Changlai Du

dblp:02/6435 · DBLP profile ↗
← Back
12ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0001-8888-7440ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2024 TriSAS: Toward Dependable Inter-SAS Coordination with Auditability
abstract
To facilitate dynamic spectrum sharing, the FCC has designated certified SAS administrators to implement their own spectrum access systems (SASs) that manage the shared spectrum usage in the novel CBRS band. As a premise, different SAS servers must conduct periodic inter-SAS coordination to synchronize service states and avoid allocation conflicts. However, SAS servers may inevitably stop service for regular upgrades, crash down, or even perform maliciously that deviate from the normal routines, posing a fundamental operation security problem --- the system shall be robust against these faults to guarantee secure and efficient spectrum sharing service. Unfortunately, the incumbent inter-SAS coordination mechanism, CPAS, is prone to SAS failures and does not support real-time allocation. Recent proposals that rely on blockchain smart contracts or state machine replication mechanisms to realize fault-tolerant inter-SAS coordination require all SASs to follow a unified allocation algorithm. They however face performance bottlenecks and cannot accommodate the current fact that different SASs hold their own proprietary allocation algorithms.
Shanghao Shi, Yang Xiao 0010, Changlai Du, Yi Shi 0001, Chonggang Wang, Robert Gazda, Y. Thomas Hou 0001, Eric William Burger, Luiz A. DaSilva, Wenjing Lou
AsiaCCS3
2024 SoK: Public Blockchain Sharding
abstract
Blockchain’s decentralization, transparency, and tamper-resistance properties have facilitated the system’s use in various application fields. However, the low throughput and high confirmation latency hinder the widespread adoption of Blockchain. Many solutions have been proposed to address these issues, including first-layer solutions (or on-chain solutions) and second-layer solutions (or off-chain solutions). Among the proposed solutions, the blockchain sharding system is the most scalable one, where the nodes in the network are divided into several groups. The nodes in different shards work in parallel to validate the transactions and add them to the blocks, and in such a way, the throughput increases significantly. However, previous works have not adequately summarized the latest achievements in blockchain sharding, nor have they fully showcased its state-of-the-art. Our study provides a systemization of knowledge of public blockchain sharding, including the core components of sharding systems, challenges, limitations, and mechanisms of the latest sharding protocols. We also compare their performance and discuss current constraints and future research directions.
Md Mohaimin Al Barat, Shaoyu Li, Changlai Du, Y. Thomas Hou 0001, Wenjing Lou
ICBC3
2024 AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous Credentials
Hexuan Yu, Changlai Du, Yang Xiao 0010, Angelos D. Keromytis, Chonggang Wang, Robert Gazda, Y. Thomas Hou 0001, Wenjing Lou
NDSS2
2024 EchoSensor: Fine-grained Ultrasonic Sensing for Smart Home Intrusion Detection
abstract
This article presents the design and implementation of a novel intrusion detection system, called EchoSensor, which leverages speakers and microphones in smart home devices to capture human gait patterns for individual identification. EchoSensor harnesses the speaker to send inaudible acoustic signals (around 20 kHz) and utilizes the microphone to capture the reflected signals. As the reflected signals have unique variations in the Doppler shift respective to the gaits of different people, EchoSensor is able to profile human gait patterns from the generated spectrograms. To mine the gait information, we first propose a two-stage interference cancellation scheme to remove the background noise and environmental interference, followed by a new method to detect the starting point of walking and estimate the gait cycle time. We then perform the fine-grained analysis of the spectrograms to extract a series of features. In the end, machine learning is employed to construct an identifier for individual recognition. We implement the EchoSensor system and deploy it under different household environments to conduct intrusion detection tasks. Extensive experimental results have demonstrated that EchoSensor can achieve the averaged Intruder Gait Detection Rate (IDR) and True Family Member Gait Detection Rate (TFR) of 92.7% and 91.9%, respectively.
Changlai Du, Jiadong Lou, Li Chen 0019, Xu Yuan 0001
ACM Trans. Sens. Networks2
2023 UCBlocker: Unwanted Call Blocking Using Anonymous Authentication
Changlai Du, Hexuan Yu, Yang Xiao 0010, Y. Thomas Hou 0001, Angelos D. Keromytis, Wenjing Lou
USENIX Security Symposium1
2023 MS-PTP: Protecting Network Timing from Byzantine Attacks
abstract
Time-sensitive applications, such as 5G and IoT, are imposing increasingly stringent security and reliability requirements on network time synchronization. Precision time protocol (PTP) is a de facto solution to achieve high precision time synchronization. It is widely adopted by many industries. Existing efforts in securing the PTP focus on the protection of communication channels, but little attention has been given to the threat of malicious insiders. In this paper, we first present the security vulnerabilities of PTP and discuss why the current defense mechanisms are unable to counter Byzantine insiders. We demonstrate how a malicious insider can spoof a time source to arbitrarily shift the system time of a victim node on an IoT testbed. We further demonstrate the harmful consequence of the attack on a real Turtlebot3 robotic platform as the robot fails to locate itself and follows a false trajectory. As a countermeasure, we propose multi-source PTP, in short, MS-PTP, a Byzantine-resilient network time synchronization mechanism that relies on time crowdsourcing. MS-PTP changes the current PTP's single source hierarchy to a multi-source client-server architecture, in which PTP clients take responses from multiple time servers and apply a novel secure aggregation scheme to eliminate the effect of malicious responses from unreliable sources. MS-PTP is able to counter f Byzantine failures when the total number of time sources n used by a client satisfies n>=3f+1. We provide rigorous proof for its non-parametric accuracy guarantee---achieving bounded error regardless of the Byzantine population. We implemented a prototype of MS-PTP on our IoT testbed and the results show its resilience against Byzantine insiders while maintaining high synchronization accuracy.
Shanghao Shi, Yang Xiao 0010, Changlai Du, Md Hasan Shahriar, Ao Li 0006, Ning Zhang 0017, Y. Thomas Hou 0001, Wenjing Lou
WISEC3
2018 Context-Free Fine-Grained Motion Sensing Using WiFi
abstract
WiFi-based motion sensing has received a lot of research attention in recent years. Taking advantage of Channel State Information(CSI) collected from physical layer, previous techniques are able to extract useful information from CSI values to infer human movements. However, these works concentrate either on coarse-grained motion sensing or on fine-grained but context-related motion sensing. In this paper, we propose WiTalk, a new fine-grained human motion sensing technique with the distinct context-free character. To profile human motion using CSI, WiTalk generates CSI spectrograms using signal processing techniques and extracts features by calculating the contours of the CSI spectrograms. We verify the proposed technique in the application scenario of lip reading, where the fine-grained motion is the mouth movements. We implement WiTalk on a commercial laptop. Experiment results show that WiTalk can achieve over 92.3% recognition accuracy to discern a set of 12 syllables and 74.3% accuracy to discern a set of short sentences up to six words.
Changlai Du, Xiaoqun Yuan, Wenjing Lou, Y. Thomas Hou 0001
SECON1
2017 AugAuth: Shoulder-surfing resistant authentication for augmented reality
abstract
As computing system continues to play an increasing role in daily life, user authentication is now an important component. One of the most widely accepted methods for user authentication is through proof of knowledge of a piece of secret information, such as password. However, entering this non-mutable secret for authentication in public space often allows attackers to steal the secret by shoulder surfing or video recording. We observe that it is possible to block attacker's access to user input using augmented reality (AR) display, which is only available to the user. Based on this intuition, we present AugAuth, an authentication scheme in AR using commercial off-the-shelf(COTS) gesture control sensors as an input device. AugAuth can resist against shoulder surfing by presenting user input interface that is only visible to the user and is unique every time. To enable user input with finger movement using the gesture control armband, Myo, we have solved several challenges in electromyogram signal processing, such as annotating the start of signal and finger classification. The experiment results for our input system of a group of volunteers show that our finger classification function has high accuracy and AugAuth is practical for use in real life authentication scenarios.
Ruide Zhang, Ning Zhang 0017, Changlai Du, Wenjing Lou, Y. Thomas Hou 0001, Yuichi Kawamoto
ICC3
2017 From Electromyogram to Password: Exploring the Privacy Impact of Wearables in Augmented Reality
abstract
With the increasing popularity of augmented reality (AR) services, providing seamless human-computer interactions in the AR setting has received notable attention in the industry. Gesture control devices have recently emerged to be the next great gadgets for AR due to their unique ability to enable computer interaction with day-to-day gestures. While these AR devices are bringing revolutions to our interaction with the cyber world, it is also important to consider potential privacy leakages from these always-on wearable devices. Specifically, the coarse access control on current AR systems could lead to possible abuse of sensor data. Although the always-on gesture sensors are frequently quoted as a privacy concern, there has not been any study on information leakage of these devices. In this article, we present our study on side-channel information leakage of the most popular gesture control device, Myo. Using signals recorded from the electromyography (EMG) sensor and accelerometers on Myo, we can recover sensitive information such as passwords typed on a keyboard and PIN sequence entered through a touchscreen. EMG signal records subtle electric currents of muscle contractions. We design novel algorithms based on dynamic cumulative sum and wavelet transform to determine the exact time of finger movements. Furthermore, we adopt the Hudgins feature set in a support vector machine to classify recorded signal segments into individual fingers or numbers. We also apply coordinate transformation techniques to recover fine-grained spatial information with low-fidelity outputs from the sensor in keystroke recovery. We evaluated the information leakage using data collected from a group of volunteers. Our results show that there is severe privacy leakage from these commodity wearable sensors. Our system recovers complex passwords constructed with lowercase letters, uppercase letters, numbers, and symbols with a mean success rate of 91%.
Ruide Zhang, Ning Zhang 0017, Changlai Du, Wenjing Lou, Y. Thomas Hou 0001, Yuichi Kawamoto
ACM Trans. Intell. Syst. Technol.3
2016 MobTrack: Locating indoor interfering radios with a single device
abstract
In this paper, we present MobTrack, a single device system which aims to locate interfering radios on unlicensed ISM band in indoor environments. Compared with existing techniques which require a deployment of dense access points (APs), MobTrack only demands a single device equipped with multiple antennas. The location of an interfering signal source are estimated by computing the angle of arrival (AoA) of Line of Sight (LoS) component using an antenna array. Taking advantage of cyclostationary property, MobTrack differentiates interfering signals from working signals. By moving the device around for a short distance within one meter, it depresses multipath effects and determines the LoS component. Simultaneously, the AoAs on the moving trace are recorded to estimate the location of the interfering radio by triangulation. We evaluate the performance of MobTrack by setting up a prototype experimental system. Compared with recent interference localization schemes, MobTrack has much lower hardware complexity and gets better localization accuracy with a median of 0.55 meters.
Changlai Du, Ruide Zhang, Wenjing Lou, Y. Thomas Hou 0001
INFOCOM1
2015 On cyclostationary analysis of WiFi signals for direction estimation
abstract
Cyclostationary analysis is a powerful tool to study the Signal-Selective Direction Estimation (SSDE) problem as different types of wireless signals have different cyclostationary patterns. Generally speaking, each type of wireless signal has unique cyclic frequencies with the frequency-selective property, which distinguishes itself from other types of signals. The cyclostationary property of a signal may be induced by its modulation method, its carrier frequency, and/or its frame structure. In this paper, we study the cyclostationary property of IEEE 802.11 (WiFi) signals induced by their underlying OFDM frame structure, which includes pilots, cyclic prefix (CP), and preambles. We first analyze the pilot-induced, CP-induced, and preamble-induced cyclostationary properties of WiFi signals, respectively. We then derive their spectral correlation function (SCF) and investigate their applicability to solving the SSDE problem. Simulation results show that the pilot-induced cyclostationary property of WiFi signals is a promising feature that can be used to solve the SSDE problem.
Changlai Du, Huacheng Zeng, Wenjing Lou, Y. Thomas Hou 0001
ICC1
2008 VCNF: A Secure Video Conferencing System Based on P2P Technology
abstract
The goal of a video conferencing system is to deliver multimedia data to the conference participants efficiently and securely. To meet the requirement of a video conferencing system over the internet, many issues have to be addressed, such as security, scalability and heterogeneity. In this paper, we propose a secure and scalable video conferencing system named VCNF (Video Conference Network Foundation), to support large number of conferencing groups simultaneously with each group has limited members. We use a P2PSIP overlay to store and lookup the user and group contact information. SIP protocol is used to setup media sessions and a new kind of session-- VPN session. We adopt a layered data transfer mechanism which traits different kinds of media-streams as of different importance level. We have implemented the system and analyzed its performance and security. An Internet video-based game based on our platform has also been deployed over the Internet.
Changlai Du, Chuang Lin 0002, Yada Hu
HPCC1