6 papers
Connect the Dots: Knowledge Graph-Guided Crawler Attack on Retrieval-Augmented Generation Systems
Mengyu Yao, Ziqi Zhang, Ning Luo +5
Stealing attacks pose a persistent threat to the intellectual property of deployed machine-learning systems. Retrieval-augmented generation (RAG) intensifies this risk by extending…
Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control
Yifeng Cai, Ziming Wang, Zhaomeng Deng +6
AI agents capable of GUI understanding and Model Context Protocol are increasingly deployed to automate mobile tasks. However, their reliance on over-privileged, static permissions…
Who Moved My Transaction? Uncovering Post-Transaction Auditability Vulnerabilities in Modern Super Apps
Junlin Liu, Zhaomeng Deng, Ziming Wang +6
Super apps are the cornerstones of modern digital life, embedding financial transactions into nearly every aspect of daily routine. The prevailing security paradigm for these platf…
GroupTuner: Efficient Group-Aware Compiler Auto-Tuning
Bingyu Gao, Mengyu Yao, Ziming Wang +4
Modern compilers typically provide hundreds of options to optimize program performance, but users often cannot fully leverage them due to the huge number of options. While standard…
I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps
Yifeng Cai, Ziqi Zhang, Mengyu Yao +8
Super-apps have emerged as comprehensive platforms integrating various mini-apps to provide diverse services. While super-apps offer convenience and enriched functionality, they ca…
TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models
Ding Li, Ziqi Zhang, Mengyu Yao +3
Trusted Execution Environments (TEE) are used to safeguard on-device models. However, directly employing TEEs to secure the entire DNN model is challenging due to the limited compu…