journal First Track
-
[C9] Seeing is (Not) Believing: The Mirage Card Attack Targeting Online Social Networks CCF-CProceedings of the 16th Asia-Pacific Symposium on Internetware (Internetware'25) PDF
-
[C8] Exploring Typo Squatting Threats in the Hugging Face Ecosystem CCF-CProceedings of the 15th Asia-Pacific Symposium on Internetware PDF
-
[C7] GPT Store Mining and Analysis CCF-CProceedings of the 15th Asia-Pacific Symposium on Internetware PDF
-
[J2] LLM App Store Analysis: A Vision and Roadmap CCF-AACM Transactions on Software Engineering and Methodology, Special Issue: 2030 Software Engineering Roadmap (TOSEM) PDF
-
[J1] Large Language Model Supply Chain: A Research Agenda CCF-A
-
[W2] Towards Reliable Vector Database Management Systems: A Software Testing Roadmap for 2030ACM 2030 Roadmap for Software Engineering, co-located with FSE PDF
2024
-
[C6] CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial Environments CCF-A CORE-A*The 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS'24) PDF
-
[C5] Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs CCF-A CORE-A*
-
[C4] Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments CCF-A CORE-A*
-
[C3] GPTZoo: A Large-scale Dataset of GPTs for the Research Community CCF-A CORE-A*
2023
-
[W1] On the Usage-scenario-based Data Minimization in Mini ProgramsThe 2023 ACM Workshop on Secure and Trustworthy Superapps, co-located with CCS (SaTS) PDF
-
[C2] WeMinT: Tainting Sensitive Data Leaks in WeChat Mini-Programs CCF-A CORE-A*
-
[C1] MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains CCF-A CORE-A*