Yan Zhang 0091

dblp:04/3348-91 · DBLP profile ↗
← Back
18ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0001-8691-1267ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 3 first-author · 11 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath Keyboards
Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042
INFOCOM2
2026 RIS-CLA: Reviving CSI-Based Continuous Location Authentication With Reconfigurable Intelligent Surfaces
Yan Zhang 0091, Jiawei Li 0010, Dianqi Han, Aditya Shekhawat, George Trichopoulos
SP1
2026 BadAMC: A Model-Agnostic Digital Backdoor Attack for Automatic Modulation Classification in Crowdsourced Platforms
Yan Zhang 0091, Ang Li 0013, Tao Li 0042
IEEE Trans. Netw.2
2024 WaveKey: Secure Mobile Ad Hoc Access to RFID-Protected Systems
abstract
This paper presents the design and evaluation of WaveKey, a cross-modal deep learning-based method to enable mobile ad hoc in-situ access to RFID- protected cyber systems. Built upon the ever-growing popularity of user-carried mobile devices and RFID technologies, WaveKey is motivated by the need for secure and user-friendly data access in various application contexts. WaveKey explores a random gesture performed by the mobile user to induce correlated IMU data and RFID signals at the involved mobile device and RFID server, adopts deep learning techniques to extract the complex cross-modal correlation, and devises an Oblivious Transfer-based key-agreement protocol to-ward secure and efficient key establishment. Theoretical analysis and experimental human-based evaluation confirmed the high security and efficiency of WaveKey. In particular, WaveKey shows very high key-establishment success rates consistently exceeding 98 % across all evaluated settings and renders extremely low success rates below 0.5 % for all evaluated common attacks.
Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042
ICDCS4
2023 PhyAuth: Physical-Layer Message Authentication for ZigBee Networks
Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042, Ting Zhu 0001
USENIX Security Symposium4
2023 SmartMagnet: Proximity-Based Access Control for IoT Devices With Smartphones and Magnets
abstract
Ubiquitous smartphones can be powerful tools to access IoT devices. Proximity-based access control (PBAC) is needed such that IoT devices only allow data access by legitimate users in close proximity. Traditional smartphone-based authentication techniques do not satisfy the PBAC requirements. This paper presents SmartMagnet, a novel scheme that combines smartphones and cheap magnets to achieve PBAC for IoT devices. SmartMagnet explores a few cheap, tiny commodity magnets which we propose to attach to or embed into IoT devices, as well as the magnetometer and attitude sensor on commodity smartphones. Each legitimate user performs a self-chosen 3D password gesture near the target IoT device with the enrolled smartphone. Then the system server uses the IoT device’s confidential magnet configuration parameters to reconstruct the user gesture from the magnetometer and attitude sensor data submitted by the smartphone. If the reconstructed gesture matches the stored template of the purported user, the smartphone user is deemed legitimate and allowed access to the IoT device. Extensive experiments confirm the high usability of SmartMagnet and its strong resilience to lost/stolen smartphones and also remote attacks via signal relaying.
Yan Zhang 0091, Dianqi Han, Ang Li 0013, Jiawei Li 0010, Tao Li 0042
IEEE Trans. Mob. Comput.1
2023 MagAuth: Secure and Usable Two-Factor Authentication With Magnetic Wrist Wearables
abstract
Secure and usable user authentication is the first line of defense against cyber attacks on smart end-user devices. Advanced hacking techniques pose severe threats to the traditional authentication systems based on the password/PIN/fingerprint. We propose MagAuth, a secure and usable two-factor authentication scheme with commercial off-the-shelf (COTS) wrist wearables with magnetic strap bands to enhance the security and usability of password-based authentication for mobile touchscreen devices. In MagAuth, a user enrolls a self-chosen unlock pattern or touch gesture into his touchscreen device by performing it with the same hand the magnetic wrist wearable is on. The chosen unlock pattern or touch gesture serves as the first authentication factor, and the user’s behavioral features manifested in the magnetic field changes during his finger movement correspond to the second factor. The user can unlock his touchscreen device only when both authentication factors can be validated. Comprehensive user experiments confirm the high security and usability of MagAuth. In particular, MagAuth achieves an average true-positive rate up to 96.3 percent and a false-positive rate no larger than 8.4 percent. Moreover, we show that MagAuth is highly resilient to various attacks.
Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042
IEEE Trans. Mob. Comput.1
2023 Rhythmic RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
IEEE/ACM Trans. Netw.5
2023 Secure UHF RFID Authentication With Smart Devices
abstract
Commodity ultra-high-frequency (UHF) RFID authentication systems only provide weak user authentication, as RFID tags can be easily stolen, lost, or cloned by attackers. This paper presents the design and evaluation of SmartRFID, a novel UHF RFID authentication system to promote commodity crypto-less UHF RFID tags for security-sensitive applications. SmartRFID explores extremely popular smart devices and requires a legitimate user to enroll his smart device along with his RFID tag. Besides authenticating the RFID tag as usual, SmartRFID verifies whether the user simultaneously possesses the associated smart device with both feature-based machine learning and deep learning techniques. The user is considered authentic if and only if passing the dual verifications. Comprehensive user experiments on commodity smartwatches and RFID devices confirmed the high security and usability of SmartRFID. In particular, SmartRFID achieves a true acceptance rate of above 97.5% and a false acceptance rate of less than 0.7% based on deep learning. In addition, SmartRFID can achieve an average authentication latency of less than 2.21 s, which is comparable to inputting a PIN on a door keypad or smartphone.
Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Tao Li 0042
IEEE Trans. Wirel. Commun.3
2022 WearRF-CLA: Continuous Location Authentication with Wrist Wearables and UHF RFID
abstract
Continuous location authentication (CLA) seeks to continuously and automatically verify the physical presence of legitimate users in a protected indoor area. CLA can play an important role in contexts where access to electrical or physical resources must be limited to physically present legitimate users. In this paper, we present WearRF-CLA, a novel CLA scheme built upon increasingly popular wrist wearables and UHF RFID systems. WearRF-CLA explores the observation that human daily routines in a protected indoor area comprise a sequence of human-states (e.g., walking and sitting) that follow predictable state transitions. Each legitimate WearRF-CLA user registers his/her RFID tag and also wrist wearable during system enrollment. After the user enters a protected area, WearRF-CLA continuously collects and processes the gyroscope data of the wrist wearable and the phase data of the RFID tag signals to verify three factors to determine the user's physical presence/absence without explicit user involvement: (1) the tag ID as in a traditional RFID authentication system, (2) the validity of the human-state chain, and (3) the continuous coexistence of the paired wrist wearable and RFID tag with the user. The user passes CLA if and only if all three factors can be validated. Extensive user experiments on commodity smartwatches and UHF RFID devices confirm the very high security and low authentication latency of WearRF-CLA.
Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042
AsiaCCS4
2022 RCID: Fingerprinting Passive RFID Tags via Wideband Backscatter
abstract
Tag cloning and spoofing pose great challenges to RFID applications. This paper presents the design and evaluation of RCID, a novel system to fingerprint RFID tags based on the unique reflection coefficient of each tag circuit. Based on a novel OFDM-based fingerprint collector, our system can quickly acquire and verify each tag’s RCID fingerprint which are independent of the RFID reader and measurement environment. Our system applies to COTS RFID tags and readers after a firmware update at the reader. Extensive prototyped experiments on 600 tags confirm that RCID is highly secure with the authentication accuracy up to 97.15% and the median authentication error rate equal to 1.49%. RCID is also highly usable because it only takes about 8 s to enroll a tag and 2 ms to verify an RCID fingerprint with a fully connected multi-class neural network. Finally, empirical studies demonstrate that the entropy of an RCID fingerprint is about 202 bits over a bandwidth of 20 MHz in contrast to the best prior result of 17 bits, thus offering strong theoretical resilience to RFID cloning and spoofing.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Tao Li 0042
INFOCOM4
2022 (In)secure Acoustic Mobile Authentication
abstract
Acoustic fingerprinting aims to identify a mobile device based on its internal microphone(s) and speaker(s) which are unique due to manufacturing imperfection. This paper seeks a thorough understanding of the (in)security of exploring acoustic fingerprints for achieving distributed mobile authentication. Our contributions are threefold. First, we present a new acoustic fingerprint-emulation attack and demonstrate that it is a common vulnerability of acoustic mobile authentication systems. Second, we propose a dynamic challenge-response defense to secure acoustic mobile authentication systems against the acoustic fingerprint-emulation attack. Finally, we thoroughly investigate existing acoustic fingerprinting schemes and identify the best option for accurate, secure, and deployable acoustic mobile authentication systems.
Dianqi Han, Ang Li 0013, Tao Li 0042, Yan Zhang 0091, Jiawei Li 0010, Rui Zhang 0007
IEEE Trans. Mob. Comput.5
2022 SpecKriging: GNN-Based Secure Cooperative Spectrum Sensing
abstract
Cooperative spectrum sensing (CSS) adopted by spectrum-sensing providers (SSPs) plays a key role for dynamic spectrum access and is essential for avoiding interference with licensed primary users (PUs). A typical SSP system consists of geographically distributed spectrum sensors which can be compromised to submit fake spectrum-sensing reports. In this paper, we propose SpecKriging, a new spatial-interpolation technique based on Inductive Graph Neural Network Kriging (IGNNK) for secure CSS. In SpecKriging, we first pretrain a graphical neural network (GNN) model with the historical sensing records of a few trusted anchor sensors. During system runtime, we use the trained model to evaluate the trustworthiness of non-anchor sensors’ data and also use them along with anchor sensors’ new data to retrain the model. SpecKriging outputs trustworthy sensor reports for spectrum-occupancy detection. To the best of our knowledge, SpecKriging is the first work that explores GNNs for trustworthy CSS and also incorporates the hardware heterogeneity of spectrum sensors. Extensive experiments confirm the high efficacy and efficiency of SpecKriging for trustworthy spectrum-occupancy detection even when malicious spectrum sensors constitute the majority.
Yan Zhang 0091, Ang Li 0013, Jiawei Li 0010, Dianqi Han, Tao Li 0042, Rui Zhang 0007
IEEE Trans. Wirel. Commun.1
2021 DroneKey: A Drone-Aided Group-Key Generation Scheme for Large-Scale IoT Networks
abstract
The Internet of Things (IoT) networks are finding massive applications in mission-critical contexts. A group key is needed to encrypt and authenticate broadcast/multicast messages commonly seen in large-scale wireless networks. In this paper, we propose DroneKey, a novel drone-aided PHY-based Group-Key Generation (GKG) scheme for large-scale IoT networks. In DroneKey, a drone is dispatched to fly along random 3D trajectories and keep broadcasting standard wireless signals to refresh the group keys in the whole network. Every IoT device receives the broadcast signals from which to extract the Channel State Information (CSI) stream which captures the dynamic variations of the individual wireless channel between the IoT device and the drone. DroneKey explores a deep-learning approach to extract the hidden correlation among the CSI streams to establish a common group key. We thoroughly evaluate DroneKey with a prototype in both indoor and outdoor environments. We show that DroneKey can achieve a high key-generation rate of 89.5 bit/sec for 10 devices in contrast to 40 bit/sec in the state-of-art prior work. In addition, DroneKey is much more scalable and can support 100 devices in contrast to 10 nodes in the state-of-art prior work with comparable key-generate rates.
Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042
CCS4
2021 Your Home is Insecure: Practical Attacks on Wireless Home Alarm Systems
abstract
Wireless home alarm systems are being widely deployed, but their security has not been well studied. Existing attacks on wireless home alarm systems exploit the vulnerabilities of networking protocols while neglecting the problems arising from the physical component of IoT devices. In this paper, we present new event-eliminating and event-spoofing attacks on commercial wireless home alarm systems by interfering with the reed switch in almost all COTS alarm sensors. In both attacks, the external adversary uses his own magnet to control the state of the reed switch in order to either eliminate legitimate alarms or spoof false alarms. We also present a new battery-depletion attack with programmable electromagnets to deplete the alarm sensor's battery quickly and stealthily in hours which is expected to last a few years. The efficacy of our attacks is confirmed by detailed experiments on a representative Ring alarm system.
Tao Li 0042, Dianqi Han, Jiawei Li 0010, Ang Li 0013, Yan Zhang 0091, Rui Zhang 0007
INFOCOM5
2021 Deep Learning-Guided Jamming for Cross-Technology Wireless Networks: Attack and Defense
abstract
Wireless networks of different technologies may interfere with each other when they are deployed at proximity. Such cross-technology interference (CTI) has become prevalent with the surge of IoT devices. In this paper, we exploit CTI in coexisting WiFi-Zigbee networks and propose DeepJam, a new stealthy jamming strategy, to jam Zigbee traffic. DeepJam relies on deep learning techniques to capture the temporal pattern of the past wireless traffic and predict the future wireless traffic. By only jamming the victim’s transmissions that are not disrupted by CTI, DeepJam can significantly reduce the victim’s throughput with far fewer jamming signals and is thus much more stealthy than conventional jamming strategies. Detailed evaluations show that DeepJam can converge within 10 sec and achieve the jamming-efficiency gains of up to 742% and 285% over conventional random and reactive jamming strategies, respectively, in practical scenarios. We also propose a simple yet effective countermeasure against DeepJam.
Dianqi Han, Ang Li 0013, Yan Zhang 0091, Jiawei Li 0010, Tao Li 0042, Ting Zhu 0001
IEEE/ACM Trans. Netw.4
2020 RF-Rhythm: Secure and Usable Two-Factor RFID Authentication
abstract
Passive RFID technology is widely used in user authentication and access control. We propose RF-Rhythm, a secure and usable two-factor RFID authentication system with strong resilience to lost/stolen/cloned RFID cards. In RF-Rhythm, each legitimate user performs a sequence of taps on his/her RFID card according to a self-chosen secret melody. Such rhythmic taps can induce phase changes in the backscattered signals, which the RFID reader can detect to recover the user’s tapping rhythm. In addition to verifying the RFID card’s identification information as usual, the backend server compares the extracted tapping rhythm with what it acquires in the user enrollment phase. The user passes authentication checks if and only if both verifications succeed. We also propose a novel phase-hopping protocol in which the RFID reader emits Continuous Wave (CW) with random phases for extracting the user’s secret tapping rhythm. Our protocol can prevent a capable adversary from extracting and then replaying a legitimate tapping rhythm from sniffed RFID signals. Comprehensive user experiments confirm the high security and usability of RF-Rhythm with false-positive and false-negative rates close to zero.
Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Jinhang Zuo, Rui Zhang 0007, Lei Xie 0004
INFOCOM5
2019 SocialDistance: how far are you from verified users in online social media?
abstract
Verified users on online social media (OSM) largely determine the quality of OSM services and applications, but most OSM users are unverified due to the significant effort involved in becoming a verified user. This paper presents SocialDistance, a novel technique to identify unverified users that can be considered as trustworthy as verified users. SocialDistance is motivated by the observation that online interactions initiated from verified users towards unverified users can translate into some sort of trustworthiness. It treats all verified users equally and assigns a trust score between 0 and 1 to each unverified user. The higher the trust score, the closer an unverified user to verified users. We propose various metrics to model the interactions from verified to unverified users and then derive corresponding trust scores. SocialDistance is thoroughly evaluated with large Twitter datasets containing 276,143 verified users and 19,047,202 unverified users. Our results demonstrate that SocialDistance can produce a non-trivial number of unverified users that can be regarded as verified users for OSM applications. We also show the high efficacy of SocialDistance in sybil detection, a fundamental operation performed by virtually every OSM operator.
Ang Li 0013, Tao Li 0042, Yan Zhang 0091
IWQoS3