7 papers
Connect the Dots: Knowledge Graph-Guided Crawler Attack on Retrieval-Augmented Generation Systems
Mengyu Yao, Ziqi Zhang, Ning Luo +5
Stealing attacks pose a persistent threat to the intellectual property of deployed machine-learning systems. Retrieval-augmented generation (RAG) intensifies this risk by extending…
Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control
Yifeng Cai, Ziming Wang, Zhaomeng Deng +6
AI agents capable of GUI understanding and Model Context Protocol are increasingly deployed to automate mobile tasks. However, their reliance on over-privileged, static permissions…
Who Moved My Transaction? Uncovering Post-Transaction Auditability Vulnerabilities in Modern Super Apps
Junlin Liu, Zhaomeng Deng, Ziming Wang +6
Super apps are the cornerstones of modern digital life, embedding financial transactions into nearly every aspect of daily routine. The prevailing security paradigm for these platf…
PromoGuardian: Detecting Promotion Abuse Fraud with Multi-Relation Fused Graph Neural Networks
Shaofei Li, Xiao Han, Ziqi Zhang +6
As e-commerce platforms develop, fraudulent activities are increasingly emerging, posing significant threats to the security and stability of these platforms. Promotion abuse is on…
I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps
Yifeng Cai, Ziqi Zhang, Mengyu Yao +8
Super-apps have emerged as comprehensive platforms integrating various mini-apps to provide diverse services. While super-apps offer convenience and enriched functionality, they ca…
Moss: Proxy Model-based Full-Weight Aggregation in Federated Learning with Heterogeneous Models
Yifeng Cai, Ziqi Zhang, Ding Li +2
Modern Federated Learning (FL) has become increasingly essential for handling highly heterogeneous mobile devices. Current approaches adopt a partial model aggregation paradigm tha…