Jie Yang 0003

dblp:12/1198-3 · DBLP profile ↗
← Back
94ranked-venue papers
12as first author
23since 2021 · last 2026
0000-0002-8244-2181ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 69 · 8 first-author · 16 since 2021Security and privacy · 14 · 1 first-author · 7 since 2021Systems, architecture and hardware · 6 · 2 first-authorHuman-computer interaction and ubiquitous computing · 5 · 1 first-authorArtificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Automating Function-Level TARA for Automotive Full-Lifecycle Security
Yuqiao Yang, Yongzhao Zhang, Pengtao Shi, DingYu Zhong, Jie Yang 0003, Ting Chen 0002, Yuntao Ren, Yongyue Wu, Xiaosong Zhang 0001
NDSS7
2026 Acoustic-URL: Multisignal-Domain and Multichannel Fusion for Unsupervised Representation Learning in Acoustic Sensing
Bingzhi Wang, Yongzhao Zhang, Jiajun Yu, Jie Yang 0003
IEEE Internet Things J.4
2026 An Intrusion Feature Selection Method Based on Feature Distribution and Gini Impurity
abstract
Intrusion detection systems (IDS) can effectively monitor network traffic and accurately detect malicious behaviors. In Internet of Things (IoT) environments, the massive influx of heterogeneous, resource-constrained devices introduces more complex security challenges, making IDS even more crucial for maintaining network security. However, the presence of redundant or irrelevant features in network traffic can significantly degrade the detection performance of IDS. To address this issue, this paper proposes a Feature distribution and Gini Impurity Filter-based intrusion feature selection method (FGIF). It combines the cardinality and Gini impurity distributions of features within a dataset to construct a multi-parameter evaluation framework, which is used to define efficient feature filtering rules that eliminate redundant and irrelevant features. Theoretical analysis demonstrates that, compared to entropy-based methods, FGIF mitigates selection bias during the feature selection process and significantly reduces computational overhead. Experiments conducted on six widely used IDS benchmark datasets and five commonly adopted classification models further confirm its effectiveness. FGIF significantly reduces feature dimensionality while maintaining detection performance comparable to that of the full feature set. Moreover, compared to existing state-of-the-art methods, FGIF achieves a superior balance between dimensionality reduction and model performance.
Ying Xie 0008, Qianni Zhang, Xuyang Ding, Yongzhao Zhang, Jie Yang 0003
IEEE Internet Things J.6
2026 Exploiting Cyber Threat Intelligence for Indirect Attacks Against Serverless Infrastructures
abstract
Cyber Threat Intelligence (CTI) and serverless computing are two emerging technologies that have significantly impacted their respective domains in recent years. However, their interaction remains surprisingly underexplored. In this work, through in-depth semi-structured interviews with cybersecurity experts, we identify the trust issues within the CTI ecosystem that can be exploited to introduce fake CTI manipulation, enabling indirect attacks against entities with dynamic IP allocation, such as those in serverless computing. Furthermore, these attacks can be amplified by commercial CTI platforms due to their widespread adoption and sharing mechanisms. Based on these insights, we propose Ares, a novel attack strategy that leverages fake CTI manipulation to enable large-scale, stealthy indirect denial-of-service attacks against serverless infrastructures. We demonstrate the feasibility and impact of Ares through extensive evaluations in a controlled experimental environment. Our results show that Ares can rapidly and widely disseminate fake CTI within the CTI ecosystem, leading to an overall average reject rate of 23.03% and a high reject rate of up to 45.42% when accessing top websites in certain industries, while maintaining a low detection rate across state-of-the-art serverless security systems. These findings underscore the urgent need for more frequent communication and collaboration among CTI platforms and related stakeholders to develop a more robust trustworthiness model across the ecosystem.
Baojin Wang, Yongzhao Zhang, Xiong Li 0002, Jie Yang 0003, Ting Chen 0002, Xiaosong Zhang 0001, Dian Ding, Yi-Chao Chen 0001
IEEE Trans. Inf. Forensics Secur.4
2025 A Practical DoS Attack on Commercial UWB Ranging Systems
abstract
Ultra-wideband (UWB) ranging systems are increasingly deployed in critical, security-sensitive applications due to their precise positioning and secure ranging capabilities. In this work, we introduce a practical DoS attack via reactive jamming, referred to as UWBAD+, which targets commercial UWB ranging systems by exploiting the vulnerabilities of the normalized cross-correlation process. This allows UWBAD+ to selectively and effectively disrupt ranging sessions without requiring prior knowledge of the victim devices' configurations, leading to potentially severe consequences such as property loss, unauthorized access, or vehicle theft. The enhanced effectiveness and low detectability of UWBAD+ stem from the following: (i) it can rapidly sniff the physical layer structures of unknown UWB systems, even in the presence of multiple UWB devices operating simultaneously; (ii) it blocks each ranging session efficiently by employing field-level jamming, thus exerting a significant impact on commercial UWB ranging systems; and (iii) its compact, reactive, and selective design based on COTS UWB chips, which makes it both affordable and less noticeable. We successfully executed real-world attacks on commercial UWB ranging systems produced by the three largest UWB chip vendors in the market, including Apple, NXP, and Qorvo. We disclosed our findings to Apple, relevant Original Equipment Manufacturers (OEMs), and the Automotive Security Research Group. As of the time of writing, the involved OEM has acknowledged this vulnerability in their automotive systems and has issued a${\$} 5,000$bounty as a reward.
Yongzhao Zhang, Yuqiao Yang, Zhongjie Wu, Ting Chen 0002, Jie Yang 0003, Guowen Xu, Xiaosong Zhang 0001, Jingwei Li 0001, Yu Jiang 0001, Zhuo Su 0005
IEEE Trans. Mob. Comput.7
2024 UWBAD: Towards Effective and Imperceptible Jamming Attacks Against UWB Ranging Systems with COTS Chips
abstract
UWB ranging systems have been adopted in many critical and security sensitive applications due to its precise positioning and secure ranging capabilities. We present a practical jamming attack, namely UWBAD, against commercial UWB ranging systems, which exploits the vulnerability of the adoption of the normalized cross-correlation process in UWB ranging and can selectively and quickly block ranging sessions without prior knowledge of the configurations of the victim devices, potentially leading to severe consequences such as property loss, unauthorized access, or vehicle theft. UWBAD achieves more effective and less imperceptible jamming due to: (i) it efficiently blocks every ranging session by leveraging the field-level jamming, thereby exerting a tangible impact on commercial UWB ranging systems, and (ii) the compact, reactive, and selective system design based on COTS UWB chips, making it affordable and less imperceptible. We successfully conducted real attacks against commercial UWB ranging systems from the three largest UWB chip vendors on the market, e.g., Apple, NXP, and Qorvo. We reported our findings to Apple, related Original Equipment Manufacturers (OEM), and the Automotive Security Research Group. As of the writing of this paper, the related OEM has acknowledged this vulnerability in their automotive systems and has offered a 5, 000 reward as a bounty.
Yuqiao Yang, Zhongjie Wu, Yongzhao Zhang, Ting Chen 0002, Jie Yang 0003, Xiaosong Zhang 0001, Ruicong Shi, Jingwei Li 0001, Yu Jiang 0001, Zhuo Su 0005
CCS6
2024 Acoustic-based Alphanumeric Input Interface for Earables
abstract
As earables gain popularity, there emerges a need for intuitive user interfaces that adapt to diverse daily scenarios. Traditional methods like touchscreens and voice control often fall short in environments like movie theatres, where silence and darkness are required, or on busy streets where visual distraction introduces extra risk. We propose an innovative earable-based system utilizing unique acoustic friction generated by fingers for alphanumeric input. Our approach digs into the acoustic friction theory, applying this knowledge to better understand the transformation from 2D handwriting into a 1D acoustic time series. This theoretical foundation guides our system design and feature extraction. Specifically, we have redesigned certain characters to enhance their acoustic distinctiveness without compromising the natural handwriting style of users, ensuring the system userfriendly. Our system combines DenseNet and GRU architectures in a multimodal model, refined through transfer learning to adapt to diverse user behaviors. Tested in real-world scenarios with 10 participants, our system achieves a 95% accuracy in recognizing both letters and numbers.
Yilin Wang 0034, Zi Wang 0003, Jie Yang 0003
ICCCN3
2023 Person Re-identification in 3D Space: A WiFi Vision-based Approach
Yili Ren, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
USENIX Security Symposium5
2023 A Phoneme Localization Based Liveness Detection for Text-Independent Speaker Verification
abstract
Voice authentication is drawing increasing attention and becomes an attractive alternative to passwords for mobile authentication. Recent advances in mobile technology further accelerate the adoption of voice biometrics in an array of diverse mobile applications. However, recent studies show that voice authentication is vulnerable to replay attacks, where an adversary can spoof a voice authentication system using a pre-recorded voice sample collected from the victim. In this article, we propose VoiceLive, a liveness detection system for both text-dependent and text-independent voice authentication on smartphones. VoiceLive detects a live user by leveraging the user's unique vocal system and the stereo recording of smartphones. In particular, utilizing the built-in gyroscope, loudspeaker and microphone, VoiceLive first measures the smartphone's distance and angle from the user, then it captures the position specific time-difference-of-arrival (TDoA) changes in a sequence of phoneme sounds to the two microphones of the phone, and uses such unique TDoA dynamic which doesn't exist under replay attacks for liveness detection. VoiceLive is practical as it doesn't require additional hardware but two-channel stereo recording that is supported by virtually all smartphones. Our experimental evaluation with 12 participants and different types of phones shows that VoiceLive achieves over 99% detection accuracy at around 1% Equal Error Rate (EER) on the text-dependent system and around 99% accuracy and 2% EER on the text-independent one. Results also show that VoiceLive is robust to different phone positions, i.e., the user are free to hold the smartphone with distinct distances and angles.
Linghan Zhang, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
IEEE Trans. Mob. Comput.4
2022 Poster: A WiFi Vision-based Approach to Person Re-identification
abstract
In this work, we propose a WiFi vision-based approach to person re-identification (Re-ID) indoors. Our approach leverages the advances of WiFi to visualize a person and utilizes deep learning to help WiFi devices identify and recognize people. Specifically, we leverage multiple antennas on WiFi devices to estimate the two-dimensional angle of arrival (2D AoA) of the WiFi signal reflections to enable WiFi devices to "see'' a person. We then utilize deep learning techniques to extract a 3D mesh representation of a person and extract the body shape and walking patterns for person Re-ID. Our preliminary study shows that our system achieves high overall ranking accuracies. It also works under non-line-of-sight and different person appearance conditions, where the traditional camera vision-based systems do not work well.
Yili Ren, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
CCS5
2022 Poster: Fingerprint-Face Friction Based Earable Authentication
abstract
Ear wearables (earables) have become an emerging and wide acceptable platform for various applications. Because of the limited input interface of earables, traditional authentication methods become less desired. However, the feature-rich sensing abilities of earables and the unique human face-ear channel bring us new sensing opportunities to reutilize fingerprints. In this work, we proposed SlidePass, a secure earables authentication system that leverages the finger-face acoustic friction produced by sliding finger gestures on the face. In particular, our system leverages the inward-facing microphone of the earables to reliably capture the acoustic of finger-face frictions. The core insight of our system is to utilize the face as a natural scanner for finger-face friction and earables to capture and reconstruct the fingerprint features. SlidePass is specially designed for earables. Due to the finger-face friction captured and encrypted by the face channel that is unique and hidden in the human skull, SlidePass is more resistant to various spoofing attacks. Our preliminary evaluation included ten different fingerprints showing that SlidePass achieves an average accuracy of 94%.
Zi Wang 0003, Yilin Wang 0034, Yingying Chen 0001, Jie Yang 0003
CCS4
2022 Person re-identification using wifi signals
abstract
Person re-identification (Re-ID) has become increasingly important as it supports a wide range of security applications. In this work, we propose a WiFi-based person Re-ID system in 3D space, which leverages the advances of WiFi and deep learning to extract the static body shape and dynamic walking patterns to recognize people. In particular, we leverage multiple antennas on WiFi devices to capture signal reflections of the human body and produce a WiFi image of a person. We then leverage deep learning to extract both the static body shape and dynamic walking patterns for person Re-ID. Our evaluation results show that our system achieves an overall rank-1 accuracy of 87.1%.
Yili Ren, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
MobiCom5
2022 A wifi vision-based 3D human mesh reconstruction
abstract
In this work, we present, Wi-Mesh, a WiFi vision-based 3D human mesh construction system. Our system leverages the advances of WiFi to visualize the shape and deformations of the human body for 3D mesh construction. In particular, it estimates the two-dimensional angle of arrival (2D AoA) of the WiFi signal reflections to enable WiFi devices to "see" the physical environment as we humans do. It then extracts only the images of the human body from the physical environment, and leverages deep learning models to digitize the extracted human body into 3D mesh representation. Experimental evaluation under various indoor environments shows that Wi-Mesh achieves an average vertices location error of 2.58cm and joint position error of 2.24cm.
Yili Ren, Yingying Chen 0001, Jie Yang 0003
MobiCom4
2022 Liquid level detection using wireless signals
abstract
Sensing the liquid level in a container is critical to building many smart home and mobile healthcare applications. This paper presents a liquid level sensing system that is low-cost, high accuracy, widely applicable to different daily liquids and containers, and can be easily integrated with existing smart home networks. Our system uses an existing home WiFi network and a low-cost transducer that is attached to the container to sense the resonance of the container for liquid level detection. We evaluate our system in home environments with various containers and liquids. Preliminary results show that our system achieves an accuracy of 97% for continuous prediction and an F-score of 0.968 for discrete prediction.
Yili Ren, Zi Wang 0003, Beiyu Wang, Sheng Tan, Jie Yang 0003
MobiSys5
2022 A Vision-Based Approach for Commodity WiFi Sensing
abstract
The ubiquitous WiFi signals provide us the opportunity to sense human activities and the physical environment. In this work, we take a layered approach to design a vision-based method for commodity WiFi sensing. Specifically, the next-generation WiFi supports a larger number of antennas that can provide spatial information of the signal reflections, which enables a vision-based approach for WiFi sensing. To better leverage the spatial formation of the signal reflections and fulfill emerging applications, we provide a holistic layered framework including hardware, physical, deep learning, and application layers as well as a case study. The proposed layered approach could enlighten the research on future WiFi sensing.
Yili Ren, Yingying Chen 0001, Jie Yang 0003
SenSys4
2022 Wi-Mesh: A WiFi Vision-Based Approach for 3D Human Mesh Construction
abstract
In this paper, we present, Wi-Mesh, a WiFi vision-based 3D human mesh construction system. Our system leverages the advances of WiFi to visualize the shape and deformations of the human body for 3D mesh construction. In particular, it leverages multiple transmitting and receiving antennas on WiFi devices to estimate the two-dimensional angle of arrival (2D AoA) of the WiFi signal reflections to enable WiFi devices to "see" the physical environment as we humans do. It then extracts only the images of the human body from the physical environment, and leverages deep learning models to digitize the extracted human body into a 3D mesh representation. Experimental evaluation under various indoor environments shows that Wi-Mesh achieves an average vertices location error of 2.81cm and joint position error of 2.4cm, which is comparable to the systems that utilize specialized and dedicated hardware. The proposed system has the advantage of reusing the WiFi devices that already exist in the environment for potential mass adoption. It can also work in non-line of sight (NLoS), poor lighting conditions, and baggy clothes, where the camera-based systems do not work well.
Yili Ren, Yingying Chen 0001, Jie Yang 0003
SenSys4
2022 Commodity WiFi Sensing in Ten Years: Status, Challenges, and Opportunities
abstract
The prevalence of WiFi devices and ubiquitous coverage of WiFi networks provide us the opportunity to extend WiFi capabilities beyond communication, particularly in sensing the physical environment. In this article, we survey the evolution of WiFi sensing systems utilizing commodity devices over the past decade. It groups WiFi sensing systems into three main categories: 1) activity recognition (large scale and small scale); 2) object sensing; and 3) localization. We highlight the milestone work in each category and the underline techniques they adopted. Next, this work presents the challenges faced by existing WiFi sensing systems. Finally, we comprehensively discuss the future trending of commodity WiFi sensing.
Sheng Tan, Yili Ren, Jie Yang 0003, Yingying Chen 0001
IEEE Internet Things J.3
2022 A Continuous Articulatory-Gesture-Based Liveness Detection for Voice Authentication on Smart Devices
abstract
Voice biometrics is drawing increasing attention to user authentication on smart devices. However, voice biometrics is vulnerable to replay attacks, where adversaries try to spoof voice authentication systems using prerecorded voice samples collected from genuine users. To this end, we propose VoiceGesture, a liveness detection solution for voice authentication on smart devices, such as smartphones and smart speakers. With audio hardware advances on smart devices, VoiceGesture leverages built-in speaker and microphone pairs on smart devices as Doppler radar to sense articulatory gestures for liveness detection during voice authentication. The experiments with 21 participants and different smart devices show that VoiceGesture achieves over 99% and around 98% detection accuracy for text-dependent and text-independent liveness detection, respectively. Moreover, VoiceGesture is robust to different device placements, low audio sampling frequency, and supports medium-range liveness detection on smart speakers in various use scenarios, including smart homes and smart vehicles.
Linghan Zhang, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
IEEE Internet Things J.4
2022 Enabling Fine-Grained Finger Gesture Recognition on Commodity WiFi Devices
abstract
Gesture recognition has become increasingly important in human-computer interaction and can support different applications such as smart home, VR, and gaming. Traditional approaches usually rely on dedicated sensors that are worn by the user or cameras that require line of sight. In this paper, we present a fine-grained finger gesture recognition system by using commodity WiFi without requiring user to wear any sensors. Our system takes advantages of the fine-grained Channel State Information available from commodity WiFi devices and the prevalence of WiFi network infrastructures. It senses and identifies subtle movements of finger gestures by examining the unique patterns exhibited in the detailed CSI. We devise environmental noise removal mechanism to mitigate the effect of signal dynamic due to the environment changes. Moreover, we propose to capture the intrinsic gesture behavior to deal with individual diversity and gesture inconsistency. Lastly, we utilize multiple WiFi links and larger bandwidth at 5GHz to achieve finger gesture recognition under multi-user scenario. Our experimental evaluation in different environments demonstrates that our system can achieve over 90 percent recognition accuracy and is robust to both environment changes and individual diversity. Results also show that our system can provide accurate gesture recognition under different scenarios.
Sheng Tan, Jie Yang 0003, Yingying Chen 0001
IEEE Trans. Mob. Comput.2
2021 Earable Authentication via Acoustic Toothprint
abstract
Earables (ear wearable) are rapidly emerging as a new platform to enable a variety of personal applications. The traditional authentication methods thus become less applicable and inconvenient for earables due to their limited input interface. Earables, however, often feature rich around the head sensing capability that can be leveraged to capture new types of biometrics. In this work, we propose ToothSonic that leverages the toothprint-induced sonic effect produced by a user performing teeth gestures for user authentication. In particular, we design several representative teeth gestures that can produce effective sonic waves carrying the information of the toothprint. To reliably capture the acoustic toothprint, it leverages the occlusion effect of the ear canal and the inward-facing microphone of the earables. It then extracts multi-level acoustic features to represent the intrinsic acoustic toothprint for authentication. The key advantages of ToothSonic are that it is suitable for earables and is resistant to various spoofing attacks as the acoustic toothprint is captured via the private teeth-ear channel of the user that is unknown to others. Our preliminary studies with 20 participants show that ToothSonic achieves 97% accuracy with only three teeth gestures.
Zi Wang 0003, Yili Ren, Yingying Chen 0001, Jie Yang 0003
CCS4
2021 Tracking free-form activity using wifi signals
abstract
WiFi human sensing has become increasingly attractive in enabling emerging human-computer interaction applications. The corresponding technique has gradually evolved from the classification of multiple activity types to more fine-grained tracking of 3D human poses. However, existing WiFi-based 3D human pose tracking is limited to a set of predefined activities. In this work, we present Winect, a 3D human pose tracking system for free-form activity using commodity WiFi devices. Our system tracks free-form activity by estimating a 3D skeleton pose that consists of a set of joints of the human body. In particular, Winect first identifies the moving limbs by leveraging the signals reflected off the human body and separates the entangled signals for each limb. Then, our system tracks each limb and constructs a 3D skeleton of the body by modeling the inherent relationship between the movements of the limb and the corresponding joints. Our evaluation results show that Winect achieves centimeter-level accuracy for free-form activity tracking under various environments.
Yili Ren, Zi Wang 0003, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
MobiCom5
2021 An ear canal deformation based continuous user authentication using earables
abstract
Biometric-based authentication is gaining increasing attention for wearables and mobile applications. Meanwhile, the growing adoption of sensors in wearables also provides opportunities to capture novel wearable biometrics. In this work, we propose EarDynamic, an ear canal deformation based user authentication using ear wearables (earables). EarDynamic provides continuous and passive user authentication and is transparent to users. It leverages ear canal deformation that combines the unique static geometry and dynamic motions of the ear canal when the user is speaking for authentication. It utilizes an acoustic sensing approach to capture the ear canal deformation with the built-in microphone and speaker of the earables. Specifically, it first emits well-designed inaudible beep signals and records the reflected signals from the ear canal. It then analyzes the reflected signals and extracts fine-grained acoustic features that correspond to the ear canal deformation for user authentication. Our experimental evaluation shows that EarDynamic can achieve a recall of 97.38% and an F1 score of 96.84%.
Zi Wang 0003, Sheng Tan, Linghan Zhang, Yili Ren, Zhi Wang 0004, Jie Yang 0003
MobiCom6
2021 3D Human Pose Estimation Using WiFi Signals
abstract
This paper presents GoPose, a 3D skeleton-based human pose estimation system that uses commodity WiFi devices at home. Our system leverages the WiFi signals reflected off the human body for 3D pose estimation. In contrast to prior systems that need dedicated sensors, our system does not require a user to wear any sensors and can reuse the WiFi devices that already exist in a home environment for mass adoption. To realize such a system, we leverage the 2D AoA estimation of the signals reflected from the human body and the deep learning techniques. Preliminary results show GoPose achieves a high accuracy of 4.5cm in various scenarios.
Yili Ren, Zi Wang 0003, Sheng Tan, Yingying Chen 0001, Jie Yang 0003
SenSys6
2020 VibLive: A Continuous Liveness Detection for Secure Voice User Interface in IoT Environment
abstract
The voice user interface (VUI) has been progressively used to authenticate users to numerous devices and applications. Such massive adoption of VUIs in IoT environments like individual homes and businesses arises extensive privacy and security concerns. Latest VUIs adopting traditional voice authentication methods are vulnerable to spoofing attacks, where a malicious party spoofs the VUIs with pre-recorded or synthesized voice commands of the genuine user. In this paper, we design VibLive, a continuous liveness detection system for secure VUIs in IoT environments. The underlying principle of VibLive is to catch the dissimilarities between bone-conducted vibrations and air-conducted voices when human speaks for liveness detection. VibLive is a text-independent system that verifies live users and detects spoofing attacks without requiring users to enroll specific passphrases. Moreover, VibLive is practical and transparent as it requires neither additional operations nor extra hardwares, other than a loudspeaker and a microphone that are commonly equipped on VUIs. Our evaluation with 25 participants under different IoT intended experiment settings shows that VibLive is highly effective with over 97% detection accuracy. Results also show that VibLive is robust to various use scenarios.
Linghan Zhang, Sheng Tan, Zi Wang 0003, Yili Ren, Zhi Wang 0004, Jie Yang 0003
ACSAC6
2020 Signature Verification Using Critical Segments for Securing Mobile Transactions
abstract
The explosive usage of mobile devices enables conducting electronic transactions involving direct signature on such devices. Thus, user signature verification becomes critical to ensure the success deployment of online transactions such as approving legal documents and authenticating financial transactions. Existing approaches mainly focus on user verification targeting the unlocking of mobile devices or performing continuous verification based on a user's behavioral traits. Few studies provide efficient real-time user signature verification. In this work, we propose a critical segment based online signature verification system to secure mobile transactions on multi-touch mobile devices. Our system identifies and exploits the segments which remain invariant within a user's signature to capture the intrinsic signing behavior embedded in each user's signature. Our system extracts useful features from a user's signature that describe both the geometric layout of the signature as well as behavioral and physiological characteristics in the user's signing process. Given the input signatures for user enrollment, our system further designs a quality score to identify the problematic signature sets to achieve robust user signature profile construction. Moreover, we develop the signature normalization and interpolation methods to achieve robust signature verification in the presence of signature geometric distortions caused by different writing sizes, orientations and locations on touch screens. Our experimental evaluation of 25 subjects over six months time period shows that our system is highly accurate in provide signature verification and robust to signature forging attacks.
Yanzhi Ren, Chen Wang 0009, Yingying Chen 0001, Mooi Choo Chuah, Jie Yang 0003
IEEE Trans. Mob. Comput.5
2019 MultiTrack: Multi-User Tracking and Activity Recognition Using Commodity WiFi
abstract
This paper presents MultiTrack, a commodity WiFi based human sensing system that can track multiple users and recognize activities of multiple users performing them simultaneously. Such a system can enable easy and large-scale deployment for multi-user tracking and sensing without the need for additional sensors through the use of existing WiFi devices (e.g., desktops, laptops and smart appliances). The basic idea is to identify and extract the signal reflection corresponding to each individual user with the help of multiple WiFi links and all the available WiFi channels at 5GHz. Given the extracted signal reflection of each user, MultiTrack examines the path of the reflected signals at multiple links to simultaneously track multiple users. It further reconstructs the signal profile of each user as if only a single user has performed activity in the environment to facilitate multi-user activity recognition. We evaluate MultiTrack in different multipath environments with up to 4 users for multi-user tracking and up to 3 users for activity recognition. Experimental results show that our system can achieve decimeter localization accuracy and over 92% activity recognition accuracy under multi-user scenarios.
Sheng Tan, Linghan Zhang, Zi Wang 0003, Jie Yang 0003
CHI4
2019 Origin-sensitive Control Flow Integrity
Mustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang 0004, Jie Yang 0003
USENIX Security Symposium5
2019 Noninvasive Fine-Grained Sleep Monitoring Leveraging Smartphones
abstract
Sleep monitoring has drawn increasing attention as sleep quality is important to maintain a person's well-being. For instance, serious health problems, such as cardiovascular disease, fatigue, or depression, are usually associated with inadequate and irregular sleep. Traditional sleep monitoring systems involve wearable sensors with professional installation, and thus are usually limited to clinical usage. Recent work for sleep monitoring can detect several sleep events, such as coughing and snoring, using smartphone sensors. However, such coarse-grained sleep monitoring is unable to detect the breathing rate which is an important health indicator. In this paper, we present a fine-grained sleep monitoring system to detect the breathing rate and sleep events simultaneously by leveraging smartphones. Our system exploits the readily available smartphone earphone placed close to the user to reliably capture the human breathing sound. Given the captured acoustic sound, noise reduction is performed to remove the environmental noise and the breathing rate is then identified based on the signal envelope detection. Our system can further detect some sleep events, including snoring, coughing, turning over, and getting up, based on the features extracted from the acoustic sound. Moreover, we develop a body movement-assisted sleep event detection method to provide higher detection accuracy by further exploiting the user's body movement patterns captured by the accelerometer embedded on smartphones. Our extensive experiments involving nine subjects over six months confirm the effectiveness of our proposed system on breathing rate monitoring and sleep events detection under various environments. By combining breathing rate and sleep events, our system can provide noninvasive and continuous fine-grained sleep monitoring for healthcare related applications, such as sleep apnea monitoring, as evidenced by our experimental study.
Yanzhi Ren, Chen Wang 0009, Yingying Chen 0001, Jie Yang 0003, Hongwei Li 0001
IEEE Internet Things J.4
2019 Implications of smartphone user privacy leakage from the advertiser's perspective
Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003, Hongbo Liu 0002, Jie Yang 0003
Pervasive Mob. Comput.5
2018 Sensing Fruit Ripeness Using Wireless Signals
abstract
This paper presents FruitSense, a novel fruit ripeness sensing system that leverages wireless signals to enable non-destructive and low-cost detection of fruit ripeness. Such a system can reuse existing WiFi devices in homes without the need for additional sensors. It uses WiFi signals to sense the physiological changes associated with fruit ripening for detecting the ripeness of fruit. FruitSense leverages the larger bandwidth at 5GHz (i.e., over 600MHz) to extract the multipath-independent signal components to characterize the physiological compounds of the fruit. It then measures the similarity between the extracted features and the ones in ripeness profiles for identifying the ripeness level. We evaluate FruitSense in different multipath environments with two types of fruits (i.e, kiwi and avocado) under four levels of ripeness. Experimental results show that FruitSense can detect the ripeness levels of fruits with an accuracy over 90%.
Sheng Tan, Linghan Zhang, Jie Yang 0003
ICCCN3
2018 Monitoring Vital Signs and Postures During Sleep Using WiFi Signals
abstract
Tracking human sleeping postures and vital signs of breathing and heart rates during sleep is important as it can help to assess the general physical health of a person and provide useful clues for diagnosing possible diseases. Traditional approaches (e.g., polysomnography) are limited to clinic usage. Recent radio frequency-based approaches require specialized devices or dedicated wireless sensors and are only able to track breathing rate. In this paper, we propose to track the vital signs of both breathing rate and heart rate during sleep by using off-the-shelf WiFi without any wearable or dedicated devices. Our system reuses existing WiFi network and exploits the fine-grained channel information to capture the minute movements caused by breathing and heart beats. Our system thus has the potential to be widely deployed and perform continuous long-term monitoring. The developed algorithm makes use of the channel information in both time and frequency domain to estimate breathing and heart rates, and it works well when either individual or two persons are in bed. Our extensive experiments demonstrate that our system can accurately capture vital signs during sleep under realistic settings, and achieve comparable or even better performance comparing to traditional and existing approaches, which is a strong indication of providing noninvasive, continuous fine-grained vital signs monitoring without any additional cost.
Jian Liu 0001, Yingying Chen 0001, Yan Wang 0003, Xu Chen 0011, Jerry Q. Cheng, Jie Yang 0003
IEEE Internet Things J.6
2018 Authenticating Users Through Fine-Grained Channel Information
abstract
User authentication is the critical first step in detecting identity-based attacks and preventing subsequent malicious attacks. However, the increasingly dynamic mobile environments make it harderto always apply cryptographic-based methods for user authentication due to their infrastructural and key management overhead. Exploiting non-cryptographic based techniques grounded on physical layer properties to perform user authentication appears promising. In this work, the use of channel state information (CSI), which is available from off-the-shelf WiFi devices, to perform fine-grained user authentication is explored. Particularly, a user-authentication framework that can work with both stationary and mobile users is proposed. When the user is stationary, the proposed framework builds a user profile for user authentication that is resilient to the presence of a spoofer. The proposed machine learning based user-authentication techniques can distinguish between two users even when they possess similar signal fingerprints and detect the existence of a spoofer. When the user is mobile, it is proposed to detect the presence of a spoofer by examining the temporal correlation of CSI measurements. Both office building and apartment environments show that the proposed framework can filter out signal outliers and achieve higher authentication accuracy compared with existing approaches using received signal strength (RSS).
Hongbo Liu 0002, Yan Wang 0003, Jian Liu 0001, Jie Yang 0003, Yingying Chen 0001, H. Vincent Poor
IEEE Trans. Mob. Comput.4
2017 Hearing Your Voice is Not Enough: An Articulatory Gesture Based Liveness Detection for Voice Authentication
abstract
Voice biometrics is drawing increasing attention as it is a promising alternative to legacy passwords for mobile authentication. Recently, a growing body of work shows that voice biometrics is vulnerable to spoofing through replay attacks, where an adversary tries to spoof voice authentication systems by using a pre-recorded voice sample collected from a genuine user. In this work, we propose VoiceGesture, a liveness detection system for replay attack detection on smartphones. It detects a live user by leveraging both the unique articulatory gesture of the user when speaking a passphrase and the mobile audio hardware advances. Specifically, our system re-uses the smartphone as a Doppler radar, which transmits a high frequency acoustic sound from the built-in speaker and listens to the reflections at the microphone when a user speaks a passphrase. The signal reflections due to user's articulatory gesture result in Doppler shifts, which are then analyzed for live user detection. VoiceGesture is practical as it requires neither cumbersome operations nor additional hardware but a speaker and a microphone that are commonly available on smartphones. Our experimental evaluation with 21 participants and different types of phones shows that it achieves over 99% detection accuracy at around 1% Equal Error Rate (EER). Results also show that it is robust to different phone placements and is able to work with different sampling frequencies.
Linghan Zhang, Sheng Tan, Jie Yang 0003
CCS3
2017 Enabling Self-Healing Smart Grid Through Jamming Resilient Local Controller Switching
abstract
A key component of a smart grid is its ability to collect useful information from a power grid for enabling control centers to estimate the current states of the power grid. Such information can be delivered to the control centers via wireless or wired networks. It is envisioned that wireless technology will be widely used for local-area communication subsystems in the smart grid (e.g., in distribution networks). However, various attacks with serious impact can be launched in wireless networks such as channel jamming attacks and denial-of-service attacks. In particular, jamming attacks can cause significant damages to power grids, e.g., delayed delivery of time-critical messages can prevent control centers from properly controlling the outputs of generators to match load demands. In this paper, a communication subsystem with enhanced self-healing capability in the presence of jamming is designed via intelligent local controller switching while integrating a retransmission mechanism. The proposed framework allows sufficient readings from smart meters to be continuously collected by various local controllers to estimate the states of a power grid under various attack scenarios. The jamming probability is also analyzed considering the impact of jammer power and shadowing effects. In addition, guidelines on optimal placement of local controllers to ensure effective switching of smart meters under jamming are provided. Via theoretical, experimental and simulation studies, it is demonstrated that our proposed system is effective in maintaining communications between smart meters and local controllers even when multiple jammers are present in the network.
Hongbo Liu 0002, Yingying Chen 0001, Mooi Choo Chuah, Jie Yang 0003, H. Vincent Poor
IEEE Trans. Dependable Secur. Comput.4
2017 Locating Rogue Access Point Using Fine-Grained Channel Information
abstract
Rogue access point (AP) has emerged as an important security problem in WLANs. However, it is a challenge task to localize the rogue AP with both high accuracy and minimal infrastructure cost. Either expensive professional infrastructure (e.g., multiple wireless sniffers) or additional hardware (e.g., directional antenna) need to be pre-deployed for rogue AP localization with high cost. Moreover, existing methods using Received Signal Strength (RSS) result in a large error as RSS is suffered from the multipath and shadowing effects in complex wireless environment. In this work, we exploit the channel state information (CSI), which is readily available from commercial Wi-Fi devices, to locate the rogue AP with high accuracy. We use only a single off-the-shelf Wi-Fi device for rogue AP localization which involves minimal infrastructure requirement. Our proposed rogue AP localization framework consists of two components: direction determination and position estimation. The direction determination can be carried out by using the human blocking effect on the CSI amplitude or phase. The multiple antennas on the Wi-Fi devices can be further utilized to enhance the rogue AP direction estimation. Given the estimated direction, two schemes are proposed to pinpoint the position of the rogue AP: determining directions at multiple locations grounded on triangulation and walking towards the rogue AP with direction adjustment. Results from extensive experiments in both indoor and outdoor environments show that our framework can achieve more practical and accurate rogue AP localization when comparing with the existing RSS-based approach.
Chen Wang 0009, Xiuyuan Zheng, Yingying Chen 0001, Jie Yang 0003
IEEE Trans. Mob. Comput.4
2016 VoiceLive: A Phoneme Localization based Liveness Detection for Voice Authentication on Smartphones
abstract
Voice authentication is drawing increasing attention and becomes an attractive alternative to passwords for mobile authentication. Recent advances in mobile technology further accelerate the adoption of voice biometrics in an array of diverse mobile applications. However, recent studies show that voice authentication is vulnerable to replay attacks, where an adversary can spoof a voice authentication system using a pre-recorded voice sample collected from the victim. In this paper, we propose VoiceLive, a practical liveness detection system for voice authentication on smartphones. VoiceLive detects a live user by leveraging the user's unique vocal system and the stereo recording of smartphones. In particular, with the phone closely placed to a user's mouth, it captures time-difference-of-arrival (TDoA) changes in a sequence of phoneme sounds to the two microphones of the phone, and uses such unique TDoA dynamic which doesn't exist under replay attacks for liveness detection. VoiceLive is practical as it doesn't require additional hardware but two-channel stereo recording that is supported by virtually all smartphones. Our experimental evaluation with 12 participants and different types of phones shows that VoiceLive achieves over 99% detection accuracy at around 1% Equal Error Rate (EER). Results also show that VoiceLive is robust to different phone placements and is compatible to different sampling rates and phone models.
Linghan Zhang, Sheng Tan, Jie Yang 0003, Yingying Chen 0001
CCS3
2016 Leveraging wearables for steering and driver tracking
abstract
Given the increasing popularity of wearable devices, this paper explores the potential to use wearables for steering and driver tracking. Such capability would enable novel classes of mobile safety applications without relying on information or sensors in the vehicle. In particular, we study how wrist-mounted inertial sensors, such as those in smart watches and fitness trackers, can track steering wheel usage and angle. In particular, tracking steering wheel usage and turning angle provide fundamental techniques to improve driving detection, enhance vehicle motion tracking by mobile devices and help identify unsafe driving. The approach relies on motion features that allow distinguishing steering from other confounding hand movements. Once steering wheel usage is detected, it further uses wrist rotation measurements to infer steering wheel turning angles. Our on-road experiments show that the technique is 99% accurate in detecting steering wheel usage and can estimate turning angles with an average error within 3.4 degrees.
Çagdas Karatas, Jian Liu 0001, Yan Wang 0003, Sheng Tan, Jie Yang 0003, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
INFOCOM7
2016 WiFinger: leveraging commodity WiFi for fine-grained finger gesture recognition
abstract
Gesture recognition has become increasingly important in human-computer interaction (HCI) and can support a broad array of emerging applications, such as smart home, virtual reality, and mobile gaming. Traditional approaches usually rely on dedicated sensors that are worn by the user or cameras that require line of sight. In this paper, we present fine-grained finger gesture recognition by using a single commodity WiFi device without requiring user to wear any sensors. Our low-cost system, WiFinger, takes advantages of the fine-grained Channel State Information (CSI) available from commodity WiFi devices and the prevalence of WiFi network infrastructures. It senses and identifies subtle movements of finger gestures by examining the unique patterns exhibited in the detailed CSI. In WiFigner, we devise environmental noise removal mechanism to mitigate the effect of signal dynamic due to the environment changes. Moreover, we propose to capture the intrinsic gesture behavior to deal with individual diversity and gesture inconsistency. Our experimental evaluation in both home and office environments demonstrates that our system can achieve over 93% recognition accuracy and is robust to both environment changes and individual diversity. Results also show that our system can work with WiFi beacon signals and provides accurate gesture recognition under NLOS scenarios.
Sheng Tan, Jie Yang 0003
MobiHoc2
2016 Determining Driver Phone Use by Exploiting Smartphone Integrated Sensors
abstract
This paper utilizes smartphone sensing of vehicle dynamics to determine driver phone use, which can facilitate many traffic safety applications. Our system uses embedded sensors in smartphones, i.e., accelerometers and gyroscopes, to capture differences in centripetal acceleration due to vehicle dynamics. These differences combined with angular speed can determine whether the phone is on the left or right side of the vehicle. Our low infrastructure approach is flexible with different turn sizes and driving speeds. Extensive experiments conducted with two vehicles in two different cities demonstrate that our system is robust to real driving environments. Despite noisy sensor readings from smartphones, our approach can achieve a classification accuracy of over 90 percent with a false positive rate of a few percent. We also find that by combining sensing results in a few turns, we can achieve better accuracy (e.g., 95 percent) with a lower false positive rate. In addition, we seek to exploit the electromagnetic field measurement inside a vehicle to complement vehicle dynamics for driver phone sensing under the scenarios when little vehicle dynamics is present, for example, driving straight on highways or standing at roadsides.
Yan Wang 0003, Yingying Chen 0001, Jie Yang 0003, Marco Gruteser, Richard P. Martin, Hongbo Liu 0002, Çagdas Karatas
IEEE Trans. Mob. Comput.3
2015 Towards Understanding the Advertiser's Perspective of Smartphone User Privacy
abstract
Many smartphone apps routinely gather various private user data and send them to advertisers. Despite recent study on protection mechanisms and analysis on apps' behavior, the understanding about the consequences of such privacy losses remains limited. In this paper we investigate how much an advertiser can infer about users' social and community relationships by combining data from multiple applications and across many users. After one month's user study involving about 200 most popular Android apps, we find that an advertiser can infer 90% of the social relationships. We further propose a privacy leakage inference framework and use real mobility traces and Foursquare data to quantify the consequences of privacy leakage. We find that achieving 90% inference accuracy of the social and community relationships requires merely 3 weeks' user data. The discoveries underscore the importance of early adoption of privacy protection mechanisms.
Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003, Jie Yang 0003, Hongbo Liu 0002
ICDCS4
2015 Fine-grained sleep monitoring: Hearing your breathing with smartphones
abstract
Sleep monitoring has drawn increasingly attention as the quality and quantity of the sleep are important to maintain a person's health and well-being. For example, inadequate and irregular sleep are usually associated with serious health problems such as fatigue, depression and cardiovascular disease. Traditional sleep monitoring systems, such as PSG, involve wearable sensors with professional installations, and thus are limited to clinical usage. Recent work in using smartphone sensors for sleep monitoring can detect several events related to sleep, such as body movement, cough and snore. Such coarse-grained sleep monitoring however is unable to detect the breathing rate which is an important vital sign and health indicator. This work presents a fine-grained sleep monitoring system which is capable of detecting the breathing rate by leveraging smartphones. Our system exploits the readily available smartphone earphone placed close to the user to reliably capture the human breathing sound. Given the captured acoustic sound, our system performs noise reduction to remove environmental noise and then identifies the breathing rate based on the signal envelope detection. Our system can further detect detailed sleep events including snore, cough, turn over and get up based on the acoustic features extracted from the acoustic sound. Our experimental evaluation of six subjects over six months time period demonstrates that the breathing rate monitoring and sleep events detection are highly accurate and robust under various environments. By combining breathing rate and sleep events, our system can provide continuous and noninvasive fine-grained sleep monitoring for healthcare related applications, such as sleep apnea monitoring as evidenced by our experimental study.
Yanzhi Ren, Chen Wang 0009, Jie Yang 0003, Yingying Chen 0001
INFOCOM3
2015 Snooping Keystrokes with mm-level Audio Ranging on a Single Phone
abstract
This paper explores the limits of audio ranging on mobile devices in the context of a keystroke snooping scenario. Acoustic keystroke snooping is challenging because it requires distinguishing and labeling sounds generated by tens of keys in very close proximity. Existing work on acoustic keystroke recognition relies on training with labeled data, linguistic context, or multiple phones placed around a keyboard --- requirements that limit usefulness in an adversarial context. In this work, we show that mobile audio hardware advances can be exploited to discriminate mm-level position differences and that this makes it feasible to locate the origin of keystrokes from only a single phone behind the keyboard. The technique clusters keystrokes using time-difference of arrival measurements as well as acoustic features to identify multiple strokes of the same key. It then computes the origin of these sounds precise enough to identify and label each key. By locating keystrokes this technique avoids the need for labeled training data or linguistic context. Experiments with three types of keyboards and off-the-shelf smartphones demonstrate scenarios where our system can recover $94\%$ of keystrokes, which to our knowledge, is the first single-device technique that enables acoustic snooping of passwords.
Jian Liu 0001, Yan Wang 0003, Gorkem Kar, Yingying Chen 0001, Jie Yang 0003, Marco Gruteser
MobiCom5
2015 Tracking Vital Signs During Sleep Leveraging Off-the-shelf WiFi
abstract
Tracking human vital signs of breathing and heart rates during sleep is important as it can help to assess the general physical health of a person and provide useful clues for diagnosing possible diseases. Traditional approaches (e.g., Polysomnography (PSG)) are limited to clinic usage. Recent radio frequency (RF) based approaches require specialized devices or dedicated wireless sensors and are only able to track breathing rate. In this work, we propose to track the vital signs of both breathing rate and heart rate during sleep by using off-the-shelf WiFi without any wearable or dedicated devices. Our system re-uses existing WiFi network and exploits the fine-grained channel information to capture the minute movements caused by breathing and heart beats. Our system thus has the potential to be widely deployed and perform continuous long-term monitoring. The developed algorithm makes use of the channel information in both time and frequency domain to estimate breathing and heart rates, and it works well when either individual or two persons are in bed. Our extensive experiments demonstrate that our system can accurately capture vital signs during sleep under realistic settings, and achieve comparable or even better performance comparing to traditional and existing approaches, which is a strong indication of providing non-invasive, continuous fine-grained vital signs monitoring without any additional cost.
Jian Liu 0001, Yan Wang 0003, Yingying Chen 0001, Jie Yang 0003, Xu Chen 0011, Jerry Q. Cheng
MobiHoc4
2015 Sensing Ambient Light for User Experience-Oriented Color Scheme Adaptation on Smartphone Displays
abstract
With the rapid development of information technology, mobile devices have exhibited increasing popularity in recent years. To support the anytime-anywhere service model of mobile devices, one important problem related to the screen display arises when using these devices (e.g., smartphone and tablet) under various lighting conditions. On one hand, it is hard for users to see the display clearly under strong lighting conditions (e.g., sunlight). On the other hand, the screen appears dazzling under weak lighting conditions. This problem related to the mobile device display can significantly degrade user experience and undermine the successful deployment of the anytime-anywhere mobile service model. Existing solutions mainly focus on the automatic adjustment of brightness level under different light conditions. We show that merely utilizing brightness level to solve the display problem is not enough to maintain the user experience under both strong and weak lighting scenarios through experimenting with over 200 volunteers. In this work, we take a different approach by investigating automatic color scheme adjustment to improve user experience. We find that Readability, Comfort level and Similarity are major factors that contribute to user experience. In recognizing these problems, we propose a system, ColorVert, which utilizes the DKL color space to adaptively transform color schemes by sensing ambient light to improve user experience under various lighting scenarios. Our experimental evaluation with over 200 precipitants and various mobile devices demonstrates that ColorVert is more effective in both maintaining as well as improving user experience compared with the existing automatic brightness adjustment system.
Jiadi Yu, Yingying Chen 0001, Jie Yang 0003
SenSys4
2015 User Verification Leveraging Gait Recognition for Smartphone Enabled Mobile Healthcare Systems
abstract
The rapid deployment of sensing technology in smartphones and the explosion of their usage in people's daily lives provide users with the ability to collectively sense the world. This leads to a growing trend of mobile healthcare systems utilizing sensing data collected from smartphones with/without additional external sensors to analyze and understand people's physical and mental states. However, such healthcare systems are vulnerable to user spoofing, in which an adversary distributes his registered device to other users such that data collected from these users can be claimed as his own to obtain more healthcare benefits and undermine the successful operation of mobile healthcare systems. Existing mitigation approaches either only rely on a secret PIN number (which can not deal with colluded attacks) or require an explicit user action for verification. In this paper, we propose a user verification system leveraging unique gait patterns derived from acceleration readings to detect possible user spoofing in mobile healthcare systems. Our framework exploits the readily available accelerometers embedded within smartphones for user verification. Specifically, our user spoofing mitigation framework (which consists of three components, namely Step Cycle Identification, Step Cycle Interpolation, and Similarity Comparison) is used to extract gait patterns from run-time accelerometer measurements to perform robust user verification under various walking speeds. We show that our framework can be implemented in two ways: user-centric and server-centric, and it is robust to not only random but also mimic attacks. Our extensive experiments using over 3,000 smartphone-based traces with mobile phones placed on different body positions confirm the effectiveness of the proposed framework with users walking at various speeds. This strongly indicates the feasibility of using smartphone based low grade accelerometer to conduct gait recognition and facilitate effective user verification without active user cooperation.
Yanzhi Ren, Yingying Chen 0001, Mooi Choo Chuah, Jie Yang 0003
IEEE Trans. Mob. Comput.4
2015 Sensing Human-Screen Interaction for Energy-Efficient Frame Rate Adaptation on Smartphones
abstract
Touch-screen technique has gained the large popularity in human-screen interaction with modern smartphones. Due to the limited size of equipped screens, scrolling operations are indispensable in order to display the content of interest on screen. While power consumption caused by hardware and software installed within smartphones is well studied, the energy cost made by human-screen interaction such as scrolling remains unknown. In this paper, we analyze the impact of scrolling operations to the power consumption of smartphones, finding that the state-of-art strategy of smartphones in responding a scrolling operation is to always use the highest frame rate which arouses huge computation burden and can contribute nearly 50 percent to the total power consumption of smartphones. In recognizing this significance, we further propose a novel system, energy-efficient engine (E3), which automatically tracks the scrolling speed and adaptively adjusts the frame rate according to user preference. The goal of E3is to guarantee the user experience and minimize the energy consumption caused by scrolling at the same time. Extensive experiment results demonstrate the efficiency of E3design. On average, E3can save up to 60 percent of the energy consumed by CPU and 35 percent of the overall energy consumption.
Jiadi Yu, Haofu Han, Hongzi Zhu, Yingying Chen 0001, Jie Yang 0003, Yanmin Zhu 0006, Guangtao Xue, Minglu Li 0001
IEEE Trans. Mob. Comput.5
2015 An Adaptive Framework Coping with Dynamic Target Speed for Device-Free Passive Localization
abstract
The problem of device-free passive localization aims on locating moving objects which do not carry any localization devices. The rationale of this problem is based on the fact that a moving object can result in the changes of received signal strength (RSS) of the wireless links. Existing studies on this problem usually do not consider the impact of dynamic target speed on device-free passive localization. However, the experiments show that the localization performance degrades substantially when an object is moving at dynamic speed. To meet this challenge, in this paper, we propose an adaptive device-free passive localization framework which has three components to detect target speed change and perform adaptive localization. This framework can be easily adapted for existing device-free localization methods which are based on the detection of signal strength changes. As demonstrated in the experiments, the proposed framework can lead to 50 and 30 percent improvement on median and maximum error respectively over the localization algorithms without considering dynamic moving speeds of the target.
Xiuyuan Zheng, Jie Yang 0003, Yingying Chen 0001, Hui Xiong 0001
IEEE Trans. Mob. Comput.2
2015 Protecting Multi-Lateral Localization Privacy in Pervasive Environments
abstract
Location-based services (LBSs) have raised serious privacy concerns in the society, due to the possibility of leaking a mobile user's location information in enabling location-dependent services. While existing location-privacy studies are mainly focused on preventing the leakage of a user's location in accessing the LBS server, the possible privacy leakage in the calculation of the user's location, i.e., the localization, has been largely ignored. Such a privacy leakage stems from the fact that a localization algorithm typically takes the location of anchors (reference points for localization) as input, and generates the target's location as output. As such, the location of anchors and target could be leaked to others. An adversary could further utilize the leakage of anchor's locations to attack the localization infrastructure and undermine the accurate estimation of the target's location. To address this issue, in this paper, we study the multi-lateral privacy-preserving localization problem, whereby the location of a target is calculated without the need of revealing anchors' location, and the knowledge of the localization outcome, i.e., the target's location, is strictly limited to the target itself. To fully protect the user's privacy, our study protects not only the user's exact location information (the geo-coordinates), but also any side information that may lead to a coarse estimate of the location. We formulate the problem as a secure least-squared-error (LSE) estimation for an overdetermined linear system and develop three privacy-preserving solutions by leveraging combinations of information-hiding and homomorphic encryption. These solutions provide different levels of protection for location-side information and resilience to node collusion and have the advantage of being able to trade a user's privacy requirements for better computation and communication efficiency. Through numerical results, we verify the significant efficiency improvement of the proposed schemes over existing multiparty secure LSE algorithms.
Tao Shu, Yingying Chen 0001, Jie Yang 0003
IEEE/ACM Trans. Netw.3
2014 Practical user authentication leveraging channel state information (CSI)
abstract
User authentication is the critical first step to detect identity-based attacks and prevent subsequent malicious attacks. However, the increasingly dynamic mobile environments make it harder to always apply the cryptographic-based methods for user authentication due to their infrastructural and key management overhead. Exploiting non-cryptographic based techniques grounded on physical layer properties to perform user authentication appears promising. In this work, we explore to use channel state information (CSI), which is available from off-the-shelf WiFi devices, to conduct fine-grained user authentication. We propose an user-authentication framework that has the capability to build the user profile resilient to the presence of the spoofer. Our machine learning based user-authentication techniques can distinguish two users even when they possess similar signal fingerprints and detect the existence of the spoofer. Our experiments in both office building and apartment environments show that our framework can filter out the signal outliers and achieve higher authentication accuracy compared with existing approaches using received signal strength (RSS).
Hongbo Liu 0002, Yan Wang 0003, Jian Liu 0001, Jie Yang 0003, Yingying Chen 0001
AsiaCCS4
2014 Privacy-preserving ranked multi-keyword search leveraging polynomial function in cloud computing
abstract
The rapid deployment of cloud computing provides users with the ability to outsource their data to public cloud for economic savings and flexibility. To protect data privacy, users have to encrypt the data before outsourcing to the cloud, which makes the data utilization, such as data retrieval, a challenging task. It is thus desirable to enable the search service over encrypted cloud data for supporting effective and efficient data retrieval over a large number of data users and documents in the cloud. Existing approaches on encrypted cloud data search either focus on single keyword search or become inefficient when a large amount of documents are present, and thus have little support for the efficient multi-keyword search. In this paper, we propose a light-weight search approach that supports efficient multi-keyword ranked search in cloud computing system. Specifically, we first propose a basic scheme using polynomial function to hide the encrypted keyword and search patterns for efficient multi-keyword ranked search. To enhance the search privacy, we propose a privacy-preserving scheme which utilizes the secure inner product method for protecting the privacy of the searched multi-keywords. We analyze the privacy guarantee of our proposed scheme and conduct extensive experiments based on the real-world dataset. The experiment results demonstrate that our scheme can enable the encrypted multi-keyword ranked search service with high efficiency in cloud computing.
Yanzhi Ren, Yingying Chen 0001, Jie Yang 0003
GLOBECOM3
2014 SenSpeed: Sensing driving conditions to estimate vehicle speed in urban environments
abstract
Acquiring instant vehicle speed is desirable and a corner stone to many important vehicular applications. This paper utilizes smartphone sensors to estimate the vehicle speed, especially when GPS is unavailable or inaccurate in urban environments. In particular, we estimate the vehicle speed by integrating the accelerometer's readings over time and find the acceleration errors can lead to large deviations between the estimated speed and the real one. Further analysis shows that the changes of acceleration errors are very small over time which can be corrected at some points, called reference points, where the true vehicle speed is known. Recognizing this observation, we propose an accurate vehicle speed estimation system, SenSpeed, which senses natural driving conditions in urban environments including making turns, stopping and passing through uneven road surfaces, to derive reference points and further eliminates the speed estimation deviations caused by acceleration errors. Extensive experiments demonstrate that SenSpeed is accurate and robust in real driving environments. On average, the real-time speed estimation error on local road is 1.32mph, and the offline speed estimation error is as low as 0.75mph. Whereas the average error of GPS is 3.1mph and 2.8mph respectively.
Haofu Han, Jiadi Yu, Hongzi Zhu, Yingying Chen 0001, Jie Yang 0003, Yanmin Zhu 0006, Guangtao Xue, Minglu Li 0001
INFOCOM5
2014 Multi-lateral privacy-preserving localization in pervasive environments
abstract
Location based services (LBSs) have raised serious privacy concerns in the society, due to the possibility of leaking a mobile user's location information in enabling location-dependent services. While existing location-privacy studies are mainly focused on preventing the leakage of user's location in accessing the LBS server, the possible privacy leakage during the localization process has been largely ignored. Such a privacy leakage stems from the fact that a localization algorithm typically takes the location of anchors (i.e., reference points for localization) as input, and generates the target's location as output. As such, the location of anchors, and consequently the target's location, could be leaked to others. An adversary could further utilize the leakage of anchor's locations to attack the localization infrastructure and undermine the accurate estimation of the target's location. To address this issue, in this paper, we study the multi-lateral privacy preserving localization problem, whereby the location of a target is calculated without the need of revealing anchors' location, and the knowledge of the localization outcome is strictly limited to the target itself. To fully protect user's privacy, our study protects not only the user's exact location information (the geo-coordinates), but also any side information that may lead to a coarse estimate of the location. Three privacy-preserving localization solutions are developed by leveraging combinations of information hiding and homomorphic encryption. These solutions provide different levels of protection for location side information and resilience to node collusion, and have the advantage of being able to trade user's privacy requirements for better computation/communication efficiency.
Tao Shu, Yingying Chen 0001, Jie Yang 0003, Albert Williams
INFOCOM3
2014 Robot-assisted human indoor localization using the Kinect sensor and smartphones
abstract
Human indoor localization was previously implemented using wireless sensor networks at the cost of sensing infrastructure deployment. Motivated by high density of smartphones in public spaces, we propose to use a robot-assisted localization system in which the low-cost Kinect sensor and smartphone-based acoustic relative ranging are used to localize moving human targets in indoor environments. An extended Kalman filter based localization algorithm is developed for real-time dynamic position estimation. We present both simulations and real robot-smartphone experiments demonstrating the performance with a localization accuracy of approximately 0.5m.
Chao Jiang 0001, Muhammad Fahad 0003, Yi Guo 0004, Jie Yang 0003, Yingying Chen 0001
IROS4
2014 Poster: hearing your breathing: fine-grained sleep monitoring using smartphones
abstract
Sleep monitoring has drawn increasingly attention as the quality and quantity of the sleep are important for maintaining a person's health and well-being. For example, inadequate and irregular sleep are usually associated with serious health problems such as fatigue, depression and cardiovascular disease. Traditional sleep monitoring systems, such as PSG, involve wearable sensors with professional installations, and thus are limited to clinical usage. Recent work in using smartphone sensors for sleep monitoring can detect several events related to sleep, such as body movement, cough and snore. Such coarse-grained sleep monitoring however is unable to detect the breathing rate which is a vital sign and health indicator. This work presents a fine-grained sleep monitoring system which is capable of detecting the breathing rate by leveraging smartphones. Our system exploits the readily available smartphone earphone that placed close to the user to capture the breath sound reliably. Given the captured acoustic signal, our system performs noise reduction to remove environmental noise and then identifies the breathing rate based on the signal envelope detection. Our experimental evaluation of six subjects over six months time period demonstrates that the breathing rate monitoring is highly accurate and robust under various environments. This strongly indicates the feasibility of using the smartphone and its earphone to perform continuous and noninvasive fine-grained sleep monitoring.
Yanzhi Ren, Chen Wang 0009, Yingying Chen 0001, Jie Yang 0003
MobiCom4
2014 E-eyes: device-free location-oriented activity identification using fine-grained WiFi signatures
abstract
Activity monitoring in home environments has become increasingly important and has the potential to support a broad array of applications including elder care, well-being management, and latchkey child safety. Traditional approaches involve wearable sensors and specialized hardware installations. This paper presents device-free location-oriented activity identification at home through the use of existing WiFi access points and WiFi devices (e.g., desktops, thermostats, refrigerators, smartTVs, laptops). Our low-cost system takes advantage of the ever more complex web of WiFi links between such devices and the increasingly fine-grained channel state information that can be extracted from such links. It examines channel features and can uniquely identify both in-place activities and walking movements across a home by comparing them against signal profiles. Signal profiles construction can be semi-supervised and the profiles can be adaptively updated to accommodate the movement of the mobile devices and day-to-day signal calibration. Our experimental evaluation in two apartments of different size demonstrates that our approach can achieve over 96% average true positive rate and less than 1% average false positive rate to distinguish a set of in-place and walking activities with only a single WiFi access point. Our prototype also shows that our system can work with wider signal band (802.11ac) with even higher accuracy.
Yan Wang 0003, Jian Liu 0001, Yingying Chen 0001, Marco Gruteser, Jie Yang 0003, Hongbo Liu 0002
MobiCom5
2014 Tracking human queues using single-point signal monitoring
abstract
We investigate using smartphone WiFi signals to track human queues, which are common in many business areas such as retail stores, airports, and theme parks. Real-time monitoring of such queues would enable a wealth of new applications, such as bottleneck analysis, shift assignments, and dynamic workflow scheduling. We take a minimum infrastructure approach and thus utilize a single monitor placed close to the service area along with transmitting phones. Our strategy extracts unique features embedded in signal traces to infer the critical time points when a person reaches the head of the queue and finishes service, and from these inferences we derive a person's waiting and service times. We develop two approaches in our system, one is directly feature-driven and the second uses a simple Bayesian network. Extensive experiments conducted both in the laboratory as well as in two public facilities demonstrate that our system is robust to real-world environments. We show that in spite of noisy signal readings, our methods can measure service and waiting times to within a $10$ second resolution.
Yan Wang 0003, Jie Yang 0003, Yingying Chen 0001, Hongbo Liu 0002, Marco Gruteser, Richard P. Martin
MobiSys2
2014 Accurate WiFi Based Localization for Smartphones Using Peer Assistance
abstract
Highly accurate indoor localization of smartphones is critical to enable novel location based features for users and businesses. In this paper, we first conduct an empirical investigation of the suitability of WiFi localization for this purpose. We find that although reasonable accuracy can be achieved, significant errors (e.g., 6 8m) always exist. The root cause is the existence of distinct locations with similar signatures, which is a fundamental limit of pure WiFi-based methods. Inspired by high densities of smartphones in public spaces, we propose a peer assisted localization approach to eliminate such large errors. It obtains accurate acoustic ranging estimates among peer phones, then maps their locations jointly against WiFi signature map subjecting to ranging constraints. We devise techniques for fast acoustic ranging among multiple phones and build a prototype. Experiments show that it can reduce the maximum and 80-percentile errors to as small as 2m and 1m, in time no longer than the original WiFi scanning, with negligible impact on battery lifetime.
Hongbo Liu 0002, Jie Yang 0003, Simon Sidhom, Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003
IEEE Trans. Mob. Comput.2
2014 Group Secret Key Generation via Received Signal Strength: Protocols, Achievable Rates, and Implementation
abstract
Secret key generation among wireless devices using physical layer information of radio channel has been an attractive alternative for ensuring security in mobile environments. Received signal strength (RSS) based secret key extraction gains much attention due to its easy accessibility in wireless infrastructure. However, the problem of using RSS to generate keys among multiple devices to ensure secure group communication in practice remains open. In this work, we propose a framework for collaborative key generation among multiple wireless devices leveraging RSS. To deal with mobile devices not within each other’s communication range, we employ relay nodes to achieve reliable key extraction. To enable secure group communication, two protocols are developed to perform collaborative group key generation via star and chain topologies respectively. We further provide the theoretic analysis on the achievable secrecy rate for both star and chain topologies in the presence of an eavesdropper. Our prototype development using MICAz motes and extensive experiments using fading trend based key extraction demonstrate the feasibility of using RSS for group key generation in both indoor and outdoor environments, and concurrently achieving a lower bit mismatch rate compared to existing studies.
Hongbo Liu 0002, Jie Yang 0003, Yan Wang 0003, Yingying Chen 0001, Can Emre Koksal
IEEE Trans. Mob. Comput.2
2014 A Study of Localization Accuracy Using Multiple Frequencies and Powers
abstract
Wireless localization using the received signal strength (RSS) can have tremendous savings over using specialized positioning infrastructures. In this work, we explore improving RSS localization performance in multipath environments by varying the transmitter's signal power and frequency. We first derive and analyze the Cramér-Rao Lower Bound (CRLB) of RSS-based localization based on the frequency dependent path loss propagation model that considers the transmitter's signal power and frequency. The derived CRLB shows the feasibility of improving localization performance by applying frequency and power level selection for RSS-based localization. Using this analysis, we develop two new selection metrics based on the observed standard deviations of RSS as well as residuals. We then show a set of selection methods that attempt to select the combinations of power and frequencies which minimize the localization error in a representative class of localization algorithms. Our simulation results confirm the proposed selection methods can improve the localization accuracy under CRLB. Additionally, using active RFID tags, we experimentally characterize the effect of using multiple signal powers and frequencies on a wide spectrum of RSS-based algorithms. We found that the performance of all the algorithms improves when leveraging on multiple power levels and frequencies, although different algorithms present different sensitivity in terms of localization accuracy under different selection methods.
Xiuyuan Zheng, Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001, Richard P. Martin
IEEE Trans. Parallel Distributed Syst.3
2013 Fast and practical secret key extraction by exploiting channel response
abstract
Securing wireless communication remains challenging in dynamic mobile environments due to the shared nature of wireless medium and lacking of fixed key management infrastructures. Generating secret keys using physical layer information thus has drawn much attention to complement traditional cryptographic-based methods. Although recent work has demonstrated that Received Signal Strength (RSS) based secret key extraction is practical, existing RSS-based key generation techniques are largely limited in the rate they generate secret bits and are mainly applicable to mobile wireless networks. In this paper, we show that exploiting the channel response from multiple Orthogonal Frequency-Division Multiplexing (OFDM) subcarriers can provide fine-grained channel information and achieve higher bit generation rate for both static and mobile cases in real-world scenarios. We further develop a Channel Gain Complement (CGC) assisted secret key extraction scheme to cope with channel non-reciprocity encountered in practice. Our extensive experiments using WiFi networks in both indoor as well as outdoor environments demonstrate that our approach can achieve significantly faster secret bit generation rate at 60 ~ 90bit/packet, and is resilient to malicious attacks identified to be harmful to RSS-based techniques including predictable channel attack and stalking attack.
Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001
INFOCOM3
2013 Adaptive device-free passive localization coping with dynamic target speed
abstract
Device-free passive localization enables locating targets (e.g., intruders or victims) that do not carry any radio devices nor do they actively participate in the wireless localization process. This is because the wireless environments will get affected when people move into the area, which result in the changes of Received Signal Strength (RSS) of the wireless links. In this paper, we first show that the localization performance degrades significantly when people are moving in dynamic speeds. This is because existing studies in device-free passive localization system have an implicit assumption that the target is moving at a constant speed, which is not always true in practical scenarios. To cope with targets moving with dynamic speeds, we propose an adaptive speed change detection framework including three components: speed change detection, determination of time-window size and adaptive localization. Two speed change detection schemes have been developed to capture the changes of moving speed and adjust the time-window size adaptively to facilitate effective localization. We demonstrate that our framework is flexible to work with any device-free localization method using signal strength. Results from the real experiments confirm that our approach has over 30% improvement on both median and max localization error, under dynamically changing speed of the target.
Xiuyuan Zheng, Jie Yang 0003, Yingying Chen 0001, Yu Gan 0003
INFOCOM2
2013 Proactive call drop avoidance in UMTS networks
abstract
The rapid advancement of smartphones has instigated tremendous data applications for cell phones. Supporting simultaneous voice and data services in a cellular network is not only desirable but also becoming indispensable. However, if the voice and data are serviced through the same antenna (like the 3G UMTS network), a voice call with data sessions requires better radio connection than a voice-only call. In this paper, we systematically study the coordination between the voice and data transmissions in UMTS networks. From analyzing a large carrier's UMTS network recording data, we first identify the most relevant network measurements/features indicating a potential call drop, then propose a drop-call predictor based on AdaBoost. Moreover, we develop an intelligent call management strategy to voluntarily block data sessions when the voice is predicted to be dropped. Our analysis utilizing real service provider's data sets shows that our proposed scheme can not only predict drop calls with a very high accuracy but also achieve the highest user satisfaction compared to the other existing call management strategies.
Jie Yang 0003, Dahai Xu, Guangzhi Li, Yu Jin 0001, Zihui Ge, Mario Kosseifi, Robert D. Doverspike, Yingying Chen 0001, Lei Ying 0001
INFOCOM2
2013 Measuring human queues using WiFi signals
abstract
We investigate using smartphone WiFi signals to track human queues, which are common in many business areas such as retail stores, airports, and theme parks. Real-time monitoring of such queues would enable a wealth of new applications, such as bottleneck analysis, shift assignments, and dynamic workflow scheduling. We take a minimum infrastructure approach and thus utilize a single monitor placed close to the service area along with transmitting phones. Our strategy extracts unique features embedded in the signal traces to infer the critical time points when a person reaches the head of the queue and finishes service, and from these inferences we derive a person's waiting and service times. We develop a feature driven approach in our system. Extensive experiments conducted both in the laboratory demonstrate that our system is robust to queues with different waiting time. We show that in spite of noisy signal readings, our methods can measure important time periods in queue (e.g., service and waiting times) to within a $10$ second resolution.
Yan Wang 0003, Jie Yang 0003, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
MobiCom2
2013 Sensing vehicle dynamics for determining driver phone use
abstract
This paper utilizes smartphone sensing of vehicle dynamics to determine driver phone use, which can facilitate many traffic safety applications. Our system uses embedded sensors in smartphones, i.e., accelerometers and gyroscopes, to capture differences in centripetal acceleration due to vehicle dynamics. These differences combined with angular speed can determine whether the phone is on the left or right side of the vehicle. Our low infrastructure approach is flexible with different turn sizes and driving speeds. Extensive experiments conducted with two vehicles in two different cities demonstrate that our system is robust to real driving environments. Despite noisy sensor readings from smartphones, our approach can achieve a classification accuracy of over $90\%$ with a false positive rate of a few percent. We also find that by combining sensing results in a few turns, we can achieve better accuracy (e.g., $95\%$) with a lower false positive rate.
Yan Wang 0003, Jie Yang 0003, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
MobiSys2
2013 Smartphone based user verification leveraging gait recognition for mobile healthcare systems
abstract
The rapid deployment of sensing technology in smartphones and the explosion of their usage in people's daily lives provide users with the ability to collectively sense the world. This leads to a growing trend of mobile healthcare systems utilizing sensing data collected from smartphones with/without additional external sensors to analyze and understand people's physical and mental states. However, such healthcare systems are vulnerable to user spoofing attacks, in which an adversary distributes his registered device to other users such that data collected from these users can be claimed as his own to obtain more healthcare benefits and undermine the successful operation of mobile healthcare systems. Existing mitigation approaches either only rely on a secret PIN number (which can not deal with colluded attacks) or require an explicit user action for verification. In this paper, we propose a user verification scheme leveraging unique gait patterns derived from acceleration readings in mobile healthcare systems to detect possible user spoofing attacks. Our framework exploits the readily available accelerometers embedded within smartphones for user verification. Specifically, our user spoofing attack mitigation scheme (which consists of three components, namely Step Cycle Identification, Step Cycle Interpolation, and Similarity Score Computation) is used to extract gait patterns from run-time accelerometer measurements to perform robust user verification under various walking speeds. Our experiments using 322 smartphone-based traces over a period of 6 months confirm that our scheme is highly effective for detecting user spoofing attacks. This strongly indicates the feasibility of using smartphone based low grade accelerometer to conduct gait recognition and facilitate effective user verification without active user cooperation.
Yanzhi Ren, Yingying Chen 0001, Mooi Choo Chuah, Jie Yang 0003
SECON4
2013 E3: energy-efficient engine for frame rate adaptation on smartphones
abstract
Touch-screen technique has gained the large popularity in human-screen interaction with modern smartphones. Due to the limited size of equipped screens, scrolling operations are indispensable in order to display the content of interest on screen. While power consumption caused by hardware and software installed within smartphones is well studied, the energy cost made by human-screen interaction such as scrolling remains unknown. In this paper, we analyze the impact of scrolling operations to the power consumption of smartphones, finding that the state-of-art strategy of smartphones in responding a scrolling operation is to always use the highest frame rate which arouses huge computation burden and can contribute nearly 50% to the total power consumption of smartphones. In recognizing this significance, we further propose a novel system, Energy-Efficient Engine(E3), which automatically tracks the scrolling speed and adaptively adjusts the frame rate according to individual user preference. The goal of E3 is to guarantee the user experience and minimize the energy consumption caused by scrolling at the same time. Extensive experiment results demonstrate the efficiency of E3 design. On average, E3 can save up to 58% of the energy consumed by CPU and 34% of the overall energy consumption.
Haofu Han, Jiadi Yu, Hongzi Zhu, Yingying Chen 0001, Jie Yang 0003, Guangtao Xue, Yanmin Zhu 0006, Minglu Li 0001
SenSys5
2013 Detection and Localization of Multiple Spoofing Attackers in Wireless Networks
abstract
Wireless spoofing attacks are easy to launch and can significantly impact the performance of networks. Although the identity of a node can be verified through cryptographic authentication, conventional security approaches are not always desirable because of their overhead requirements. In this paper, we propose to use spatial information, a physical property associated with each node, hard to falsify, and not reliant on cryptography, as the basis for 1) detecting spoofing attacks; 2) determining the number of attackers when multiple adversaries masquerading as the same node identity; and 3) localizing multiple adversaries. We propose to use the spatial correlation of received signal strength (RSS) inherited from wireless nodes to detect the spoofing attacks. We then formulate the problem of determining the number of attackers as a multiclass detection problem. Cluster-based mechanisms are developed to determine the number of attackers. When the training data are available, we explore using the Support Vector Machines (SVM) method to further improve the accuracy of determining the number of attackers. In addition, we developed an integrated detection and localization system that can localize the positions of multiple attackers. We evaluated our techniques through two testbeds using both an 802.11 (WiFi) network and an 802.15.4 (ZigBee) network in two real office buildings. Our experimental results show that our proposed methods can achieve over 90 percent Hit Rate and Precision when determining the number of attackers. Our localization results using a representative set of algorithms provide strong evidence of high accuracy of localizing multiple adversaries.
Jie Yang 0003, Yingying Chen 0001, Wade Trappe, Jerry Q. Cheng
IEEE Trans. Parallel Distributed Syst.1
2012 Collaborative secret key extraction leveraging Received Signal Strength in mobile wireless networks
abstract
Securing communication in mobile wireless networks is challenging because the traditional cryptographic-based methods are not always applicable in dynamic mobile wireless environments. Using physical layer information of radio channel to generate keys secretly among wireless devices has been proposed as an alternative in wireless mobile networks. And the Received Signal Strength (RSS) based secret key extraction gains much attention due to the RSS readings are readily available in wireless infrastructure. However, the problem of using RSS to generate keys among multiple devices to ensure secure group communication remains open. In this work, we propose a framework for collaborative key generation among a group of wireless devices leveraging RSS. The proposed framework consists of a secret key extraction scheme exploiting the trend exhibited in RSS resulted from shadow fading, which is robust to outsider adversary performing stalking attacks. To deal with mobile devices not within each other's communication range, we employ relay nodes to achieve reliable key extraction. To enable secure group communication, two protocols, namely star-based and chain-based, are developed in our framework by exploiting RSS from multiple devices to perform group key generation collaboratively. Our experiments in both outdoor and indoor environments confirm the feasibility of using RSS for group key generation among multiple wireless devices under various mobile scenarios. The results also demonstrate that our collaborative key extraction scheme can achieve a lower bit mismatch rate compared to existing works when maintaining the comparable bit generation rate.
Hongbo Liu 0002, Jie Yang 0003, Yan Wang 0003, Yingying Chen 0001
INFOCOM2
2012 Push the limit of WiFi based localization for smartphones
abstract
Highly accurate indoor localization of smartphones is critical to enable novel location based features for users and businesses. In this paper, we first conduct an empirical investigation of the suitability of WiFi localization for this purpose. We find that although reasonable accuracy can be achieved, significant errors (e.g., $6\sim8m$) always exist. The root cause is the existence of distinct locations with similar signatures, which is a fundamental limit of pure WiFi-based methods. Inspired by high densities of smartphones in public spaces, we propose a peer assisted localization approach to eliminate such large errors. It obtains accurate acoustic ranging estimates among peer phones, then maps their locations jointly against WiFi signature map subjecting to ranging constraints. We devise techniques for fast acoustic ranging among multiple phones and build a prototype. Experiments show that it can reduce the maximum and 80-percentile errors to as small as $2m$ and $1m$, in time no longer than the original WiFi scanning, with negligible impact on battery lifetime.
Hongbo Liu 0002, Yu Gan 0003, Jie Yang 0003, Simon Sidhom, Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003
MobiCom3
2012 Securing Mobile Location-based Services through position verification leveraging key distribution
abstract
Technological advancements have made it possible to use information associated with a mobile's location to form new computing and services. One concern with these emerging location-based services (LBS) is their ability to provide security while remaining reliable and accurate. In this paper, we focus on securing Mobile Location-based Services (MLBS), where certain goods or services are provided by mobile vendors to a clientele based on the proximity of vendors to potential customers. We identify different attacks and misuse faced by MLBS, and show that position verification is a critical step in providing a secure and trustworthy MLBS. To provide position verification, we propose a scheme called Key Distribution-based Position Verification (KEPI), which takes advantage of an auxiliary network of transponders to facilitate trustworthy location-based services. We derive an analytical model to evaluate our approach and our simulation results provide useful insights about how auxiliary networks can help provide trustworthy mobile services.
Jie Yang 0003, Yingying Chen 0001, Sanjay Macwan, Cristina Serban, Wade Trappe
WCNC1
2012 Toward attack-resistant localization under infrastructure attacks
abstract
ABSTRACT Trustworthy location information is important because it is a critical input to a wide variety of location‐based applications. However, the localization infrastructure is vulnerable to physical attacks, and consequently, the localization results are affected. In this paper, we aim to achieve robust localization under infrastructure attacks. We first investigated the impact of infrastructure attacks on localization and showed that the performance of location estimations degraded significantly under the attack. We then derived an attack‐resistant scheme that is not algorithm specific and can be integrated with existing localization algorithms. Our attack‐resistant scheme exploited the characteristics of the geometric patterns returned by location estimates under the attack; that is, the localization results of a wireless device under the normal situation were clearly clustered together, whereas the localization results were scattered when an attack was present. Thus, our attack‐resistant scheme is grounded on K‐means clustering analysis of intra‐distance of localization results from all possible combinations of any three access points. To evaluate the effectiveness and scalability of our proposed scheme, we used received signal strength for validation and applied our approach to three broad classes of localization algorithms: lateration based, fingerprint matching, and Bayesian networks. We validated our scheme in the ORBIT test bed (North Brunswick, NJ, USA) using an 802.11 (Wi‐Fi) network and in a real office building environment using an 802.15.4 (ZigBee) network. The extensive experimental results demonstrated that the application of our scheme could help the broad range of localization algorithms to achieve comparable or even better localization performance when under infrastructure attacks as compared with normal situations without attack, thus, effectively eliminating the effects of infrastructure attacks. Copyright © 2011 John Wiley & Sons, Ltd.
Jie Yang 0003, Yingying Chen 0001
Secur. Commun. Networks1
2012 Sensing Driver Phone Use with Acoustic Ranging through Car Speakers
abstract
This work addresses the fundamental problem of distinguishing between a driver and passenger using a mobile phone, which is the critical input to enable numerous safety and interface enhancements. Our detection system leverages the existing car stereo infrastructure, in particular, the speakers and Bluetooth network. Our acoustic approach has the phone send a series of customized high frequency beeps via the car stereo. The beeps are spaced in time across the left, right, and if available, front and rear speakers. After sampling the beeps, we use a sequential change-point detection scheme to time their arrival, and then use a differential approach to estimate the phone's distance from the car's center. From these differences a passenger or driver classification can be made. To validate our approach, we experimented with two kinds of phones and in two different cars. We found that our customized beeps were imperceptible to most users, yet still playable and recordable in both cars. Our customized beeps were also robust to background sounds such as music and wind, and we found the signal processing did not require excessive computational resources. In spite of the cars' heavy multipath environment, our approach had a classification accuracy of over 90 percent, and around 95 percent with some calibrations. We also found, we have a low false positive rate, on the order of a few percent.
Jie Yang 0003, Simon Sidhom, Gayathri Chandrasekaran, Tam Vu 0001, Hongbo Liu 0002, Nicolae Cecan, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
IEEE Trans. Mob. Comput.1
2012 Achieving robust wireless localization resilient to signal strength attacks
Yingying Chen 0001, Jie Yang 0003, Xiuyuan Zheng
Wirel. Networks3
2011 Distributed Spatio-Temporal Social Community Detection Leveraging Template Matching
abstract
Community association is an important attribute of a social network because people may belong to varying groups with different characteristics at different times. Traditional community detection approaches often rely on a centralized server and are only useful for offline data analysis. In this paper, we propose and evaluate a distributed community detection approach that allows individual users to detect their own communities based on local observations. Our proposed template- matching method derives dynamic spatial and temporal characteristics of social communities by exploiting human's mobility patterns. Our template matching method allows users with similar moving patterns to be grouped together as one community. Our results using both simulation as well as real experiments demonstrate that our method can detect local communities effectively with high detection rate and low false positive rate.
Yanzhi Ren, Mooi Choo Chuah, Jie Yang 0003, Yingying Chen 0001
GLOBECOM3
2011 Designing localization algorithms robust to signal strength attacks
abstract
Received Signal Strength (RSS) based localization algorithms are sensitive to a set of non-cryptographic attacks. For example, the attacker can perform signal strength attacks by placing an absorbing or reflecting material around a wireless device to modify its RSS readings. In this work, we first formulate the all-around signal strength attacks, where similar attacks are launched towards all landmarks, and experimentally show the feasibility of launching such attacks. We then propose a general principle for designing RSS-based algorithms so that they are robust to all-around signal strength attacks. To evaluate our approach, we adapt two RSS-based localization algorithms according to our principle and experiment with real attack scenarios. All the experiments show that our design principle can be applied to achieve comparable performance with much better robustness.
Yingying Chen 0001, Jie Yang 0003, Xiuyuan Zheng
INFOCOM3
2011 Mobile Phone Enabled Social Community Extraction for Controlling of Disease Propagation in Healthcare
abstract
New mobile phones equipped with multiple sensors provide users with the ability to sense the world at a microscopic level. The collected mobile sensing data can be comprehensive enough to be mined not only for the understanding of human behaviors but also for supporting multiple applications ranging from monitoring/tracking, to medical, emergency and military applications. In this work, we investigate the feasibility and effectiveness of using human contact traces collected from mobile phones to derive social community information to control the disease propagation rate in the healthcare domain. Specifically, we design a community-based framework that extracts the dynamic social community information from human contact based traces to make decisions on who will receive disease alert messages and take vaccination. We have experimentally evaluated our framework via a trace-driven approach by using data sets collected from mobile phones. The results confirmed that our approach of utilizing mobile phone enabled dynamic community information is more effective than existing methods, without utilizing social community information or merely using static community information, at reducing the propagation rate of an infectious disease. This strongly indicates the feasibility of exploiting the social community information derived from mobile sensing data for supporting healthcare related applications.
Yanzhi Ren, Jie Yang 0003, Mooi Choo Chuah, Yingying Chen 0001
MASS2
2011 Detecting driver phone use leveraging car speakers
abstract
This work addresses the fundamental problem of distinguishing between a driver and passenger using a mobile phone, which is the critical input to enable numerous safety and interface enhancements. Our detection system leverages the existing car stereo infrastructure, in particular the speakers and Bluetooth network. Our acoustic approach has the phone send a series of customized high frequency beeps via the car stereo. The beeps are spaced in time across the left, right, and if available, front and rear speakers. After sampling the beeps, we use a sequential change-point detection scheme to time their arrival, and then use a differential approach to estimate the phone's distance from the car's center. From these differences a passenger or driver classification can be made. To validate our approach, we experimented with two kinds of phones and in two different cars. We found that our customized beeps were imperceptible to most users, yet still playable and recordable in both cars. Our customized beeps were also robust to background sounds such as music and wind, and we found the signal processing did not require excessive computational resources. In spite of the cars' heavy multi-path environment, our approach had a classification accuracy of over 90%, and around 95% with some calibrations. We also found we have a low false positive rate, on the order of a few percent.
Jie Yang 0003, Simon Sidhom, Gayathri Chandrasekaran, Tam Vu 0001, Hongbo Liu 0002, Nicolae Cecan, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
MobiCom1
2011 Tracking vehicular speed variations by warping mobile phone signal strengths
abstract
In this paper, we consider the problem of tracking fine-grained speeds variations of vehicles using signal strength traces from GSM enabled phones. Existing speed estimation techniques using mobile phone signals can provide longer-term speed averages but cannot track short-term speed variations. Understanding short-term speed variations, however, is important in a variety of traffic engineering applications-for example, it may help distinguish slow speeds due to traffic lights from traffic congestion when collecting real time traffic information. Using mobile phones in such applications is particularly attractive because it can be readily obtained from a large number of vehicles. Our approach is founded on the observation that the large-scale path loss and shadow fading components of signal strength readings (signal profile) obtained from the mobile phone on any given road segment appear similar over multiple trips along the same road segment except for distortions along the time axis due to speed variations. We therefore propose a speed tracking technique that uses a Derivative Dynamic Time Warping (DDTW) algorithm to realign a given signal profile with a known training profile from the same road. The speed tracking technique then translates the warping path (i.e., the degree of stretching and compressing needed for alignment) into an estimated speed trace. Using 6.4 hours of GSM signal strength traces collected from a vehicle, we show that our algorithm can estimate vehicular speed with a median error of ± 5mph compared to using a GPS and can capture significant speed variations on road segments with a precision of 68% and a recall of 84%.
Gayathri Chandrasekaran, Tam Vu 0001, Alexander Varshavsky, Marco Gruteser, Richard P. Martin, Jie Yang 0003, Yingying Chen 0001
PerCom6
2010 Vehicular speed estimation using received signal strength from mobile phones
abstract
This paper introduces an algorithm that estimates the speed of a mobile phone by matching time-series signal strength data to a known signal strength trace from the same road. Knowing a mobile phone's speed is useful, for example, to estimate traffic congestion or other transportation performancemetrics. The proposed algorithmcan be implemented in the carrier's infrastructure with Network Measurement Reports obtained by a base station or on a mobile phone with signal strength readings obtained by the handset and depending on implementation choices, promises lower energy consumption than Global Positioning System (GPS) receivers. We evaluate the effectiveness of our algorithm on highway and arterial roads using GSM signal strength traces obtained from several phones over a one month period. The results show that the Correlation algorithm is significantly more accurate than existing techniques based on handoffs or phone localization.
Gayathri Chandrasekaran, Tam Vu 0001, Alexander Varshavsky, Marco Gruteser, Richard P. Martin, Jie Yang 0003, Yingying Chen 0001
UbiComp6
2010 Accuracy characterization of cell tower localization
abstract
Cell tower triangulation is a popular technique for determining the location of a mobile device. However, cell tower triangulation methods require the knowledge of the actual locations of cell towers. Because the locations of cell towers are not publicly available, these methods often need to use estimated tower locations obtained through wardriving. This paper provides the first large scale study of the accuracy of two existing methods for cell tower localization using wardriving data. The results show that naively applying these methods results in very large localization errors. We analyze the causes for these errors and conclude that one can localize a cell accurately only if it falls within the area covered by the wardriving trace. We further propose a bounding technique to select the cells that fall within the area covered by the wardriving trace and identify a cell combining optimization that can further reduce the localization error by half.
Jie Yang 0003, Alexander Varshavsky, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser
UbiComp1
2010 Performing Joint Learning for Passive Intrusion Detection in Pervasive Wireless Environments
abstract
Recent years have witnessed increasing interests in passive intrusion detection for wireless environments, e.g., asset protection in industrial facilities and emergency rescue of trapped people. Most previous studies have focused primarily on exploiting a single intrusion indicator, such as moving variance, for capturing an intrusion pattern at a time. However, in real-world, there are many intrusion patterns which may be only detectable by combining different intrusion indicators and performing detection jointly. To this end, we propose a joint intrusion learning approach, which has the ability in combining the detection power of several complementary intrusion indicators and detects different intrusion patterns at the same time. We developed the GREEK algorithm, which utilizes grid-based clustering over K-neighborhood to effectively diagnose the presence of intrusions. Further, we show that the performance of intrusion detection can be enhanced by utilizing the collaborative detecting efforts among multiple transmitter-receiver pairs. To validate the effectiveness of the joint intrusion learning method, we conducted experiments in a real-office environment using an IEEE 802.15.4 (Zigbee) network. Our experimental results provide strong evidence of the effectiveness of our joint learning approach in performing passive intrusion detection with a minimized false positive rate.
Jie Yang 0003, Yong Ge 0001, Hui Xiong 0001, Yingying Chen 0001, Hongbo Liu 0002
INFOCOM1
2010 Characterizing the impact of multi-frequency and multi-power on localization accuracy
abstract
Wireless localization using the received signal strength (RSS) can have tremendous savings over using specialized positioning infrastructures. In this work, we explore improving RSS localization performance in multipath environments by varying the transmitter's signal power and frequency. Using a theoretical analysis, we first show how selection of different signal powers and frequencies can improve localization accuracy for the least squares algorithm. We next develop a set of selection methods that attempt to select the combinations of power and frequencies which minimize the localization error. Our selection methods are based on the observed standard deviations of RSS as well as algorithm specific residuals. Using active RFID tags, we experimentally characterize the effect of using multiple signal powers and frequencies on a wide spectrum of RSS-based algorithms. We found that the performance of all the algorithms improves when leveraging on multiple power levels and frequencies, although different algorithms present different sensitivity in terms of localization accuracy under different selection methods.
Xiuyuan Zheng, Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001, John-Austen Francisco, Richard P. Martin
MASS3
2010 MUTON: Detecting Malicious Nodes in Disruption-Tolerant Networks
abstract
The Disruption Tolerant Networks (DTNs) are vulnerable to insider attacks, in which the legitimate nodes are compromised and the adversary modifies the delivery metrics of the node to launch harmful attacks in the networks. The traditional detection approaches of secure routing protocols can not address such kind of insider attacks in DTNs. In this paper, we propose a mutual correlation detection scheme (MUTON) for addressing these insider attacks. MUTON takes into consideration of the transitive property when calculating the packet delivery probability of each node and correlates the information collected from other nodes. We evaluated our approach through extensive simulations using both Random Way Point and Zebranet mobility models. Our results show that MUTON can detect insider attacks efficiently with high detection rate and low false positive rate.
Yanzhi Ren, Mooi Choo Chuah, Jie Yang 0003, Yingying Chen 0001
WCNC3
2010 Detecting blackhole attacks in Disruption-Tolerant Networks through packet exchange recording
abstract
The Disruption Tolerant Networks (DTNs) are especially useful in providing mission critical services such as in emergency networks or battlefield scenarios. However, DTNs are vulnerable to insider attacks, in which the legitimate nodes are compromised and the adversary nodes launch blackhole attacks by dropping packets in the networks. The traditional approaches of securing routing protocols can not address such insider attacks in DTNs. In this paper, we propose a method to secure the history records of packet delivery information at each contact so that other nodes can detect insider attacks by analyzing these packet delivery records. We evaluated our approach through extensive simulations using both Random Way Point and Zebranet mobility models. Our results show that our method can detect insider attacks efficiently with high detection rate and low false positive rate.
Yanzhi Ren, Mooi Choo Chuah, Jie Yang 0003, Yingying Chen 0001
WOWMOM3
2010 Empirical Evaluation of Wireless Localization when Using Multiple Antennas
abstract
We show that signal strength variability can be reduced by employing multiple low-cost antennas at fixed locations. We further explore the impact of this reduction on wireless localization by analyzing a representative set of algorithms ranging from fingerprint matching, to statistical maximum likelihood estimation, to threshold bounding of signal fingerprints, and to multilateration. Using an indoor wireless testbed, we provide experimental evaluation of the localization performance under multiple antennas. We found that in nearly all cases the performance of localization algorithms improved when using multiple antennas. Specifically, the median and the 90th percentile error can be reduced up to 70 percent. Additionally, we found that multiple antennas improve the localization stability significantly, up to 100 percent improvement, when there are small-scale three-dimensional movements of a mobile device around a given location.
Konstantinos Kleisouris, Yingying Chen 0001, Jie Yang 0003, Richard P. Martin
IEEE Trans. Parallel Distributed Syst.3
2009 Indoor Localization Using Improved RSS-Based Lateration Methods
abstract
Location estimation is a critical step for many location-aware applications. To obtain location information, localization methods employing received signal strength (RSS) are attestative since it can reuse the existing wireless infrastructure for localization. Among the large class of localization schemes, RSS-based lateration methods have the advantage of providing closed-form solutions for mathematical analysis as compared to heuristic-based localization approaches. However, the localization accuracy of RSS-based lateration methods are significantly affected by the unpredictable setup in indoor environments. To improve the applicability of RSS-based lateration methods in indoors, we propose two approaches, regression-based and correlation-based. The regression-based approach uses linear regression to discover a better fit of signal propagation model between RSS and the distance, while the correlation-based approach utilizes the correlation among RSS in local area to obtain more accurate signal propagation. Our results using both simulation as well as real experiments demonstrate that our improved methods outperform the original RSS-based lateration methods significantly.
Jie Yang 0003, Yingying Chen 0001
GLOBECOM1
2009 Determining the Number of Attackers and Localizing Multiple Adversaries in Wireless Spoofing Attacks
abstract
Wireless spoofing attacks are easy to launch and can significantly impact the performance of networks. Although the identity of a node can be verified through cryptographic authentication, conventional security approaches are not always desirable because of their overhead requirements. In this paper, we propose to use location information, a physical property associated with each node, hard to falsify, and not reliant on cryptography, as the basis for (1) detecting spoofing attacks; (2) determining the number of attackers when multiple adversaries masquerading as a same node identity; and (3) localizing multiple adversaries. We formulate the problem of determining the number of attackers as a multi-class detection problem. We first propose two cluster-based mechanisms to determine the number of attackers. We then develop SILENCE that employs the minimum distance testing of RSS values in addition to cluster analysis and can achieve better accuracy than other methods under study that merely use cluster analysis alone. We further developed an integrated detection and localization system that can localize the positions of multiple attackers. We evaluated our techniques through two testbeds using both an 802.11 (WiFi) network and an 802.15.4 (ZigBee) network in two real office buildings. Our experimental results show that SILENCE can achieve over 90% Hit Rate and Precision when determining the number of attackers. Additionally, our localization results using a representative set of algorithms provide strong evidence of high accuracy of localizing multiple adversaries.
Jie Yang 0003, Yingying Chen 0001, Wade Trappe, Jay Cheng
INFOCOM1
2009 Empirical Evaluation of the Limits on Localization Using Signal Strength
abstract
This work investigates the lower bounds of wireless localization accuracy using signal strength on commodity hardware. Our work relies on trace-driven analysis using an extensive indoor experimental infrastructure. First, we report the best experimental accuracy, twice the best prior reported accuracy for any localization system. We experimentally show that adding more and more resources (e.g., training points or landmarks) beyond a certain limit, can degrade the localization performance for lateration-based algorithms, and that it could only be improved further by "cleaning" the data. However, matching algorithms are more robust to poor quality RSS measurements. We next compare with a theoretical lower bound using standard Cramer Rao Bound (CRB) analysis for unbiased estimators, which is frequently used to provide bounds on localization precision. Because many localization algorithms are based on different mathematical foundations, we apply a diverse set of existing algorithms to our packet traces and found that the variance of the localization errors from these algorithms are smaller than the variance bound established by the CRB. Finally, we found that there exists a wide discrepancy from what free- space models predict in the signal to distance function even in an environment with limited shadowing and multipath, thereby imposing a fundamental limit on the achievable localization accuracy indoors.
Gayathri Chandrasekaran, Mesut Ali Ergin, Jie Yang 0003, Yingying Chen 0001, Marco Gruteser, Richard P. Martin
SECON3
2009 Detecting Spoofing Attacks in Mobile Wireless Environments
abstract
The flexibility and openness of wireless networks enables an adversary to masquerade as other devices easily. Identity-based spoofing attacks are serious network threats as they can facilitate a variety of advanced attacks to undermine the normal operation of networks. However, the existing mechanisms can only detect spoofing attacks when the victim node and the spoofing node are static. In this paper, we propose a method for detecting spoofing attacks in the mobile wireless environment, that is when wireless devices, such as the victim node and/or the spoofing node are moving. We develop the DEMOTE system, which exploits received signal strength (RSS) traces collected over time and achieves an optimal threshold to partition the RSS traces into classes for attack detection. Further, our novel algorithm alignment prediction (ALP), when without the knowledge of spatial constraint of the wireless nodes, utilizes temporal constraints to predict the best RSS alignment of partitioned RSS classes for RSS trace reconstruction over time. Our approach does not require any changes or cooperation from wireless devices other than packet transmissions. Through experiments from an office building environment, we show that DEMOTE achieves accurate attack detection both in signal space as well as in physical space using localization and is generic across different technologies including IEEE 802.11 b/g and IEEE 802.15.4.
Jie Yang 0003, Yingying Chen 0001, Wade Trappe
SECON1
2009 DECODE: Exploiting Shadow Fading to DEtect COMoving Wireless DEvices
abstract
We present the DECODE technique to determine whether a set of transmitters are comoving, i.e., moving together in close proximity. Comovement information can find use in applications ranging from inventory tracking to social network sensing and to optimizing mobile device localization. The positioning errors from indoor RSS-based localization systems tend to be too large, making it difficult to detect whether two devices are moving together based on the interdevice distances. DECODE achieves accurate comovement detection by exploiting the correlations in positioning errors over time. DECODE can not only be implemented in the position space but also in the signal space where a correlation in shadow fading due to objects blocking the path between the transmitter and receiver exists. This technique requires no change in or cooperation from the tracked devices other than sporadic transmission of packets. Using experiments from an office environment, we show that DECODE can achieve near-perfect comovement detection at walking speed mobility using correlation coefficients computed over approximately 60-second time intervals. We further show that DECODE is generic and could accomplish detection for mixed mobile transmitters of different technologies (IEEE 802.11b/g and IEEE 802.15.4), and our results are not very sensitive to the frequency at which transmitters communicate.
Gayathri Chandrasekaran, Mesut Ali Ergin, Marco Gruteser, Richard P. Martin, Jie Yang 0003, Yingying Chen 0001
IEEE Trans. Mob. Comput.5
2008 A theoretical analysis of wireless localization using RF-based fingerprint matching
abstract
Accurately obtaining the position of mobile devices is critical to high-level applications. In indoor environments, localization approaches employing RF-based fingerprint matching is an active research area because it can reuse the existing communication infrastructure, as well as reduce the signal uncertainty to achieve better location accuracy. In this paper, we provide a theoretical analysis of the localization performance when using fingerprint matching schemes. Specifically, we derived an analytic expression for the Cumulative Distribution Function (CDF) of the location error and investigated the mathematical relationship between the location error and the sampling points. Particularly, we studied the effects of the number of sampling points and the distance between adjacent sampling points. We further conducted experiments using an 802.11 network in a real office building environment. Our performance evaluation provides strong evidence that theoretical analysis is effective as the experimental results match our analytic study very well.
Jie Yang 0003, Yingying Chen 0001
IPDPS1
2008 DECODE : Detecting co-moving wireless devices
abstract
We present the DECODE technique to determine from a remote receiver whether a set of transmitters are co-moving, i.e., moving together in close proximity. Co-movement information can find use in applications ranging from inventory tracking, to social network sensing, and to optimizing mobile device localization. DECODE detects co-moving transmitters by identifying correlations in communication signal strength due to shadow fading. Unlike localization systems, it can operate using measurements from only a single receiver. It requires no changes in or cooperation from the tracked devices other than sporadic transmission of packets. Using experiments from an office environment, we show that DECODE can achieve near perfect co-movement detection at walking-speed mobility using correlation coefficients computed over approximately 60-second time intervals.
Gayathri Chandrasekaran, Mesut Ali Ergin, Marco Gruteser, Richard P. Martin, Jie Yang 0003, Yingying Chen 0001
MASS5
2008 Detecting sybil attacks inwireless and sensor networks using cluster analysis
abstract
Wireless networks are vulnerable to sybil attacks, in which a sybil node forges multiple identifications to trick the system and conduct harmful attacks. The traditional approach to address sybil attacks is to employ cryptographic-related methods. However, conventional security approaches may not always desirable due to their infrastructural overhead. In this paper, we propose to utilize K-means cluster analysis for detecting sybil attacks based on the spatial correlation between the signal strength and physical locations. Our approach requires minimal overhead to wireless devices. We have evaluated our methods through experimentation using both an 802.11 (WiFi) network as well as an 802.15.4 (ZigBee) network in two office buildings. Our results show that the proposed sybil attack detector is highly effective with over 95% detection rates and under 5% false positive rates.
Jie Yang 0003, Yingying Chen 0001, Wade Trappe
MASS1
2008 The Impact of Using Multiple Antennas on Wireless Localization
abstract
We show that signal strength variability can be reduced by employing multiple low-cost antennas at fixed locations. We further explore the impact of this reduction on wireless localization by analyzing a representative set of algorithms ranging from fingerprint matching, to statistical maximum likelihood estimation, and to multilateration. We provide experimental evaluation using an indoor wireless testbed of the localization performance under multiple antennas. We found that in nearly all cases the performance of localization algorithms improved when using multiple antennas. Specifically, the median and the 90th percentile error can be reduced up to 70%. Additionally, we found that multiple antennas improve the localization stability significantly, up to 100% improvement, when there are small scale 3-dimensional movements of a mobile device around a given location.
Konstantinos Kleisouris, Yingying Chen 0001, Jie Yang 0003, Richard P. Martin
SECON3