activity
20242026
collaborators

6 papers

cs.CR2026

Connect the Dots: Knowledge Graph-Guided Crawler Attack on Retrieval-Augmented Generation Systems

Mengyu Yao, Ziqi Zhang, Ning Luo +5

Stealing attacks pose a persistent threat to the intellectual property of deployed machine-learning systems. Retrieval-augmented generation (RAG) intensifies this risk by extending…

cs.CR2025

Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control

Yifeng Cai, Ziming Wang, Zhaomeng Deng +6

AI agents capable of GUI understanding and Model Context Protocol are increasingly deployed to automate mobile tasks. However, their reliance on over-privileged, static permissions…

cs.CR2025

Who Moved My Transaction? Uncovering Post-Transaction Auditability Vulnerabilities in Modern Super Apps

Junlin Liu, Zhaomeng Deng, Ziming Wang +6

Super apps are the cornerstones of modern digital life, embedding financial transactions into nearly every aspect of daily routine. The prevailing security paradigm for these platf…

cs.SE2025

GroupTuner: Efficient Group-Aware Compiler Auto-Tuning

Bingyu Gao, Mengyu Yao, Ziming Wang +4

Modern compilers typically provide hundreds of options to optimize program performance, but users often cannot fully leverage them due to the huge number of options. While standard…

cs.CR2025

I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps

Yifeng Cai, Ziqi Zhang, Mengyu Yao +8

Super-apps have emerged as comprehensive platforms integrating various mini-apps to provide diverse services. While super-apps offer convenience and enriched functionality, they ca…

cs.CR2024

TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models

Ding Li, Ziqi Zhang, Mengyu Yao +3

Trusted Execution Environments (TEE) are used to safeguard on-device models. However, directly employing TEEs to secure the entire DNN model is challenging due to the limited compu…