Who's reading?
Eric H. Deng

Hi, I'm Eric H. (Haotian) Deng.

I study how Android hands out power — and how to take it back without asking nicely. 110+ vulnerabilities found, and counting.

I'm a graduate student in Cyberspace Security at the University of Electronic Science and Technology of China (UESTC), advised by Prof. Hongwei Li. I earned my B.E. from the School of Cyberspace Security at Beijing University of Posts and Telecommunications (BUPT) in 2024, working with Prof. Shengli Pan.

My research lives in software and systems security, centered on the Android permission model — the machinery that decides which app may do what, and all the ways that machinery can be talked into saying yes when it should say no. I'm also drawn to AI-for-security.

⚡ Try to hack Eric →

News

Research

Android decides what an app can access — your location, camera, messages, and much more — through its permission system. My work looks for gaps between what that system promises and what it actually enforces. So far, that exploration has led to more than 110 reported security issues across Android's permission mechanisms and related components.

Want to see what these look like? I keep a demo rig where the target is, fittingly, me. ⚡ Try to hack Eric →

Hack Eric

Enough reading. Here's a small interactive demo: you're the attacker, and my phone is the target. Type a command or click an exploit. All targets are Eric. No actual humans (or presidents) were harmed.

This part is an interactive terminal — enable JavaScript to try the pentest. (Everything else on this page works fine without it.)

Publications

Before Android had my full attention, I spent about a year each on secure multi-party computation and on network tomography — one paper apiece, and a lot of respect for how hard both fields are.

Beyond Work

Contact

Say hi — I like meeting people who read this far.