{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:02:09Z","timestamp":1780588929821,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785378","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1200-1212","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["CRX-ray: Large-Scale Detection of API Key Leakage in Browser Extensions"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-7002-4874","authenticated-orcid":false,"given":"Wei","family":"Zeng","sequence":"first","affiliation":[{"name":"School of Computer Science and Informatics, University of Liverpool, Liverpool, Merseyside, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3252-9254","authenticated-orcid":false,"given":"Zhi","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, Nankai University, TianJin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5692-3952","authenticated-orcid":false,"given":"Valerio","family":"Bucci","sequence":"additional","affiliation":[{"name":"Queen's University Belfast, Belfast, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3842-9366","authenticated-orcid":false,"given":"Xiaoyu","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, Nankai University, TianJin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1356-6631","authenticated-orcid":false,"given":"Xin","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, Nankai University, TianJin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7112-8550","authenticated-orcid":false,"given":"Siyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, Nankai University, TianJin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5535-2420","authenticated-orcid":false,"given":"Yuejun","family":"Guo","sequence":"additional","affiliation":[{"name":"Luxembourg Institute of Science and Technology, Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6396-9578","authenticated-orcid":false,"given":"Wanpeng","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Informatics, University of Liverpool, Liverpool, Merseyside, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"API Reference - OpenAI API. https:\/\/platform.openai.com\/docs\/api-reference\/authentication. Accessed","year":"2025","unstructured":"2025. API Reference - OpenAI API. https:\/\/platform.openai.com\/docs\/api-reference\/authentication. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_2_1","volume-title":"Rate Limits. https:\/\/platform.openai.com\/docs\/guides\/rate-limits. Accessed","year":"2025","unstructured":"2025. Rate Limits. https:\/\/platform.openai.com\/docs\/guides\/rate-limits. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_3_1","volume-title":"https:\/\/sites.google.com\/view\/crx-ray. Accessed","year":"2025","unstructured":"2025. CRX_ray. https:\/\/sites.google.com\/view\/crx-ray. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560685"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380113"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-6261.1968.tb00843.x"},{"key":"e_1_3_2_1_7_1","volume-title":"Modern Generative AI with ChatGPT and OpenAI Models: Leverage the capabilities of OpenAI's LLM for productivity and innovation with GPT3 and GPT4","author":"Alto Valentina","unstructured":"Valentina Alto. 2023. Modern Generative AI with ChatGPT and OpenAI Models: Leverage the capabilities of OpenAI's LLM for productivity and innovation with GPT3 and GPT4. Packet Publishing, Birmingham, UK."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1995376.1995398"},{"key":"e_1_3_2_1_9_1","volume-title":"Network and Distributed System Security Symposium. Internet Society","author":"Barth Adam","year":"2010","unstructured":"Adam Barth, Adrienne Porter Felt, Prateek Saxena, and Aaron Boodman. 2010. Protecting Browsers from Extension Vulnerabilities. In Network and Distributed System Security Symposium. Internet Society, San Diego, California, USA."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev53368.2022.00026"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC3986"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-49187-0_10"},{"key":"e_1_3_2_1_13_1","volume-title":"Detection of Inconsistencies in Privacy Practices of Browser Extensions. In 44th IEEE Symposium on Security and Privacy, SP 2023","author":"Bui Duc","year":"2023","unstructured":"Duc Bui, Brian Tang, and Kang G. Shin. 2023. Detection of Inconsistencies in Privacy Practices of Browser Extensions. In 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023. IEEE, 2780\u20132798."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46669-8_21"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860481"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243823"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CONISOFT52520.2021.00036"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477314.3507098"},{"key":"e_1_3_2_1_19_1","volume-title":"Accessed","author":"Faiz Shakeel","year":"2025","unstructured":"Shakeel Faiz. 2025. CRX File Format - Google Chrome Extension. https:\/\/docs.fileformat.com\/misc\/crx\/. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484745"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510150"},{"key":"e_1_3_2_1_22_1","volume-title":"Accessed","year":"2025","unstructured":"GitHub. 2025. About secret scanning - GitHub Docs. https:\/\/docs.github.com\/en\/code-security\/secret-scanning\/about-secret-scanning. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384745"},{"key":"e_1_3_2_1_24_1","volume-title":"Accessed","year":"2025","unstructured":"Google. 2025. What Is API Management? https:\/\/cloud.google.com\/learn\/what-is-api-management. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_25_1","volume-title":"Verified Security for Browser Extensions. In 2011 IEEE Symposium on Security and Privacy. 115\u2013130","author":"Guha Arjun","year":"2011","unstructured":"Arjun Guha, Matthew Fredrikson, Benjamin Livshits, and Nikhil Swamy. 2011. Verified Security for Browser Extensions. In 2011 IEEE Symposium on Security and Privacy. 115\u2013130."},{"key":"e_1_3_2_1_26_1","unstructured":"Sheryl Hsu Manda Tran and Aurore Fass. 2024. What is in the Chrome Web Store?. In AsiaCCS. https:\/\/publications.cispa.saarland\/4057\/"},{"key":"e_1_3_2_1_27_1","volume-title":"Accessed","author":"IBM.","year":"2025","unstructured":"IBM. 2025. What is a REST API? https:\/\/www.ibm.com\/topics\/rest-apis. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_28_1","volume-title":"d.]. XPI - Cross-platform Installer Package File=. https:\/\/docs.fileformat.com\/compression\/xpi\/. Accessed","author":"Iqbal Kashif","year":"2025","unstructured":"Kashif Iqbal. [n. d.]. XPI - Cross-platform Installer Package File=. https:\/\/docs.fileformat.com\/compression\/xpi\/. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_29_1","volume-title":"Accessed","author":"Jina","year":"2025","unstructured":"Jina AI. 2025. JinaChat - API Access. https:\/\/chat.jina.ai\/api. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_30_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Kim Young Min","year":"2023","unstructured":"Young Min Kim and Byoungyoung Lee. 2023. Extending a Hand to Attackers: Browser Privilege Escalation Attacks via Extensions. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 7055\u20137071. https:\/\/www.usenix.org\/conference\/usenixsecuritty23\/presentation\/kim-young-min"},{"key":"e_1_3_2_1_31_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Krause Alexander","year":"2023","unstructured":"Alexander Krause, JanH. Klemmer, Nicolas Huaman, DominikWermke, Yasemin Acar, and Sascha Fahl. 2023. Pushed by Accident: A {Mixed-Methods} Study on Strategies of Handling Secret Information in Source Code Repositories. In 32nd USENIX Security Symposium (USENIX Security 23). 2527\u20132544. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/krause"},{"key":"e_1_3_2_1_32_1","unstructured":"R.S. Liverani and N. Freeman. 2009. Abusing firefox extensions. In Defcon17."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2014.143"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2111"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Michael Meli Matthew R McNiece and Bradley Reaves. 2019. How bad can it git? characterizing secret leakage in public github repositories. In NDSS.","DOI":"10.14722\/ndss.2019.23418"},{"key":"e_1_3_2_1_36_1","volume-title":"Accessed","year":"2025","unstructured":"Mozilla. 2025. <iframe>: The Inline Frame element - HTML: HyperText Markup Language | MDN \u2014 developer.mozilla.org. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTML\/Element\/iframe. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23092"},{"key":"e_1_3_2_1_38_1","volume-title":"Accessed","author":"Cloud NLP","year":"2025","unstructured":"NLP Cloud. [n. d.]. Advanced AI Platform. https:\/\/nlpcloud.com\/. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_39_1","volume-title":"William Robertson, and Engin Kirda.","author":"Onarlioglu Kaan","year":"2015","unstructured":"Kaan Onarlioglu, Ahmet Salih Buyukkayhan, William Robertson, and Engin Kirda. 2015. SENTINEL: Securing Legacy Firefox Extensions. Computers & Security (2015), 147\u2013161."},{"key":"e_1_3_2_1_40_1","volume-title":"Accessed","author":"AI","year":"2025","unstructured":"OpenAI team. 2025. Text Generation Models. https:\/\/platform.openai.com\/docs\/guides\/text-generation. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423343"},{"key":"e_1_3_2_1_42_1","volume-title":"International Journal of Scientific & Technology Research 8 (12","author":"Prajapati Priteshkumar","year":"2019","unstructured":"Priteshkumar Prajapati, Nidhi Patel, and Parth Shah. 2019. A Review of Recent Detection Methods for HTTP DDoS Attacks. International Journal of Scientific & Technology Research 8 (12 2019), 1693\u20131696."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMSNETS48256.2020.9027350"},{"key":"e_1_3_2_1_44_1","volume-title":"Accessed","author":"Security Truffle","year":"2024","unstructured":"Truffle Security. 2024. Trufflehog. https:\/\/github.com\/trufflesecurity\/trufflehog. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_45_1","volume-title":"Accessed","author":"Security Truffle","year":"2024","unstructured":"Truffle Security. 2024. Trufflehog Detectors. https:\/\/github.com\/trufflesecurity\/trufflehog\/tree\/main\/pkg\/detectors. Accessed: August 20, 2025."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"e_1_3_2_1_47_1","volume-title":"Detecting and Mitigating Secret-Key Leaks in Source Code Repositories. In 2015 IEEE\/ACM 12th Working Conference on Mining Software Repositories. 396\u2013400","author":"Sinha Vibha Singhal","year":"2015","unstructured":"Vibha Singhal Sinha, Diptikalyan Saha, Pankaj Dhoolia, Rohan Padhye, and Senthil Mani. 2015. Detecting and Mitigating Secret-Key Leaks in Source Code Repositories. In 2015 IEEE\/ACM 12th Working Conference on Mining Software Repositories. 396\u2013400."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2637364.2592003"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-49187-0_9"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134632"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.2018.00040"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2736277.2741630"},{"key":"e_1_3_2_1_53_1","volume-title":"Threat modeling-A systematic literature review. Computers & security 84","author":"Xiong Wenjun","year":"2019","unstructured":"Wenjun Xiong and Robert Lagerstr\u00f6m. 2019. Threat modeling-A systematic literature review. Computers & security 84 (2019), 53\u201369."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616591"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2766498.2766499"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785378","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:24:27Z","timestamp":1780586667000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785378"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":55,"alternative-id":["10.1145\/3779208.3785378","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785378","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}