literature:bibliography
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| literature:bibliography [2026/09/27 12:00] – Add 27 entries for design:platforms:messaging_channels (Telegram/WhatsApp/Discord group studies and adjacent papers); generated by bibgen.mjs from the corpus index, USENIX authors from landing pages; 0 duplicate DOIs/titles. Authored by Claude. karel.kubicek.claude | literature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude | ||
|---|---|---|---|
| Line 10853: | Line 10853: | ||
| doi = {10.1145/ | doi = {10.1145/ | ||
| } | } | ||
| + | @inproceedings{lu2020_demystifying, | ||
| + | author | ||
| + | title = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2022_cross, | ||
| + | author | ||
| + | title = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2022_identity, | ||
| + | author | ||
| + | title = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2023_leak, | ||
| + | author | ||
| + | title = {Don't Leak Your Keys: Understanding, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_uncovering, | ||
| + | author | ||
| + | title = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_size, | ||
| + | author | ||
| + | title = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2024_minicat, | ||
| + | author | ||
| + | title = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_better, | ||
| + | author | ||
| + | title = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{cai2025_tell, | ||
| + | author | ||
| + | title = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{chen2026_minigames, | ||
| + | author | ||
| + | title = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2025_miniapp, | ||
| + | author | ||
| + | title = {Understanding Miniapp Malware: Identification, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2025_skeleton, | ||
| + | author | ||
| + | title = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{he2024_demystifying, | ||
| + | author | ||
| + | title = {Demystifying the Security Implications in IoT Device Rental Services}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{liu2024_riotfuzzer, | ||
| + | author | ||
| + | title = {RIoTFuzzer: | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{lee2025_deep, | ||
| + | author | ||
| + | title = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wei2026_raising, | ||
| + | author | ||
| + | title = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_convenience, | ||
| + | author | ||
| + | title = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2026_real, | ||
| + | author | ||
| + | title = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2025_wechat, | ||
| + | author | ||
| + | title = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.56553/ | ||
| + | } | ||
| + | |||
| + | @article{zhang2021_measurement, | ||
| + | author | ||
| + | title = {A Measurement Study of {WeChat} Mini-Apps}, | ||
| + | journal | ||
| + | volume | ||
| + | number | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{baskaran2023_measuring, | ||
| + | author | ||
| + | title = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_taintmini, | ||
| + | author | ||
| + | title = {{TaintMini}: | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{meng2023_wemint, | ||
| + | author | ||
| + | title = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @misc{yang2023_sok, | ||
| + | author | ||
| + | title = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps}, | ||
| + | year = {2023}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{zhang2026_oauth, | ||
| + | author | ||
| + | title = {Mini-Programs, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ciccotelli2026_tenet, | ||
| + | author | ||
| + | title = {{TENET}: Telegram Mini App (in)security}, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ferrari2026_telegapper, | ||
| + | author | ||
| + | title = {{TeleGapper}: | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| </ | </ | ||
literature/bibliography.1790510451.txt.gz · Last modified: by karel.kubicek.claude
