Xiaofeng Liu (刘晓峰)
About me
I am a postdoctoral fellow at Shandong University. I received my Ph.D. degree from Shandong University, advised by Shanqing Guo and Jianliang Wu. Before my Ph.D. study, I got my Bachelor’s degree from Shandong University. My research centers on System Security (especially on protocol) at both the design and implementation levels, by combining reverse engineering and formal analysis to improve the security and privacy of real-world network services.
Publications
“Tap” Without Tapping: A Tag Discovery Forgery Attack on Android NFC
Yilin Li, Jianliang Wu(✉️), Chaoshun Zuo, Qingchuan Zhao, Xiaofeng Liu(✉️), Xiangpu Song, Chengyu Hu, Shanqing Guo(✉️). In Proceedings of the USENIX Security Symposium (Security), 2026
SGAFuzzer: Stateful GraphQL API fuzzing
Jingge Sun, Xiangpu Song(✉️), Xiaofeng Liu, Shanqing Guo(✉️), Chengyu Hu. Software Quality Journal, 2026
Formal Analysis Framework for E2EE Protocols
Yu Wang, Xiaofeng Liu(✉️), Yu Hou, Chengyu Hu(✉️), Shanqing Guo. In Proceedings of the ACM ASIA Conference on Computer and Communications Security (Asia CCS), 2026
ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu(✉️), Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu(✉️), Qingchuan Zhao, Shanqing Guo(✉️). In Proceedings of the Network and Distributed System Security Symposium (NDSS), 2026
A Thorough Security Analysis of BLE Proximity Tracking Protocols
Xiaofeng Liu, Chaoshun Zuo, Qinsheng Hou, Pengcheng Ren, Jianliang Wu(✉️), Qingchuan Zhao(✉️), and Shanqing Guo(✉️). In Proceedings of the USENIX Security Symposium (Security), 2025 [PDF]
DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile Apps
Pengcheng Ren, Chaoshun Zuo, Xiaofeng Liu, Wenrui Diao, Qingchuan Zhao(✉️), Shanqing Guo(✉️). In Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), 2024
Security Research for Android Remote Assistance Apps
Liwei Wang, Xiaofeng Liu, Ting Lei, Wenna Song, Shanqing Guo(✉️), Pengcheng Ren. In Proceedings of the Australasian Conference on Information Security and Privacy (ACISP), 2024
Can We Trust the Phone Vendors? Comprehensive Security Measurements on the Android Firmware Ecosystem
Qinsheng Hou, Wenrui Diao, Yanhao Wang, Chenglin Mao, Lingyun Ying, Song Liu, Xiaofeng Liu, Yuanzhi Li, Shanqing Guo(✉️), Meining Nie, and Haixin Duan. In Proceedings of the IEEE Transactions on Software Engineering (TSE), 2023
ATTAA: Active Text Traffic Analysis Attacks on Secure Messaging Applications
Fengyan Lv, Cheng Liu, Xiaofeng Liu, Chengyu Hu, Zhihao Chen, Shanqing Guo(✉️). In Proceedings of the IEEE International Conference on Communications (ICC), 2023
Large-scale Security Measurements on the Android Firmware Ecosystem
Qinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu, Song Liu, Lingyun Ying, Shanqing Guo(✉️), Yuanzhi Li, Meining Nie, and Haixin Duan. In Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), 2022
Projects and Competitions
- MiSRC 2024年度获奖白帽
- 白帽新人王 ¥18888
- 华为杯 2022 第一届中国研究生网络安全创新大赛
- 二等奖 ¥5000
- DataCon 2021 大数据安全分析竞赛
- 软件供应链及物联网安全赛道:第7名
Vulnerabilities and Acknowledgments
- 累计漏洞奖金
- 人民币:中兴:800元,Vivo:17,100元,Oppo:2,000元,华为:14,000元,魅族:260元,小米:104,000元
- 美元:三星:6,660美元,谷歌:7,000美元
- Acknowledgments (厂商致谢)
- CVE
- 2026 (2): CVE-2026-0081(High, $7,000), CVE-2026-11535(CRITICAL: 9.4, ¥13,500), CVE-2026-12058
- 2025 (2): CVE-2025-20899, CVE-2025-2818
- 2024 (2): CVE-2024-45347(CRITICAL: 9.6, ¥25,000), CVE-2024-45361
- 2021 (5): CVE-2021-22486(HIGH, ¥10000), CVE-2021-26281, CVE-2021-26279, CVE-2021-21742, CVE-2021-3720
- CNVD
- 2026 (4): CNVD-2026-06588, CNVD-2026-06591, CNVD-2026-06703, CNVD-2026-11521
- 2025 (3): CNVD-2025-05845, CNVD-2025-05846, CNVD-2025-11062
- 2023 (5): CNVD-2023-60618, CNVD-2023-52830, CNVD-2023-52831, CNVD-2023-59491, CNVD-2023-59021
- 2021 (27): CNVD-2021-50158, CNVD-2021-42966, CNVD-2021-42949, CNVD-2021-44383, CNVD-2021-44382, CNVD-2021-48937, CNVD-2021-50157, CNVD-2021-42965, CNVD-2021-42964, CNVD-2021-42963, CNVD-2021-46708, CNVD-2021-48955, CNVD-2021-40258, CNVD-2021-37375, CNVD-2021-41512, CNVD-2021-40261, CNVD-2021-40262, CNVD-2021-37377, CNVD-2021-44691, CNVD-2021-40254, CNVD-2021-40255, CNVD-2021-40721, CNVD-2021-40259, CNVD-2021-41513, CNVD-2021-40256, CNVD-2021-40257, CNVD-2021-67925
- SVE
- 2024 (1): SVE-2024-1883(same as CVE-2025-20899)
- 2022 (5): SVE-2022-1176, SVE-2022-1177(Moderate, $800), SVE-2022-1178(HIGH, $2500), SVE-2022-1179(HIGH, $2500), SVE-2022-1180
