publications and talks

2025

  1. Black Hat
    Back to the Future: Hacking and Securing Connection-based OAuth Architectures in Agentic AI and Integration Platforms
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Yanxiang Bi, and Wing Cheong Lau
    Black Hat USA Briefings, 2025
  2. USENIX Security
    Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
    Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung, Wing Cheong Lau, and Julien Lecomte
    34th USENIX Security Symposium (USENIX Security 25), 2025
  3. OSW
    Cross-app OAuth Attacks in Integration Platforms: Mix-up Attacks Reloaded
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Julien Lecomte, and Wing Cheong Lau
    OAuth Security Workshop (OSW), 2025

2024

  1. Black Hat
    One Hack to Rule Them All: Pervasive Account Takeovers in Integration Platforms for Workflow Automation, Virtual Voice Assistant, IoT, & LLM Services
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Julien Lecomte, and Wing Cheong Lau
    Black Hat USA Briefings, 2024
  2. CCS
    SWIDE: A Semantic-aware Detection Engine for Successful Web Injection Attacks
    Ronghai Yang, Xianbo Wang, Kaixuan Luo, Xin Lei, Ke Li, and 2 more authors
    Proceedings ACM Conference on Computer and Communications Security (CCS), 2024
  3. ACNS
    Living a Lie: Security Analysis of Facial Liveness Detection Systems in Mobile Apps
    Xianbo Wang, Kaixuan Luo, and Wing Cheong Lau
    International Conference on Applied Cryptography and Network Security, 2024

2023

  1. Black Hat
    The Living Dead: Hacking Mobile Face Recognition SDKs with Non-Deepfake Attacks
    Xianbo Wang, Kaixuan Luo, and Wing Cheong Lau
    Black Hat USA Briefings, 2023
  2. TSE
    Effective Isolation of Fault-Correlated Variables via Statistical and Mutation Analysis
    Ming Wen, Zifan Xie, Kaixuan Luo, Xiao Chen, Yibiao Yang, and 1 more author
    IEEE Transactions on Software Engineering, 2023