User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/09/27 12:00] – Add 27 entries for design:platforms:messaging_channels (Telegram/WhatsApp/Discord group studies and adjacent papers); generated by bibgen.mjs from the corpus index, USENIX authors from landing pages; 0 duplicate DOIs/titles. Authored by Claude. karel.kubicek.claudeliterature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude
Line 10853: Line 10853:
   doi           = {10.1145/3696410.3714550},   doi           = {10.1145/3696410.3714550},
 } }
 +@inproceedings{lu2020_demystifying,
 +  author        = {Lu, Haoran and Xing, Luyi and Xiao, Yue and Zhang, Yifan and Liao, Xiaojing and Wang, XiaoFeng and Wang, Xueqiang},
 +  title         = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417255},
 +}
 +
 +@inproceedings{yang2022_cross,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2022},
 +  series        = {CCS 2022},
 +  doi           = {10.1145/3548606.3560597},
 +}
 +
 +@inproceedings{zhang2022_identity,
 +  author        = {Zhang, Lei and Zhang, Zhibo and Liu, Ancong and Cao, Yinzhi and Zhang, Xiaohan and Chen, Yanjun and Zhang, Yuan and Yang, Guangliang and Yang, Min},
 +  title         = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/zhang-lei},
 +}
 +
 +@inproceedings{zhang2023_leak,
 +  author        = {Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616591},
 +}
 +
 +@inproceedings{wang2023_uncovering,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616676},
 +}
 +
 +@inproceedings{wang2023_size,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/wang-chao},
 +}
 +
 +@inproceedings{zhang2024_minicat,
 +  author        = {Zhang, Zidong and Hou, Qinsheng and Ying, Lingyun and Diao, Wenrui and Gu, Yacong and Li, Rui and Guo, Shanqing and Duan, Haixin},
 +  title         = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670294},
 +}
 +
 +@inproceedings{shi2026_better,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Liu, Dingyi and Zhong, Kangwei and Dai, Jiarun and Yang, Min},
 +  title         = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/better-safe-than-sorry-uncovering-the-insecure-resource-management-in-app-in-app-cloud-services/},
 +}
 +
 +@inproceedings{cai2025_tell,
 +  author        = {Cai, Yifeng and Zhang, Ziqi and Yao, Mengyu and Liu, Junlin and Zhao, Xiaoke and Fu, Xinyi and Li, Ruoyu and Liu, Zhe and Chen, Xiangqun and Guo, Yao and Li, Ding},
 +  title         = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/cai-yifeng},
 +}
 +
 +@inproceedings{chen2026_minigames,
 +  author        = {Chen, Pei and Hong, Geng and Qin, Yicheng and Wang, Huazhe and Wu, Mengying and Yang, Min and Zhao, Ziru and Zhu, Yuanpeng and Su, Tao},
 +  title         = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chen-pei},
 +}
 +
 +@inproceedings{yang2025_miniapp,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Understanding Miniapp Malware: Identification, Dissection, and Characterization},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/understanding-miniapp-malware-identification-dissection-and-characterization/},
 +}
 +
 +@inproceedings{shi2025_skeleton,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Zhong, Kangwei and Yang, Guangliang and Yang, Yifan and Zhang, Xiaohan and Yang, Min},
 +  title         = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-skeleton-keys-a-large-scale-analysis-of-credential-leakage-in-mini-apps/},
 +}
 +
 +@inproceedings{he2024_demystifying,
 +  author        = {He, Yi and Guan, Yunchao and Lun, Ruoyu and Song, Shangru and Guo, Zhihao and Zhuge, Jianwei and Chen, Jianjun and Wei, Qiang and Wu, Zehui and Yu, Miao and Shi, Hetian and Li, Qi},
 +  title         = {Demystifying the Security Implications in IoT Device Rental Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/he-yi},
 +}
 +
 +@inproceedings{liu2024_riotfuzzer,
 +  author        = {Liu, Kaizheng and Yang, Ming and Ling, Zhen and Zhang, Yue and Lei, Chongqing and Luo, Junzhou and Fu, Xinwen},
 +  title         = {RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT Devices},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670342},
 +}
 +
 +@inproceedings{lee2025_deep,
 +  author        = {Lee, Woonghee and Hur, Junbeom and Kwon, Hyunsoo},
 +  title         = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765215},
 +}
 +
 +@inproceedings{wei2026_raising,
 +  author        = {Wei, Zhiao and Wang, Chao and Faheem, Haseeb-Ur-Rehman and Xing, Luyi and Aafer, Yousra and Lin, Zhiqiang},
 +  title         = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/wei-zhiao},
 +}
 +
 +@inproceedings{shi2026_convenience,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Yang, Yifan and Yang, Yunteng and Yang, Min},
 +  title         = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S\&P 2026},
 +  doi           = {10.1109/sp63933.2026.00074},
 +}
 +
 +@inproceedings{yang2026_real,
 +  author        = {Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792470},
 +}
 +
 +@inproceedings{wang2025_wechat,
 +  author        = {Wang, Mona and Lin, Pellaeon and Knockel, Jeffrey and Greenberg, Will and Mayer, Jonathan and Mittal, Prateek},
 +  title         = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0163},
 +}
 +
 +@article{zhang2021_measurement,
 +  author        = {Zhang, Yue and Turkistani, Bayan and Yang, Allen Yuqing and Zuo, Chaoshun and Lin, Zhiqiang},
 +  title         = {A Measurement Study of {WeChat} Mini-Apps},
 +  journal       = {Proceedings of the ACM on Measurement and Analysis of Computing Systems},
 +  volume        = {5},
 +  number        = {2},
 +  year          = {2021},
 +  series        = {SIGMETRICS 2021},
 +  doi           = {10.1145/3460081},
 +}
 +
 +@inproceedings{baskaran2023_measuring,
 +  author        = {Baskaran, Supraja and Zhao, Lianying and Mannan, Mohammad and Youssef, Amr},
 +  title         = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case},
 +  booktitle     = {Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses},
 +  year          = {2023},
 +  series        = {RAID 2023},
 +  doi           = {10.1145/3607199.3607236},
 +}
 +
 +@inproceedings{wang2023_taintmini,
 +  author        = {Wang, Chao and Ko, Ronny and Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {{TaintMini}: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis},
 +  booktitle     = {Proceedings of the 45th IEEE/ACM International Conference on Software Engineering},
 +  year          = {2023},
 +  series        = {ICSE 2023},
 +  doi           = {10.1109/ICSE48619.2023.00086},
 +}
 +
 +@inproceedings{meng2023_wemint,
 +  author        = {Meng, Shi and Wang, Liu and Wang, Shenao and Wang, Kailong and Xiao, Xusheng and Bai, Guangdong and Wang, Haoyu},
 +  title         = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs},
 +  booktitle     = {Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering},
 +  year          = {2023},
 +  series        = {ASE 2023},
 +  doi           = {10.1109/ASE56229.2023.00151},
 +}
 +
 +@misc{yang2023_sok,
 +  author        = {Yang, Yuqing and Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps},
 +  year          = {2023},
 +  howpublished  = {arXiv:2306.07495},
 +  url           = {https://arxiv.org/abs/2306.07495},
 +}
 +
 +@misc{zhang2026_oauth,
 +  author        = {Zhang, Zidong and Xie, Zhentao and Ying, Lingyun and Hou, Qinsheng and Gu, Yacong and Diao, Wenrui and Wu, Jianliang},
 +  title         = {Mini-Programs, Mega-Problems: Unveiling {OAuth}-based Authentication Misuses in Mini-Programs via Dynamic Analysis},
 +  year          = {2026},
 +  howpublished  = {arXiv:2607.08232, accepted at ACM CCS 2026},
 +  url           = {https://arxiv.org/abs/2607.08232},
 +}
 +
 +@misc{ciccotelli2026_tenet,
 +  author        = {Ciccotelli, Andrea and Zappone, Federico and Di Pietro, Roberto},
 +  title         = {{TENET}: Telegram Mini App (in)security},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.17538},
 +  url           = {https://arxiv.org/abs/2608.17538},
 +}
 +
 +@misc{ferrari2026_telegapper,
 +  author        = {Ferrari, Luca and Ceccato, Mariano and Verderame, Luca},
 +  title         = {{TeleGapper}: On the (un)reliability of Privacy Policies in Telegram Mini apps},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.13390},
 +  url           = {https://arxiv.org/abs/2608.13390},
 +}
 +
 </bibtex> </bibtex>
  
literature/bibliography.1790510451.txt.gz · Last modified: by karel.kubicek.claude