My research in Security and Privacy of IoT, Mobile, and Cyber-Physical Systems focuses on identifying and mitigating security and privacy threats across IoT, mobile, embedded, and cyber-physical systems, including cross-application interactions, sensor-driven attacks, permission abuse, firmware vulnerabilities, and attacks on connected physical processes.
1. Security and Privacy of IoT and Smart-Home Ecosystems: We aim to examine security and privacy risks created by interactions among applications, devices, events, and users in an IoT ecosystem.Related publications:
- Zhaohui Wang, Bo Luo, and Fengjun Li. InteractionShield: Harnessing Event Relations for Interaction Threat Detection and Resolution in Smart Homes. In Annual Computer Security Applications Conference (ACSAC), December 8-12, 2025. (Distinguished Paper Award)
- Zhaohui Wang, Bo Luo, and Fengjun Li. PrivacyGuard: Exploring Hidden Cross-App Privacy Leakage Threats In IoT Apps. In the 25th Privacy Enhancing Technologies Symposium (PETS), Washington D.C., USA, July 2025.
- Javaria Ahmad, Fengjun Li, Razvan Beuran, and Bo Luo. Eunomia: A Real-time Privacy Compliance Monitor for Alexa Skills. In Annual Computer Security Applications Conference (ACSAC), 2024.
- Zhaohui Wang, Bo Luo, and Fengjun Li. Poster Abstract: SmartAppZoo: a Repository of SmartThings Apps for IoT Benchmarking. In ACM/IEEE International Conference on Internet of Things Design and Implementation (IoTDI), 2023. (Poster)
- Javaria Ahmad, Fengjun Li, and Bo Luo. IoTPrivComp: A Measurement Study of Privacy Compliance in IoT Apps. In European Symposium on Research in Computer Security (ESORICS), Copenhagen, Denmark, September 2022.
2. Mobile and Android Security: We study how mobile applications and smartphone capabilities can introduce stealthy and context-sensitive security threats.
Related publications:
- Ye Wang, Yuying Li, Bo Luo and Fengjun Li. When Side Channels Meet Covert Channels: A Practical Fully Sensor-Driven Attack Chain. In International Conference on Information and Communications Security (ICICS), Fukui, Japan, October 27-30, 2026.
- Ye Wang, Bo Luo, and Fengjun Li. Beyond Conventional Triggers: Auto-Contextualized Covert Triggers for Android Logic Bombs. In Network and Distributed System Security (NDSS) Symposium, February 23-27, 2026.
- Prashanthi Mallojula, Fengjun Li, Xiaojiang Du, and Bo Luo. Companion Apps or Backdoors? on the Security of Automotive Companion Apps. In European Symposium on Research in Computer Security (ESORICS), Bydgoszcz, Poland, September 2024.
- Prashanthi Mallojula, Javaria Ahmad, Fengjun Li, and Bo Luo. You Are (not) Who Your Peers Are: Identification of Potentially Excessive Permission Requests in Android Apps. In IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), October 2021.
3. Embedded system and firmware security: We aim to develop scalable analysis, execution, and vulnerability-discovery techniques for embedded and microcontroller software despite hardware dependencies and resource constraints.
Related publications:
- Wenqiang Li, Jiameng Shi, Fengjun Li, Jingqiang Lin, Wei Wang, and Le Guan. uAFL: Non-intrusive Feedback-driven Fuzzing for Microcontroller Firmware. In the 44th IEEE/ACM International Conference on Software Engineering (ICSE), Pittsburgh, PA, USA, May 21-29, 2022.
- Wenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi, and Fengjun Li. From Library Portability to Para-rehosting: Natively Executing Microcontroller Software on Commodity Hardware. In the Network and Distributed System Security Symposium (NDSS) 2021.
4. Cyber-physical and automotive system security: Understanding and defending against attacks that exploit the coupling between computation, communication, and physical processes in cyber-physical systems.
Related publications:
- Shen, Jiajun, Hao Tu, Fengjun Li, Morteza Hashemi, Di Wu, and Huazhen Fang. "Dual State-space Fidelity Blade (D-STAB): A Novel Stealthy Cyber-physical Attack Paradigm." In 2025 American Control Conference (ACC), pp. 3079-3084. IEEE, 2025.
- Abdulmalik Humayed, Fengjun Li, Jingqiang Lin, and Bo Luo. CANSentry: Securing CAN-Based Cyber-Physical Systems against Denial and Spoofing Attacks. In European Symposium on Research in Computer Security (ESORICS), 2020.
- Abdulmali Humayed, Jinqiang Lin, Fengjun Li, and Bo Luo. Cyber-Physical Systems Security -- A Survey. In IEEE Internet of Things Journal - Special Issue on Security and Privacy in Cyber-Physical Systems, PP(99):1-1, 2017.