About
I am a postdoctoral researcher in the School of Cyber Science and Engineering at Huazhong University of Science and Technology (HUST), where I work in the Security PRIDE Research Group led by Prof. Haoyu Wang, my collaborating supervisor. I received my Ph.D. from Monash University in 2025, under the supervision of Prof. Li Li. Prior to that, I received my bachelor's and master's degrees from Beijing University of Posts and Telecommunications (BUPT) in 2017 and 2020, respectively.
My research interests lie at the intersection of software security and software engineering, with a particular focus on mobile security. I am especially interested in mobile app security, including app analysis, compliance checking, and ecosystem-wide characterization; as well as the emerging area of mobile agent security, including its attack surfaces and defenses. My work aims to improve the security, privacy, and trustworthiness of the mobile ecosystem at scale.
If you would like to reach me, please send an email to tmliu@hust.edu.cn
Publications
[# Co-first Author, * Corresponding Author, (s) Student I advised/co-advised during the work]
-
One Resource to Break Them All: Exploiting Malformed Resources for Permanent Denial-of-Service in Android
-
NotDec: WebAssembly Decompilation With Inter-Procedural Type Recovery
-
Mobile App Analysis in the New Era: Challenges and the Road Ahead
-
Doxing-as-a-Service: Demystifying the Chinese Online Doxing Ecosystem
-
An Empirical Study of Security Risks in the Android Push Notification Ecosystem
-
An Empirical Analysis of Rust Integration in Android Open Source Project
-
Reproducing UI Contexts Described in App Reviews with Large Language Models
-
LLMDroid: Enhancing Automated Mobile App GUI Testing Coverage with Large Language Model Guidance
-
Walls Have Ears: Demystifying Notification Listener Usage in Android Apps
-
Beyond App Markets: Demystifying Underground Mobile App Distribution Via Telegram
-
Are iOS Apps Immune to Abusive Advertising Practices?
-
The Arts and Crafts of Android Adware Across a Decade
-
Exploring Covert Third-party Identifiers through External Storage in the Android New Era
-
Same App, Different Behaviors: Uncovering Device-specific Behaviors in Android Apps
-
Towards Demystifying Android Adware: Dataset and Payload Location
-
A First Look at LLM-powered Smartphones
-
ChatGPT Chats Decoded: Uncovering Prompt Patterns for Superior Solutions in Software Development Lifecycle
-
WalletRadar: Towards Automating the Detection of Vulnerabilities in Browser-based Cryptocurrency Wallets
-
Are Mobile Advertisements in Compliance with App's Age Group?
-
Promal: Precise Window Transition Graphs for Android via Synergy of Program Analysis and Machine Learning
-
ATVHunter: Reliable Version Detection of Third-party Libraries for Vulnerability Identification in Android Applications
-
Research on Third-party Libraries in Android Apps: A Taxonomy and Systematic Literature Review
-
A Systematic Assessment on Android Third-party Library Detection Tools
-
MadDroid: Characterising and Detecting Devious Ad Content for Android Apps
-
Automated Third-party Library Detection for Android Applications: Are We There Yet?
-
DaPanda: Detecting Aggressive Push Notification in Android Apps
-
FraudDroid: Automated Ad Fraud Detection for Android Apps
The electronic versions of the papers listed on this webpage are provided for personal use. Copyright is owned by the respective publishers or persons, and should be included explicitly in any distribution of the papers.