<?xml-model href='http://www.tei-c.org/release/xml/tei/custom/schema/relaxng/tei_all.rng' schematypens='http://relaxng.org/ns/structure/1.0'?><TEI xmlns="http://www.tei-c.org/ns/1.0">
	<teiHeader>
		<fileDesc>
			<titleStmt><title level='a'>SaTS '24: The 2nd ACM Workshop on Secure and Trustworthy Superapps</title></titleStmt>
			<publicationStmt>
				<publisher>ACM</publisher>
				<date>12/02/2024</date>
			</publicationStmt>
			<sourceDesc>
				<bibl> 
					<idno type="par_id">10601274</idno>
					<idno type="doi">10.1145/3658644.3691542</idno>
					
					<author>Zhiqiang Lin</author><author>Luyi Xing</author>
				</bibl>
			</sourceDesc>
		</fileDesc>
		<profileDesc>
			<abstract><ab><![CDATA[Mobile super apps are revolutionizing mobile computing by offering diverse services through integrated "miniapps'', creating comprehensive ecosystems akin to app stores like Google Play and Apple's App Store. While these platforms, such as WeChat, Alipay, and TikTok, enhance user convenience and functionality, they also raise significant security and privacy concerns due to the vast amounts of user data they handle. In response, the Workshop on Secure and Trustworthy Superapps (SaTS 2024) aims to address these critical issues by fostering collaboration among researchers and practitioners to explore solutions that protect users and enhance security within the super app landscape.]]></ab></abstract>
		</profileDesc>
	</teiHeader>
	<text><body xmlns="http://www.tei-c.org/ns/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink">
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1">Introduction</head><p>Mobile super apps represent a transformative shift in mobile computing. These platforms, oering a wide array of services through integrated "miniapps," have experienced rapid growth in recent years. Miniapps, functioning similarly to native apps, enable super apps to build comprehensive ecosystems, much like Google Play or the Apple App Store. This ecosystem not only expands the super app's capabilities but also provides users with enhanced convenience and seamless functionality.</p><p>However, the rise of popular super apps like WeChat, Alipay, Tik-Tok, and Grab has led to the generation, storage, and transmission of vast amounts of user data. The integration of numerous services within a single platform amplies security and privacy risks, drawing the attention of users, researchers, and regulators alike.</p><p>These challenges underline the growing need for robust privacy protections and secure practices within the super app landscape.</p><p>In response to these developments, the Workshop on Secure and Trustworthy Superapps (SaTS 2024), co-located with ACM CCS 2024, oers a timely platform for addressing the pressing security and privacy challenges posed by super apps. As these apps become essential tools for communication, entertainment, and commerce, they also introduce signicant risks. SaTS 2024 aims to bring together researchers and practitioners to discuss these issues and explore solutions that benet the security community, industry, and society. The workshop's primary goal is to highlight these concerns and create a collaborative environment for knowledge sharing and problem-solving.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2">Workshop Format</head><p>SaTS '24 is a full-day workshop held alongside ACM CCS 2024, featuring a diverse range of contributions, including research papers, short/work-in-progress papers, and invited talks. The event brings together authors, organizers, and participants, creating an engaging space for knowledge exchange and collaboration. In particular, SaTS '24 oers a platform for two distinct categories of papers:</p><p>&#8226; Regular Papers (up to 8 pages): These papers present original research that has not been previously published or submitted concurrently elsewhere. &#8226; Short Papers or Work-in-Progress Papers (up to 4 pages):</p><p>This category accommodates papers that focus on fostering discussion, collaboration, and the sharing of preliminary research activities, work in progress, and industrial innovations.</p><p>The event is further enhanced by three keynote talks from experts, covering topics from miniapp standardization, data protection and access control, and malicious software in the ecosystems, oering broader context and sparking discussions. These talks deepen the workshop's insights and highlight ways to address challenges and opportunities in secure and trustworthy superapps.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3">Topics of Interest</head><p>Topics of interest include (but are not limited to) the following.</p><p>&#8226; Privacy-preserving techniques for mobile super apps (including their miniapps)</p><p>&#8226; Security analysis of mobile super app ecosystems &#8226; Authentication and authorization mechanisms for super apps &#8226; Data protection and secure storage in super apps &#8226; Privacy policies, compliance, and regulations for mobile super apps &#8226; User behavior and privacy risk analysis &#8226; Surveillance and censorship in mobile super apps &#8226; Anonymity and pseudonymity in miniapp communication &#8226; Security and privacy issues in third-party integrations &#8226; Secure payment systems in mobile super apps &#8226; Case studies and real-world experiences with mobile super app security and privacy In addition, topics of interest include, but are not limited to other emerging paradigms in mobile and ubiquitous computing. 4 Workshop Organizers Zhiqiang Lin is a Distinguished Professor of Engineering, and the director of Institute for Cybersecurity and Digital Trust (ICDT) at The Ohio State University. His research focuses on developing automated program analysis techniques for vulnerability discovery and malware analysis, as well as hardening systems and software using binary code rewriting, virtualization, and trusted execution environments. He has published over 150 papers on these and related topics. Recently, his team has been intensively studying the security and privacy of mobile super apps, and currently is ranked #2 worldwide in Tencent's security hall of fame He is an IEEE Fellow, and ACM Distinguished Member and has received numerous awards, including the NSF CAREER award, the AFOSR YIP award, Harrison Award for Excellence in Engineering Education, and Outstanding Teaching Award. He received his Ph.D. in Computer Science from Purdue University. He has been involved in organizing multiple conferences and workshops. This includes being program co-chairs for SE-CURECOMM'22, AsiaCCS'21, ISC'19, FEAST'10, local arrangement chair for CCS'17, and steering committee member for RAID and ISC. Luyi Xing is an Associate Professor of Computer Science at Indiana University Bloomington. He is a recipient of NSF CAREER award (2021), Facebook Research Award (2021, Privacy Enhancing Technologies), 5 Facebook Whitehat awards <ref type="bibr">(2012,</ref><ref type="bibr">2013,</ref><ref type="bibr">2020,</ref><ref type="bibr">2021)</ref>, Google Developer Data Protection award (2019), Microsoft Whitehat award (2019), Android Security Acknowledgements <ref type="bibr">(2013</ref><ref type="bibr">-2016</ref><ref type="bibr">, 2018</ref><ref type="bibr">), Apple Security Acknowledgement (2015</ref><ref type="bibr">, 2019</ref><ref type="bibr">, 2020)</ref>, among others. His research focus includes formal methods and guarantees for security and privacy-compliance in systems, in particular, IoT, cloud, mobile, and software supply chain. His research is known to impact security design of hundreds of operating system modules, applications, online/network services that almost everyone uses everyday, with the discovery of 50+ new types of vulnerabilities, uncovering new attack techniques and undermining modern security guarantees/assumptions. His works have been published almost exclusively at top-tier security venues. He is a co-founder and cochair of the Workshop on Security and Privacy in Standardized IoT co-located with NDSS 2024 and 2025.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="5">Committee</head><p>We highly appreciate the eorts of our Steering and Program Committees and would like to thank all members for their support.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>Steering Committee</head><p>&#8226; Zhiqiang Lin (The Ohio State University) &#8226; Luyi Xing (Indiana University Bloomington)</p><p>&#8226; Adam Doupe (Arizona State University) &#8226; Nick Nikiforakis (Stony Brook University) &#8226; Ben Stock (CISPA Helmholtz Center for Information Security) Technical Program Committee Chairs &#8226; Zhiqiang Lin (The Ohio State University) &#8226; Luyi Xing (Indiana University Bloomington) Technical Program Committee &#8226; Adwait Nadkarni (William &amp; Mary) &#8226; Aurore Fass (CISPA Helmholtz Center for Information Security) &#8226; Ding Li (Peking University) &#8226; Daniel Luo (The Hong Kong Polytechnic University) &#8226; Haoyu Wang (Huazhong University of Science and Technology) &#8226; Jianyi Zhang (Beijing Electronic Science and Technology Institute) &#8226; Omar Alrawi (Georgia Institute of Technology) &#8226; Soteris Demetriou (Imperial College London) &#8226; Wei You (Renmin University of China) &#8226; Yanjie Zhao (Monash University) &#8226; Yue Xiao (IBM Research) &#8226; Yuan Zhang (Fudan University) &#8226; Yue Zhang (The Ohio State University) &#8226; Yuhong Nan (Sun Yat-sen University) &#8226; Kaushal Kae (University of South Florida) Publicity Chair &#8226; Yue Xiao (IBM Research)</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="6">Workshop Statistics</head><p>In its second edition, the workshop received a total of four submissions. All four submissions were accepted for inclusion in the workshop proceedings, comprising two full-length research papers and two works-in-progress papers. A noteworthy aspect of this edition was our deliberate choice to adopt a more inclusive stance on paper acceptance. This decision aligns with our primary objective of creating an environment that fosters open and inclusive discussions. By adopting a more inclusive acceptance policy, we aimed to embrace a diverse range of ideas and encourage active participation from all contributors. We are eager to build upon this foundation in future editions as we continue to foster insightful and inclusive discussions within our academic community.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="7">Acknowledgement</head><p>We extend our sincere gratitude to the organizing committee of ACM CCS 2024 for graciously accepting and hosting our workshop, as well as for their invaluable support. We also appreciate all committee members for generously dedicating their time and expertise, which have greatly enriched the workshop's quality and impact. Last but not least, we would like to thank the authors and attendees for their contributions and participation. This work is partially supported by grants from the National Science Foundation (CNS-2330264 and CNS-2330265).</p></div>		</body>
		</text>
</TEI>
