Haotian
Deng

Act and do not contend.

Currently, I study how Android hands out power and how to take it back.

Haotian Deng
  • Program Analysis
  • Systems & Software Security
  • AI for Security
Currently in China
M.S. in Cyberspace Security
/ 01

News

Recent updates and milestones.

New

Our paper on detecting access control flaws in Android firmware has been accepted to NDSS 2027!

Thrilled to share our latest work!

  • Began disclosing flaws in pre-installed Android apps — 140+ reports so far.

  • SecInfer and MADU accepted to IEEE ICC 2025.

  • Started my M.S. at UESTC, advised by Prof. Hongwei Li.

/ 02

Research

I'm broadly interested in systems and security, with a current focus on Android security, privilege management, and how AI can help build more secure software systems.

Android Security

  • Permissions
  • Privilege Management
  • Mobile Systems

Access Control

  • Program Analysis
  • Vulnerability Detection
  • Security Policy

AI for Security

  • LLM for Security
  • Automated Auditing
  • Security × AI

Systems Security

  • Operating Systems
  • Software Analysis
  • Security Tooling
/ 03

Publications

Selected papers and academic work.

View full list
  1. 2027

    Beyond Sensitive APIs: Detecting Access Control Flaws at Sensitive Callsites in Android Firmware

    Haotian Deng, Meng Hao, Hanxiao Chen, Xinyuan Qian, Guowen Xu, Hongwei Li, Chaoshun Zuo

    NDSS 2027

  2. 2025

    SecInfer: Secure and Efficient Model Inference on Vertically Partitioned Data

    Haotian Deng, Hongwei Li, Hanxiao Chen, Meng Hao, Pengzhi Xing, Jia Hu, Rui Zhang, Wenbo Jiang

    IEEE ICC 2025

  3. 2025

    Making Audio Data Unlearnable

    Wenshu Fan, Hongwei Li, Wenbo Jiang, Haotian Deng

    IEEE ICC 2025

  4. 2023

    Evaluating Network Boolean Tomography under Byzantine Attacks

    Haotian Deng, Shengli Pan

    IEEE GLOBECOM 2023

/ 04

Hack Haotian

An interactive exploit demo.

Enough reading. Here's a small interactive demo: you're the attacker, and my phone is the target. Type a command or click an exploit. All targets are Haotain. No actual humans (or presidents) were harmed.

This part is an interactive terminal — enable JavaScript to try the pentest. (Everything else on this page works fine without it.)

/ 05

About

A little more about me.

Hi, I'm Haotian Deng (Haotian — like how + tyen).

I'm a graduate student in Cyberspace Security at the University of Electronic Science and Technology of China (UESTC), where I'm fortunate to be advised by Prof. Hongwei Li and to benefit greatly from the guidance of Prof. Chaoshun Zuo. I earned my B.E. from the School of Cyberspace Security at Beijing University of Posts and Telecommunications (BUPT) in 2024.

My research lives in software and systems security, centered on the Android permission model — the machinery that decides which app may do what, and all the ways that machinery can be talked into saying yes when it should say no. I'm also drawn to AI for security.

Android decides what an app can access — your location, camera, messages, and much more — through its permission system. My work looks for gaps between what that system promises and what it actually enforces. So far, that exploration has led to 140+ reported security issues across Android's permission mechanisms and related components.

Before Android had my full attention, I spent about a year each on secure multi-party computation and on network tomography — one paper apiece, and a lot of respect for how hard both fields are.

Beyond Work

  • I like singing, and I can happily lose an evening going down a rabbit hole of music.
  • I'm a stubborn believer in early nights and early mornings — 养生 (yǎngshēng).
  • I enjoy history and historical fiction, especially stories that play with time travel and alternate histories.
  • When life gets stressful, I sometimes read psychology and philosophy. I particularly enjoy Alfred Adler and Jean-Paul Sartre, who both make me think about what we can actually choose and do.

Say hi — I like meeting people who read this far. haotian.deng@ieee.org