VLDB 2026 Research / reviewers in the wild / expert
Jiachun Li 0001
dblp:09/7698-1
· DBLP profile ↗
13ranked-venue papers
5as first author
13since 2021 · last 2025
0000-0003-4032-4459ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 6 since 2021Security and privacy · 6 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Blind Points Between ASR and Intent Inferring: Vulnerability Discovering via Fuzzing in-Vehicle Voice AssistanceabstractCurrently, in-vehicle Voice Assistants (VAs) have been widely integrated into in-vehicle infotainment (IVI) systems to enhance driver safety when performing functions such as navigation and phone calls while driving. Although various studies have demonstrated the existence of vulnerabilities in general-purpose VAs, there is a lack of research specifically targeting in-vehicle VAs, which operate in a closed and black-box environment. In this paper, we utilize fuzzing testing to analyze how speech errors in voice commands affect the recognition performance of in-vehicle VAs. First, we simulate speech errors by applying linguistic knowledge to mutate voice commands. Then, we adopt a genetic algorithm to efficiently generate additional erroneous commands. To further improve the quality of these mutated commands, we assign a risk level to each original command and prioritize the mutation of those whose misrecognition by the in-vehicle VA results in an increased risk level. We conducted comprehensive fuzzing experiments on both local (Whisper–DistilBERT-based) and cloud-based (Amazon Lex) in-vehicle VA systems. Our approach generated 59112 speech-error commands in the local VA, achieving a 60.13% misrecognition rate, significantly outperforming Baseline-Fuzzing, which had an effectiveness of 40.26%. On the cloud-based VA, the effectiveness improved from 2.83% to 33.24%. These results confirm the superiority of our method in generating high-impact erroneous commands. Peilin Luo, Wei Teng, Jiachun Li 0001, Yan Meng 0001, Haojin Zhu |
TrustCom | 3 |
| 2025 | A Magnetic Signal Based Device Fingerprinting Scheme in Wireless ChargingabstractWireless charging is widely used to charge smart devices with limited battery capacity. However, it is susceptible to the identity spoofing attack, where adversaries can impersonate malicious devices as legitimate ones to gain unauthorized access and potentially disrupt the wireless charging system (e.g., resulting in incorrect billing, overheating, or even explosions). Device fingerprinting is a classical method for defending against identity spoofing attacks. However, applying existing schemes in wireless charging scenarios has drawbacks such as inconvenience (e.g., requiring specialized devices or user participation) and ineffectiveness (e.g., vulnerability to spoofing). Thus, we design a novel passive, effective, and robust device fingerprinting scheme called MagID for wireless charging systems. The insight of MagID lies in the fact that during wireless charging, the magnetic signal around a device can reflect inherent hardware differences. These differences can be extracted as unique fingerprints for authentication purposes. MagID leverages a novel scheme, SUPER-ARRAY, to precisely measure magnetic data and generate effective fingerprints for authenticating a device's identity before starting charging progress. Experimental results demonstrate that MagID achieves an accuracy rate of 98.14% across various charging devices. We have also tested its performance under different impact factors and verified its compatibility with various wireless charging pads. Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Synergistic Multi-Modal Keystroke Eavesdropping in Virtual Reality With Vision and Wi-FiabstractIn panoramic and immersive virtual reality (VR) scenarios, users type on a floating and invisible keyboard, which cannot be observed by external adversaries, creating the illusion that their input is confidential. While recent studies have demonstrated the feasibility of leveraging side-channel information (e.g., vision, Wi-Fi) to eavesdrop on keystrokes in VR, they assume users typically type with fixed gestures, similar to using traditional physical keyboards. However, in real world scenarios, VR creates a 3D immersive environment, allowing users to type from varying orientations. This variation significantly degrades the quality of side-channel information (e.g., occlusion in vision, instability in Wi-Fi channels), leading to ineffective inference. In this study, we propose a multi-modal keystroke eavesdropping attack called WiViLeak, which combines Wi-Fi and vision information to complement each other. To address low-quality side-channel data caused by users’ varying orientations, we develop a theoretical model to explore the relationship between users’ hand movements in physical space (from the vision modality) and fluctuating Wi-Fi signals (from the wireless modality) as users change orientation. Based on this, we design a fully transformer based orientation calibration module to recover users’ vision data, aligning it as if they were facing the camera (i.e., in a front-facing view). Meanwhile, WiViLeak reconstructs Wi-Fi data to correspond to the front-facing view, utilizing the orientation angle derived from vision data. Finally, WiViLeak extracts effective features from reconstructed, high-quality vision and Wi-Fi data to predict keystrokes. We implement a WiViLeak prototype, achieving 89.2% accuracy in eavesdropping keystrokes and 93.6% top-100 password theft accuracy, while also demonstrating robustness across various real world VR scenarios, including payments, chatting, and meetings. Jiachun Li 0001, Yan Meng 0001, Fazhong Liu, Tian Dong 0003, Suguo Du, Guoxing Chen, Yuling Chen 0002, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | VR-Fi: Positioning and Recognizing Hand Gestures via VR-Embedded Wi-Fi SensingabstractAccurate gesture-based interactions are crucial for enhancing the immersive experience in VR (virtual reality) systems; they in turn necessitate gesture positioning and recognition inphysical world. However, existing VR gesture recognition methods are predominantly vision-based, incurring high computational demands and raising privacy concerns. Meanwhile, Wi-Fi-based gesture recognition methods, deemed as promising complement to vision-based ones, typically lack gesture positioning capabilities. To this end, we propose VR-Fi, a gesture positioning and recognition system leveraging VR(-headset)-embedded Wi-Fi. To position gestures across different areas, VR-Fi innovates in afrequency-hopping bandwidth expansion(FHBE) technique to improve spatial resolution for locating a target. Additionally, VR-Fi innovates in neural models to process the FHBE-enhanced Wi-Fi CSI (channel state information) and enable the multi-task requirements of the joint positioning and recognition of hand gestures. Extensive experimental results demonstrate that VR-Fi achieves a positioning accuracy of 94.47%, a recognition accuracy of 92.13%, and a joint accuracy of 89.47%. Xin Li 0070, Jiachun Li 0001, Haojin Zhu, Jun Luo 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Privacy-Preserving Liveness Detection for Securing Smart Voice InterfacesabstractSmart speakers are widely used as the primary user interface in intelligent systems, including smart homes and industrial IoT. However, they are vulnerable to voice spoofing attacks which result in malicious command execution or privacy information leakage. Passive liveness detection, which thwarts voice spoofing via analyzing the collected audio rather than deploying sensors to distinguish between live-human and spoofing voices, has drawn increasing attention. But existing schemes either face performance degradation under environmental factor changes or require the user to keep fixed gestures, which limit their deployment in real-world scenarios. Besides, the space distributed property of smart speakers causes building a universal classifier for all involved users to be cumbersome and increases privacy leakage issues. To address the challenges mentioned above, we propose LIVEARRAY, an efficient, lightweight, and privacy-preserving passive liveness detection system. LIVEARRAY exploits a novel liveness feature, array fingerprint, which utilizes the microphone array inherently adopted by the smart speaker to improve the accuracy of liveness detection. LIVEARRAY's further employs the federated learning-based architecture to reduce the dataset collection overhead during classifier building and eliminate the potential privacy leakage during data transmission. Experimental results show that LIVEARRAY achieves an accuracy of 99.16%, which is superior to existing passive schemes Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Yuan Tian 0001, Jiming Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Dangers Behind Charging VR Devices: Hidden Side Channel Attacks via Charging CablesabstractVirtual reality (VR), offering 3D visuals and stereophonic sounds, significantly enhances users’ immersive experiences and has become a milestone in the era of the metaverse. However, due to the limited battery capacity of VR devices, it is common for users to rely on charging cables, which serve the dual purpose of power supply and audio output, to recharge their VR devices while in use. In this study, we propose an inconspicuous and stealthy side channel attack, coined as LineTalker, which can unveil visual-related and audio-related activities from VR devices during the charging process. The insight behind LineTalker is rooted in the observation that visual-related activities (e.g., 3D image rendering) are power-intensive and result in fluctuations in the current strength of the cable’s power supply line, which can be leveraged as side channel information. Similarly, audio-related activities (e.g., playing music) leave traces on the cable’s audio output line. Rather than providing a user with a compromised charging cable (i.e., embedding a current sensor) to measure the current strength, to make the attack less conspicuous, LineTalker employs the Hall effect to indirectly access side channel information. This is achieved by capturing magnetic signals using a Hall sensor placed near the target cable in a contactless manner. Experimental results demonstrate that LineTalker achieves an overall accuracy of 94.60% and 64.38% in inferring user activities in VR devices with intrusive and non-intrusive attack manners, respectively. Jiachun Li 0001, Yan Meng 0001, Yuxia Zhan, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | De-Anonymizing Avatars in Virtual Reality: Attacks and CountermeasuresabstractBy providing users with an immersive visual and acoustic experience, virtual reality (VR) serves as a foundational technique for the emerging metaverse. One of the most promising aspects of VR is its ability to protect users’ identities by transforming their physical appearances into avatars with arbitrary appearances in the virtual world. However, the increasing threat of de-anonymization attacks that seek to reveal users’ identities poses significant privacy risks. We propose AvatarHunter, a non-intrusive and user-unaware de-anonymization attack leveraging victims’ inherent movement signatures. AvatarHunter discreetly collects the avatar's gait information by recording videos in the VR scenario without requiring any permissions. Notably, we designed a Unity-based feature extractor that maintains the avatar's movement signature while enabling AvatarHunter to be resistant to changes in the avatar's appearance. We conduct real-world experiments on VRChat to evaluate AvatarHunter's effectiveness. The results demonstrate that in commercial settings, AvatarHunter achieves attack success rates (ASR) of 92.1% and 66.9% in closed-world and open-world avatar scenarios, respectively, significantly surpassing existing benchmarks. Additionally, simulations using an open-source dataset confirm that AvatarHunter can attain over 78% ASR in full-body tracking scenarios. Finally, we discuss several countermeasures and implement an obfuscation mechanism during the avatar rendering phase, significantly reducing the ASR. Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Data Poisoning Attack Against Anomaly Detectors in Digital Twin-Based NetworksabstractIn this paper, we study the abnormal behaviors detection and the corresponding data poisoning attacks in digital twin (DT)-based networks. We first analyze the abnormal behaviors existing in the DT-based networks, including environment anomalies, hardware and software faults, and network attacks. Specially, we design a machine learning (ML)-based anomaly detector to identify network attacks. Furthermore, due to the strong dependency of ML models on training data, in which the outputs of the trained ML models can be affected by the poisoned samples. We design a data poisoning attack scheme against the proposed ML-based anomaly detector, in which attackers can effectively compromise the output of anomaly detectors. Extensive experimental results adopting three commonly used ML-based models demonstrate that the attack can compromise these detectors with over 80% probability. Shaofeng Li 0001, Wen Wu 0003, Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Xuemin Shen |
ICC | 4 |
| 2023 | MagFingerprint: A Magnetic Based Device Fingerprinting in Wireless Charging
Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu, Xuemin Shen |
INFOCOM | 1 |
| 2023 | De-anonymization Attacks on MetaverseabstractVirtual reality (VR) can provide users with an immersive experience in the metaverse. One of the most promising properties of VR is that users’ identities can be protected by changing their physical world appearances into arbitrary virtual avatars. However, recent proposed de-anonymization attacks demonstrate the feasibility of recognizing the user’s identity behind the VR avatar’s masking. In this paper, we propose AvatarHunter, a non-intrusive and user-unconscious de-anonymization attack based on victims’ inherent movement signatures. AvatarHunter imperceptibly collects the victim avatar’s gait information via recording videos from multiple views in the VR scenario without requiring any permission. A Unity-based feature extractor is designed that preserves the avatar’s movement signature while immune to the avatar’s appearance changes. Real-world experiments are conducted in VRChat, one of the most popular VR applications. The experimental results demonstrate that AvatarHunter can achieve attack success rates of 92.1% and 66.9% in closed-world and open-world avatar settings, respectively, which are much better than existing works. Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen |
INFOCOM | 3 |
| 2022 | Your Microphone Array Retains Your Identity: A Robust Voice Liveness Detection System for Smart Speakers
Yan Meng 0001, Jiachun Li 0001, Matthew Pillari, Arjun Deopujari, Liam Brennan, Hafsah Shamsie, Haojin Zhu, Yuan Tian 0001 |
USENIX Security Symposium | 2 |
| 2022 | A Federated Learning Based Privacy-Preserving Smart Healthcare SystemabstractThe rapid development of the smart healthcare system makes the early-stage detection of dementia disease more user-friendly and affordable. However, the main concern is the potential serious privacy leakage of the system. In this article, we take Alzheimer's disease (AD) as an example and design a convenient and privacy-preserving system namedADDetectorwith the assistance of Internet of Things (IoT) devices and security mechanisms. Particularly, to achieve effective AD detection,ADDetectoronly collects user's audio by IoT devices widely deployed in the smart home environment and utilizes novel topic-based linguistic features to improve the detection accuracy. For the privacy breach existing in data, feature, and model levels,ADDetectorachieves privacy-preserving by employing a unique three-layer (i.e., user, client, cloud, etc.) architecture. Moreover,ADDetectorexploitsfederated learning (FL) based schemeto ensure the user owns the integrity of raw data and secure the confidentiality of the classification model and implementdifferential privacy (DP) mechanismto enhance the privacy level of the feature. Furthermore, to secure the model aggregation process between clients and cloud in FL-based scheme, a novelasynchronous privacy-preserving aggregation frameworkis designed. We evaluateADDetectoron 1010 AD detection trials from 99 health and AD users. The experimental results show thatADDetectorachieves high accuracy of 81.9% and low time overhead of 0.7 s when implementing all privacy-preserving mechanisms (i.e., FL, DP, and cryptography-based aggregation). Jiachun Li 0001, Yan Meng 0001, Lichuan Ma, Suguo Du, Haojin Zhu, Qingqi Pei, Xuemin Shen |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | BatFL: Backdoor Detection on Federated Learning in e-HealthabstractFederated Learning (FL) has received significant interest both from the research field and industry perspective. One of the most promising cross-silo applications on FL is electronic health records mining which trains a model on siloed data. In this application, clients can be different hospitals or health centers that are located in geo-distributed data centers. A central orchestration server (superior health center) organizes the training, while never seeing patients’ raw data. In this paper, we demonstrate that any local hospital in such a collaborative training framework can introduce hidden backdoor functionality into the joint global model. The backdoored joint global model will produce an adversary-expected output when a predefined trigger is attached to its input but it will behave normally for clean inputs. This vulnerability is exacerbated by the distributed nature of FL, making detecting backdoor attacks on FL a challenging work. Based on the coalitional game and Shapley value, we propose an effective and real-time backdoor detection system on FL. Extensive experiments over two machine learning tasks show that our techniques achieve high accuracy and are robust against multi-attackers settings. Binhan Xi, Shaofeng Li 0001, Jiachun Li 0001, Haojin Zhu |
IWQoS | 3 |