User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/09/25 02:52] – Add roberts2019_impersonation for security:domain_abuse (cited after generic review). Duplicate-checked (0 definite). Authored by Claude. karel.kubicek.claudeliterature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude
Line 10610: Line 10610:
   doi           = {10.1145/3319535.3363188},   doi           = {10.1145/3319535.3363188},
 } }
 +
 +@inproceedings{marjanov2026_stayin,
 +  author        = {Marjanov, Tina and Tsuchiya, Taro and Ioannidis, Konstantinos and Hughes, Jack and Christin, Nicolas and Hutchings, Alice},
 +  title         = {Stayin' Alive: How Global Stolen Data Markets Thrive on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/marjanov},
 +}
 +
 +@inproceedings{gao2026_doxing,
 +  author        = {Gao, Yiran and Xia, Pengcheng and Wang, Liu and Liu, Tianming and Wang, Haoyu},
 +  title         = {Doxing-as-a-Service: Demystifying the Chinese Online Doxing Ecosystem},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792296},
 +}
 +
 +@inproceedings{xu2019_anatomy,
 +  author        = {Xu, Jiahua and Livshits, Benjamin},
 +  title         = {The Anatomy of a Cryptocurrency Pump-and-Dump Scheme},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2019},
 +  series        = {USENIX Security 2019},
 +  url           = {https://www.usenix.org/conference/usenixsecurity19/presentation/xu-jiahua},
 +}
 +
 +@inproceedings{sun2021_having,
 +  author        = {Sun, Zhibo and Oest, Adam and Zhang, Penghui and Rubio-Medrano, Carlos and Bao, Tiffany and Wang, Ruoyu and Zhao, Ziming and Shoshitaishvili, Yan and Doupé, Adam and Ahn, Gail-Joon},
 +  title         = {Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/sun-zhibo},
 +}
 +
 +@inproceedings{he2025_unmasking,
 +  author        = {He, Bowen and Hu, Yufeng and Chen, Zhuo and Chen, Yuan and Yu, Ting and Chang, Rui and Wu, Lei and Zhou, Yajin},
 +  title         = {Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764476},
 +}
 +
 +@inproceedings{weyns2026_mirai,
 +  author        = {Weyns, Maarten and Ferrero, Dario and Beek, Stefan Op de and Wagner, Daniel and Smaragdakis, Georgios and Griffioen, Harm},
 +  title         = {From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/weyns},
 +}
 +
 +@inproceedings{acharya2025_pirates,
 +  author        = {Acharya, Bhupendra and Lazzaro, Dario and Cinà, Antonio Emanuele and Holz, Thorsten},
 +  title         = {Pirates of Charity: Exploring Donation-based Abuses in Social Media Platforms},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714634},
 +}
 +
 +@inproceedings{hoseini2020_demystifying,
 +  author        = {Hoseini, Mohamad and Melo, Philipe and Junior, Manoel and Benevenuto, Fabrício and Chandrasekaran, Balakrishnan and Feldmann, Anja and Zannettou, Savvas},
 +  title         = {Demystifying the Messaging Platforms' Ecosystem Through the Lens of Twitter},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423651},
 +}
 +
 +@inproceedings{resende2019_information,
 +  author        = {Resende, Gustavo and Melo, Philipe F. and Sousa, Hugo and Messias, Johnnatan and Vasconcelos, Marisa and Almeida, Jussara M. and Benevenuto, Fabrício},
 +  title         = {(Mis)Information Dissemination in WhatsApp: Gathering, Analyzing and Countermeasures},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313688},
 +}
 +
 +@inproceedings{saha2021_short,
 +  author        = {Saha, Punyajoy and Mathew, Binny and Garimella, Kiran and Mukherjee, Animesh},
 +  title         = {"Short is the Road that Leads from Fear to Hate": Fear Speech in Indian WhatsApp Groups},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450137},
 +}
 +
 +@inproceedings{kireev2025_characterizing,
 +  author        = {Kireev, Klim and Mykhno, Yevhen and Troncoso, Carmela and Overdorf, Rebekah},
 +  title         = {Characterizing and Detecting Propaganda-Spreading Accounts on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/kireev},
 +}
 +
 +@inproceedings{vu2024_easy,
 +  author        = {Vu, Anh V. and Hutchings, Alice and Anderson, Ross J.},
 +  title         = {No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00007},
 +}
 +
 +@inproceedings{vu2024_getting,
 +  author        = {Vu, Anh V. and Thomas, Daniel R. and Collier, Ben and Hutchings, Alice and Clayton, Richard and Anderson, Ross J.},
 +  title         = {Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645401},
 +}
 +
 +@inproceedings{vafa2025_learning,
 +  author        = {Vafa, Elham Pourabbas and Singhal, Mohit and Thota, Poojitha and Roy, Sayak Saha},
 +  title         = {Learning from Censored Experiences: Social Media Discussions around Censorship Circumvention Technologies},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2025},
 +  series        = {IEEE S&P 2025},
 +  doi           = {10.1109/sp61157.2025.00062},
 +}
 +
 +@inproceedings{recabarren2023_strategies,
 +  author        = {Recabarren, Ruben and Carbunar, Bogdan and Hernandez, Nestor and Shafin, Ashfaq Ali},
 +  title         = {Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/recabarren},
 +}
 +
 +@inproceedings{aliapoulios2021_characterization,
 +  author        = {Aliapoulios, Maxwell and Take, Kejsi and Ramakrishna, Prashanth and Borkan, Daniel and Goldberg, Beth and Sorensen, Jeffrey and Turner, Anna and Greenstadt, Rachel and Lauinger, Tobias and McCoy, Damon},
 +  title         = {A large-scale characterization of online incitements to harassment across platforms},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487852},
 +}
 +
 +@inproceedings{bahramali2020_practical,
 +  author        = {Bahramali, Alireza and Houmansadr, Amir and Soltani, Ramin and Goeckel, Dennis and Towsley, Don},
 +  title         = {Practical Traffic Analysis Attacks on Secure Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/practical-traffic-analysis-attacks-on-secure-messaging-applications/},
 +}
 +
 +@inproceedings{weerasinghe2020_people,
 +  author        = {Weerasinghe, Janith and Flanigan, Bailey and Stein, Aviel J. and McCoy, Damon and Greenstadt, Rachel},
 +  title         = {The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2020},
 +  series        = {TheWebConf 2020},
 +  doi           = {10.1145/3366423.3380256},
 +}
 +
 +@inproceedings{shen2024_anything,
 +  author        = {Shen, Xinyue and Chen, Zeyuan and Backes, Michael and Shen, Yun and Zhang, Yang},
 +  title         = {"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670388},
 +}
 +
 +@inproceedings{yu2024_listen,
 +  author        = {Yu, Zhiyuan and Liu, Xiaogeng and Liang, Shunning and Cameron, Zach and Xiao, Chaowei and Zhang, Ning},
 +  title         = {Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/yu-zhiyuan},
 +}
 +
 +@inproceedings{guo2024_moderating,
 +  author        = {Guo, Keyan and Utkarsh, Ayush and Ding, Wenbo and Ondracek, Isabelle and Zhao, Ziming and Freeman, Guo and Vishwamitra, Nishant and Hu, Hongxin},
 +  title         = {Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/guo-keyan},
 +}
 +
 +@inproceedings{schrittwieser2012_guess,
 +  author        = {Schrittwieser, Sebastian and Frühwirt, Peter and Kieseberg, Peter and Leithner, Manuel and Mulazzani, Martin and Huber, Markus and Weippl, Edgar},
 +  title         = {Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2012},
 +  series        = {NDSS 2012},
 +  url           = {https://www.ndss-symposium.org/ndss2012/ndss-2012-programme/guess-whos-texting-you-evaluating-security-smartphone-messaging-applications/},
 +}
 +
 +@inproceedings{li2025_investigating,
 +  author        = {Li, Jiliang and Lu, Nora Sinong and Hanimann, Isaak and Si, Janice Jianing and Cheng, Dazhao and Zhou, Xiaobo and Wang, Kanye Ye},
 +  title         = {Investigating the Impact of Online Community Involvement on Safety Practices and Perceived Risks Among People Who Use Drugs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/li-jiliang},
 +}
 +
 +@inproceedings{albrecht2021_collective,
 +  author        = {Albrecht, Martin R. and Blasco, Jorge and Jensen, Rikke Bjerg and Mareková, Lenka},
 +  title         = {Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht},
 +}
 +
 +@inproceedings{arunasalam2024_security,
 +  author        = {Arunasalam, Arjun and Farrukh, Habiba and Tekcan, Eliz and Celik, Z. Berkay},
 +  title         = {Understanding the Security and Privacy Implications of Online Toxic Content on Refugees},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/arunasalam},
 +}
 +
 +@inproceedings{chou2025_bots,
 +  author        = {Chou, Kai-Hsiang and Lin, Yi-Min and Wang, Yi-An and Li, Jonathan Weiping and Kim, Tiffany Hyun-Jin and Hsiao, Hsu-Chun},
 +  title         = {Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/chou},
 +}
 +
 +@inproceedings{wang2025_detecting,
 +  author        = {Wang, Hongyu and Li, Ying and Huang, Ronghong and Mi, Xianghang},
 +  title         = {Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714550},
 +}
 +@inproceedings{lu2020_demystifying,
 +  author        = {Lu, Haoran and Xing, Luyi and Xiao, Yue and Zhang, Yifan and Liao, Xiaojing and Wang, XiaoFeng and Wang, Xueqiang},
 +  title         = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417255},
 +}
 +
 +@inproceedings{yang2022_cross,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2022},
 +  series        = {CCS 2022},
 +  doi           = {10.1145/3548606.3560597},
 +}
 +
 +@inproceedings{zhang2022_identity,
 +  author        = {Zhang, Lei and Zhang, Zhibo and Liu, Ancong and Cao, Yinzhi and Zhang, Xiaohan and Chen, Yanjun and Zhang, Yuan and Yang, Guangliang and Yang, Min},
 +  title         = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/zhang-lei},
 +}
 +
 +@inproceedings{zhang2023_leak,
 +  author        = {Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616591},
 +}
 +
 +@inproceedings{wang2023_uncovering,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616676},
 +}
 +
 +@inproceedings{wang2023_size,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/wang-chao},
 +}
 +
 +@inproceedings{zhang2024_minicat,
 +  author        = {Zhang, Zidong and Hou, Qinsheng and Ying, Lingyun and Diao, Wenrui and Gu, Yacong and Li, Rui and Guo, Shanqing and Duan, Haixin},
 +  title         = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670294},
 +}
 +
 +@inproceedings{shi2026_better,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Liu, Dingyi and Zhong, Kangwei and Dai, Jiarun and Yang, Min},
 +  title         = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/better-safe-than-sorry-uncovering-the-insecure-resource-management-in-app-in-app-cloud-services/},
 +}
 +
 +@inproceedings{cai2025_tell,
 +  author        = {Cai, Yifeng and Zhang, Ziqi and Yao, Mengyu and Liu, Junlin and Zhao, Xiaoke and Fu, Xinyi and Li, Ruoyu and Liu, Zhe and Chen, Xiangqun and Guo, Yao and Li, Ding},
 +  title         = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/cai-yifeng},
 +}
 +
 +@inproceedings{chen2026_minigames,
 +  author        = {Chen, Pei and Hong, Geng and Qin, Yicheng and Wang, Huazhe and Wu, Mengying and Yang, Min and Zhao, Ziru and Zhu, Yuanpeng and Su, Tao},
 +  title         = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chen-pei},
 +}
 +
 +@inproceedings{yang2025_miniapp,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Understanding Miniapp Malware: Identification, Dissection, and Characterization},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/understanding-miniapp-malware-identification-dissection-and-characterization/},
 +}
 +
 +@inproceedings{shi2025_skeleton,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Zhong, Kangwei and Yang, Guangliang and Yang, Yifan and Zhang, Xiaohan and Yang, Min},
 +  title         = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-skeleton-keys-a-large-scale-analysis-of-credential-leakage-in-mini-apps/},
 +}
 +
 +@inproceedings{he2024_demystifying,
 +  author        = {He, Yi and Guan, Yunchao and Lun, Ruoyu and Song, Shangru and Guo, Zhihao and Zhuge, Jianwei and Chen, Jianjun and Wei, Qiang and Wu, Zehui and Yu, Miao and Shi, Hetian and Li, Qi},
 +  title         = {Demystifying the Security Implications in IoT Device Rental Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/he-yi},
 +}
 +
 +@inproceedings{liu2024_riotfuzzer,
 +  author        = {Liu, Kaizheng and Yang, Ming and Ling, Zhen and Zhang, Yue and Lei, Chongqing and Luo, Junzhou and Fu, Xinwen},
 +  title         = {RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT Devices},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670342},
 +}
 +
 +@inproceedings{lee2025_deep,
 +  author        = {Lee, Woonghee and Hur, Junbeom and Kwon, Hyunsoo},
 +  title         = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765215},
 +}
 +
 +@inproceedings{wei2026_raising,
 +  author        = {Wei, Zhiao and Wang, Chao and Faheem, Haseeb-Ur-Rehman and Xing, Luyi and Aafer, Yousra and Lin, Zhiqiang},
 +  title         = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/wei-zhiao},
 +}
 +
 +@inproceedings{shi2026_convenience,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Yang, Yifan and Yang, Yunteng and Yang, Min},
 +  title         = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S\&P 2026},
 +  doi           = {10.1109/sp63933.2026.00074},
 +}
 +
 +@inproceedings{yang2026_real,
 +  author        = {Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792470},
 +}
 +
 +@inproceedings{wang2025_wechat,
 +  author        = {Wang, Mona and Lin, Pellaeon and Knockel, Jeffrey and Greenberg, Will and Mayer, Jonathan and Mittal, Prateek},
 +  title         = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0163},
 +}
 +
 +@article{zhang2021_measurement,
 +  author        = {Zhang, Yue and Turkistani, Bayan and Yang, Allen Yuqing and Zuo, Chaoshun and Lin, Zhiqiang},
 +  title         = {A Measurement Study of {WeChat} Mini-Apps},
 +  journal       = {Proceedings of the ACM on Measurement and Analysis of Computing Systems},
 +  volume        = {5},
 +  number        = {2},
 +  year          = {2021},
 +  series        = {SIGMETRICS 2021},
 +  doi           = {10.1145/3460081},
 +}
 +
 +@inproceedings{baskaran2023_measuring,
 +  author        = {Baskaran, Supraja and Zhao, Lianying and Mannan, Mohammad and Youssef, Amr},
 +  title         = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case},
 +  booktitle     = {Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses},
 +  year          = {2023},
 +  series        = {RAID 2023},
 +  doi           = {10.1145/3607199.3607236},
 +}
 +
 +@inproceedings{wang2023_taintmini,
 +  author        = {Wang, Chao and Ko, Ronny and Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {{TaintMini}: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis},
 +  booktitle     = {Proceedings of the 45th IEEE/ACM International Conference on Software Engineering},
 +  year          = {2023},
 +  series        = {ICSE 2023},
 +  doi           = {10.1109/ICSE48619.2023.00086},
 +}
 +
 +@inproceedings{meng2023_wemint,
 +  author        = {Meng, Shi and Wang, Liu and Wang, Shenao and Wang, Kailong and Xiao, Xusheng and Bai, Guangdong and Wang, Haoyu},
 +  title         = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs},
 +  booktitle     = {Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering},
 +  year          = {2023},
 +  series        = {ASE 2023},
 +  doi           = {10.1109/ASE56229.2023.00151},
 +}
 +
 +@misc{yang2023_sok,
 +  author        = {Yang, Yuqing and Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps},
 +  year          = {2023},
 +  howpublished  = {arXiv:2306.07495},
 +  url           = {https://arxiv.org/abs/2306.07495},
 +}
 +
 +@misc{zhang2026_oauth,
 +  author        = {Zhang, Zidong and Xie, Zhentao and Ying, Lingyun and Hou, Qinsheng and Gu, Yacong and Diao, Wenrui and Wu, Jianliang},
 +  title         = {Mini-Programs, Mega-Problems: Unveiling {OAuth}-based Authentication Misuses in Mini-Programs via Dynamic Analysis},
 +  year          = {2026},
 +  howpublished  = {arXiv:2607.08232, accepted at ACM CCS 2026},
 +  url           = {https://arxiv.org/abs/2607.08232},
 +}
 +
 +@misc{ciccotelli2026_tenet,
 +  author        = {Ciccotelli, Andrea and Zappone, Federico and Di Pietro, Roberto},
 +  title         = {{TENET}: Telegram Mini App (in)security},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.17538},
 +  url           = {https://arxiv.org/abs/2608.17538},
 +}
 +
 +@misc{ferrari2026_telegapper,
 +  author        = {Ferrari, Luca and Ceccato, Mariano and Verderame, Luca},
 +  title         = {{TeleGapper}: On the (un)reliability of Privacy Policies in Telegram Mini apps},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.13390},
 +  url           = {https://arxiv.org/abs/2608.13390},
 +}
 +
 </bibtex> </bibtex>
  
literature/bibliography.1790304726.txt.gz · Last modified: by karel.kubicek.claude