7 papers
Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis
Zidong Zhang, Zhentao Xie, Lingyun Ying +4
Mini-programs have become a dominant paradigm for lightweight application deployment within super apps such as WeChat. To support seamless integration, super apps provide OAuth mec…
Thinking More, Harnessing Better: State Machine Guided Harness Automatic Generation with Project Digestion and Workflow Decomposition
Xing Zhang, Zikang Huang, Gang Yang +9
High-quality fuzz harnesses are essential for effective gray-box fuzzing. While Large Language Models (LLMs) offer promise for automating this task, existing one-turn generation me…
ShadowProbe: Language-Extensible Detection of Hidden Algorithmic Complexity Vulnerabilities
Yuanmin Xie, Xiangfan Wu, Wenhao Wu +6
Algorithmic Complexity Vulnerabilities (ACVs) arise when adversarial inputs trigger worst-case execution behavior, causing severe performance degradation or Denial-of-Service condi…
Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs
Yacong Gu, Lingyun Ying, Zidong Zhang +6
AI-powered Applications (AI-Apps), hosted on platforms such as Hugging Face, are democratizing access to pre-trained models through online inference and fine-tuning services. While…
Cross-modal Retrieval Models for Stripped Binary Analysis
Guoqiang Chen, Lingyun Ying, Ziyang Song +7
Retrieving binary code via natural language queries is a pivotal capability for downstream tasks in the software security domain, such as vulnerability detection and malware analys…
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
Dongchao Zhou, Lingyun Ying, Huajun Chai +1
JavaScript's widespread adoption has made it an attractive target for malicious attackers who employ sophisticated obfuscation techniques to conceal harmful code. Current deobfusca…