Our paper on detecting access control flaws in Android firmware has been accepted to NDSS 2027!
Thrilled to share our latest work!
Act and do not contend.
Currently, I study how Android hands out power and how to take it back.
Recent updates and milestones.
Thrilled to share our latest work!
Began disclosing flaws in pre-installed Android apps — 140+ reports so far.
SecInfer and MADU accepted to IEEE ICC 2025.
Started my M.S. at UESTC, advised by Prof. Hongwei Li.
Received my B.Eng. in Information Security from BUPT.
ENBT-BA accepted to IEEE GLOBECOM 2023.
I'm broadly interested in systems and security, with a current focus on Android security, privilege management, and how AI can help build more secure software systems.
Selected papers and academic work.
View full listBeyond Sensitive APIs: Detecting Access Control Flaws at Sensitive Callsites in Android Firmware
NDSS 2027
SecInfer: Secure and Efficient Model Inference on Vertically Partitioned Data
IEEE ICC 2025
Making Audio Data Unlearnable
IEEE ICC 2025
Evaluating Network Boolean Tomography under Byzantine Attacks
IEEE GLOBECOM 2023
An interactive exploit demo.
Enough reading. Here's a small interactive demo: you're the attacker, and my phone is the target. Type a command or click an exploit. All targets are Haotain. No actual humans (or presidents) were harmed.
This part is an interactive terminal — enable JavaScript to try the pentest. (Everything else on this page works fine without it.)
A little more about me.
Hi, I'm Haotian Deng (Haotian — like how + tyen).
I'm a graduate student in Cyberspace Security at the University of Electronic Science and Technology of China (UESTC), where I'm fortunate to be advised by Prof. Hongwei Li and to benefit greatly from the guidance of Prof. Chaoshun Zuo. I earned my B.E. from the School of Cyberspace Security at Beijing University of Posts and Telecommunications (BUPT) in 2024.
My research lives in software and systems security, centered on the Android permission model — the machinery that decides which app may do what, and all the ways that machinery can be talked into saying yes when it should say no. I'm also drawn to AI for security.
Android decides what an app can access — your location, camera, messages, and much more — through its permission system. My work looks for gaps between what that system promises and what it actually enforces. So far, that exploration has led to 140+ reported security issues across Android's permission mechanisms and related components.
Before Android had my full attention, I spent about a year each on secure multi-party computation and on network tomography — one paper apiece, and a lot of respect for how hard both fields are.
Say hi — I like meeting people who read this far. haotian.deng@ieee.org