Xiaohan Zhang

Dr. Xiaohan Zhang

Associate Professor · Fudan University

I work at the System Software & Security Lab, Fudan University. My research focuses on cybersecurity, including mobile application security, malware detection, and applied AI security. I obtained my B.Eng and Ph.D. at Fudan University under the supervision of Prof. Min Yang.

I have published papers as (co-)first author at the "Big Four" security venues, and received the NDSS 2025 Distinguished Paper Award, the USENIX Security 2022 Distinguished Paper Award, the USENIX Security 2025 Honorable Mention Award, and a CCS 2020 Distinguished Paper Award Nomination. My work on face verification security won the CNVD 2021 Most Valuable Vulnerability from the Chinese National Vulnerability Database.

I teach courses on deep learning foundations, system security, optimizing compilers, and attack-and-defense techniques. Students under my supervision have won the First Prize of the "Huawei Cup" China Postgraduate Network Security Innovation Competition, the Gold Award of DCIC 2025 (App Security Track), and the Second Prize of the National College Student Information Security Competition (2026), and their research projects have been funded by the School of Cybersecurity's Student Innovation Program (one concluded as "Excellent", top 5%).

I am always looking for highly-motivated undergraduate students interested in cybersecurity. Feel free to reach out at xh_zhang [AT] fudan.edu.cn.

News

Sep 2026
Our paper on login device management in Android apps has been accepted to NDSS 2027. Congrats to Jianzhou Chen!
Sep 2026
Our student research project funded by the School of Cybersecurity's Student Innovation Program concluded with an "Excellent" rating (top 5%) — congrats to Yujia Ma and Yuhan Gu! A new project by Wenjie Yang has also been awarded funding from the program.
Aug 2026
I was selected for a "Noteworthy Reviewer Recognition" for USENIX Security 2026 Artifact Evaluation.
Aug 2026
Our team won the Second Prize in the National College Student Information Security Competition (Works Track).
Jun 2026
All three 2023-cohort master students have successfully graduated! Congrats! See where they go.
Dec 2025
Our paper on Cross-Device Authentication (XDAuth) Usability has been accepted to NDSS 2026. Congrats to Xin Zhang and Huijun Zhou.
Aug 2025
Our paper QRLChecker won the USENIX Security 2025 Honorable Mention Award.
Jul 2025
The Face Verification Security student research project I supervised has been awarded funding from the School of Cybersecurity's Student Innovation Program. Congrats to Yujia Ma and Yuhan Gu!
Apr 2025
Our team won the Gold Award in the App Security Track of the Digital China Innovation Contest (DCIC 2025). Congrats to Xin Zhang, Bo Zhao, and Huijun Zhou!
Mar 2025
Our work on QRLogin security (Security '25 paper) has been selected as one of the "CAPPVD 2024 Outstanding Cases of Mobile App Vulnerability Management".
Feb 2025
Our paper on Fingerprint API Security won the NDSS 2025 Distinguished Paper Award! Congrats to Xin and all authors!
Jan 2025
Our paper on QR code authentication security has been accepted to USENIX Security 2025. Congrats to Xin Zhang!
Aug 2024
Two papers accepted to NDSS 2025. Congrats to Xin Zhang and Yizhe Shi!
Older news (2024 – 2022)
Jun 2024
All three master students (2021 cohort) have successfully graduated! See where they go.
May 2023
A white paper on AI security standards, where I am one of the drafters, was published!
Apr 2023
Our paper on face verification security, named XFVSChecker, was accepted by IEEE S&P 2023!
Mar 2023
Yang Wang received offers from CMU and GT. Congrats to her!
Jan 2023
All four master students (2020 cohort) have successfully graduated! See where they go.
Dec 2022
Our team won 1st prize in the China Graduate Network Security Innovation Competition. Congrats to Ziqi Huang, Liang Niu, Zhichen Liu, and Haoqi Ye! I received the Excellent Advising Teacher Award.

Background

2023 — Present
Fudan University, Associate Professor
2020 — 2022
Fudan University, School of Computer Science, PostDoc
2014 — 2020
Fudan University, School of Computer Science, Ph.D.
2010 — 2014
Fudan University, Software School, B.Eng.

Publications

2027

When Scene Text Hijacks the Scene: Uncovering, Exploiting, and Mitigating Rendered-Text Semantic Leakage in Image Generation Models.
Feifei Li, Runjie Wang, Xiaohan Zhang, Zhenxing Qian, Mi Wen, Mi Zhang. In Proceedings of the 48th IEEE Symposium on Security and Privacy (S&P 2027).
Hiding in Plain Sight: A Diffusion-based Mitigation of Geolocation Privacy Leakage in Vision–Language Models.
Yining Wang, Xi Li, Mi Zhang, Xiaohan Zhang, Xiaoyu You, Zhenxing Qian, Mi Wen. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2027).
Understanding Login Device Management in Real-world Android Apps: Landscape, Robustness and Security Risks.
Jianzhou Chen, Xiaohan Zhang, Yujia Ma, Min Yang. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2027).

2026

Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication.
Xin Zhang, Xiaohan Zhang✉, Huijun Zhou, Bo Zhao. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2026), San Diego.
Foot in the Door: Uncovering the Multi-Step Authorization Exploitation in Mobile Applications.
Yizhe Shi, Zhemin Yang, Qiaodan Hou, Lukai Cui, Cheng Sheng, Xiaohan Zhang, Min Yang. In Proceedings of the 33rd ACM Conference on Computer and Communications Security (CCS 2026).
SEW: Strengthening Robustness of Black-box DNN Watermarking via Specificity Enhancement.
Huming Qiu, Mi Zhang✉, Junjie Sun, Peiyi Chen, Xiaohan Zhang✉, Min Yang. The SIGKDD Conference on Knowledge Discovery and Data Mining (KDD 2026), Jeju, Korea.
ActivationBackdoor: Backdooring Large Language Models in Collaborative Inference via Intermediate Activations.
Zichun Su, Mi Zhang, Xiaohan Zhang, Geng Hong, Xiaoyu You, Min Yang. The 32nd SIGKDD Conference on Knowledge Discovery and Data Mining (KDD 2026).
3D-ANC: Adaptive Neural Collapse for Robust 3D Point Cloud Recognition.
Yuanmin Huang, Wenxuan Li, Mi Zhang, Xiaohan Zhang, Xiaoyu You, Min Yang. The 40th AAAI Conference on Artificial Intelligence (AAAI 2026).

2025

The Future Unmarked: Watermark Removal in AI-Generated Images via Next-Frame Prediction.
Huming Qiu, Zhaoxiang Wang, Mi Zhang, Xiaohan Zhang, Xiaoyu You, Min Yang. The 39th Annual Conference on Neural Information Processing Systems (NeurIPS 2025).
Demystifying the (In)Security of QR Code-based Login in Real-world Deployments.
Xin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan, Zhichen Liu, Jianzhou Chen, Huijun Zhou, Min Yang. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 2025), Seattle, WA.·Honorable Mention Award·17 CNVD & 25 NVDB IDs·CAPPVD 2024 Outstanding Cases·[Paper]
An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android Apps.
Xin Zhang★, Xiaohan Zhang★, Zhichen Liu, Bo Zhao, Zhemin Yang, Min Yang. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2025), San Diego.·Distinguished Paper Award·184 CVE & 19 CNVD IDs·[Paper]
The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps.
Yizhe Shi, Zhemin Yang, Kangwei Zhong, Guangliang Yang, Yifan Yang, Xiaohan Zhang, Min Yang. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2025), San Diego.·89 CVE IDs·[Paper]

2023

Understanding the (In)Security of Cross-side Face Verification Systems in Mobile Apps: A System Perspective.
Xiaohan Zhang, Haoqi Ye, Ziqi Huang, Xiao Ye, Yinzhi Cao, Yuan Zhang, Min Yang. In Proceedings of the 44th IEEE Symposium on Security and Privacy (S&P 2023), San Francisco, CA.·CNVD 2021 Most Valuable Vulnerability·[Paper] [Website] [National Standard] [White Paper]

2022

Slowing Down the Aging of Learning-based Malware Detectors with API Knowledge.
Xiaohan Zhang, Mi Zhang, Yuan Zhang, Ming Zhong, Xin Zhang, Yinzhi Cao, Min Yang. IEEE Transactions on Dependable and Secure Computing (TDSC).·[Paper]
Collect Responsibly but Deliver Arbitrarily? A Study on Cross-User Privacy Leakage in Mobile Apps.
Shuai Li, Zhemin Yang, Nan Hua, Peng Liu, Xiaohan Zhang, Guangliang Yang, Min Yang. In Proceedings of the 29th ACM Conference on Computer and Communications Security (CCS 2022).
Identity Confusion in WebView-based Mobile App-in-app Ecosystems.
Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang, Min Yang. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 2022), Boston, MA.·Distinguished Paper Award·[Paper]

2020

Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android Malware.
Xiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding, Yinzhi Cao, Yukun Zhang, Mi Zhang, Min Yang. In Proceedings of the 27th ACM Conference on Computer and Communications Security (CCS 2020), Orlando, FL.·Distinguished Paper Award Nomination (4/121)·AR 16.9% (121/715)·[Paper] [Website]
PDiff: Semantic-based Patch Presence Testing for Downstream Kernels.
Zheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen, Zhenghe Wang, Xiaohan Zhang, Xinyu Xing, Min Yang, Zhemin Yang. In Proceedings of the 27th ACM Conference on Computer and Communications Security (CCS 2020), Orlando, FL.·[Paper]
BScout: Direct Whole Patch Presence Test for Java Executables.
Jiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou, Junyan Chen, Xinyu Xing, Xiaohan Zhang, Xin Tan, Min Yang, Zhemin Yang. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 2020), Boston, MA.·[Paper]
How Android Developers Handle Evolution-induced API Compatibility Issues: A Large-scale Study.
Hao Xia, Yuan Zhang, Yingtian Zhou, Xiaoting Chen, Yang Wang, Xiangyu Zhang, Shuaishuai Cui, Gen Hong, Xiaohan Zhang, Min Yang, Zhemin Yang. In Proceedings of the 42nd International Conference on Software Engineering (ICSE 2020), Seoul, South Korea.·[Paper]

2018

An Empirical Study of Web Resource Manipulation in Real-world Mobile Applications.
Xiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia, Zhemin Yang, Min Yang, Xiaofeng Wang, Long Lu, Haixin Duan. In Proceedings of the 27th USENIX Security Symposium (USENIX Security 2018), Baltimore, MD.·AR 16.2% (113/697)·[Paper] [Dataset]
Detecting Third-Party Libraries in Android Applications with High Precision and Recall.
Yuan Zhang, Jiarun Dai, Xiaohan Zhang, Sirong Huang, Zhemin Yang, Min Yang, Hao Chen. In Proceedings of IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER 2018), Campobasso, Italy.·[Paper] [Source]

Pre-prints & Others

Understanding Privacy Over-collection in WeChat Sub-app Ecosystem.
2023.·[arXiv]
MiniBot: A Lightweight Dynamic Test Input Generation Framework for Mini-Apps [in Chinese].
Journal of Chinese Computer Systems, 2024.

Awards

Paper Awards

  • NDSS 2025 Distinguished Paper Award
  • USENIX Security 2025 Honorable Mention Award
  • USENIX Security 2022 Distinguished Paper Award
  • ACM CCS 2020 Distinguished Paper Award Nomination

Science & Technology Awards

  • Shanghai Decision-Making Consultation Achievement Award, First Prize, 2025
  • Shanghai Technical Invention Award, First Prize, 2024
  • CCF Natural Science Award, Second Prize, 2021
  • SCS Natural Science Award, First Prize, 2021
  • Huawei Outstanding Technical Achievement Award, 2020

Vulnerability Recognition

  • CAPPVD 2024 Outstanding Cases of Mobile App Vulnerability Management
  • CNVD 2021 Most Valuable Vulnerability

Competitions & Honors

  • Gold Award — App Security Track, Digital China Innovation Contest (DCIC 2025)
  • Excellent Instructor — "Huawei Cup" China Postgraduate Network Security Innovation Competition, 2021

Services

Conference Reviewer

USENIX Security 2026, 2027 · SecureComm 2023 · AsiaCCS 2021 · EuroS&P 2021 · CODASPY 2021 · CCS 2019, 2018

Journal Reviewer

TOSEM 2026 · TOPS 2024 · JCST 2023 · TMC 2021 · JCRD 2021 · COSE 2021, 2020, 2019 · TDSC 2020

Expert

Mobile Product Vulnerability Database (CAPPVD) and AI Vulnerability Database (CAIVD), MIIT NVDB

Teaching

Students

Current

  • 2026: Hongyuan Pan (PhD), Shaoyu Tang, Yanqi Sun
  • 2025: Xiangjing Zhang, Haozhe Zhang, Wenjie Yang (Innovation Program)
  • 2024: Huijun Zhou, Xihua Shen, Yutao Shi, Yujia Ma (Tencent project & internship; Innovation Program — Excellent conclusion)
  • 2022: Xin Zhang (PhD; NDSS'25, Security'25, NDSS'26)

2023 — Graduated

  • Jianzhou Chen (NDSS'27) → CUHK
  • Bo Zhao → Gov
  • Yuhan Gu (Tencent project & internship; Innovation Program — Excellent conclusion) → Xiaohongshu

2022 — Graduated

2021 — Graduated

2020 — Graduated

2019 — Graduated

  • Ming Zhong (CCS'20) → Ant Group
  • Ruiqi Deng → Meituan

2018 — Co-advised

  • Rui He → Tencent