VLDB 2026 Research / reviewers in the wild / expert
Tao Wang 0026
dblp:12/5838-26
· DBLP profile ↗
16ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0001-9744-107XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 1 first-author · 4 since 2021Security and privacy · 7 · 4 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hi-Fi Flow: Real-Time High-Granularity Flow Feature Extraction for Robust Network Monitoring
Shengping Bi, Tao Wang 0026, Tao Hou 0001 |
DSN | 3 |
| 2023 | Exquisite Feature Selection for Machine Learning Powered Probing Attack DetectionabstractNetwork attacks have been intensively studied by recent research. Probing attacks, however, seem not receiving as much attention as others, because they do not explicitly impact the network operations. Nevertheless, probing attacks may monitor network behaviors, extract web-sensitive information, and gather topology information of a target network, which opens a door for other attacks. It is critically important to understand the traffic patterns of network probing attacks and prevent suspicious probing activities from attackers. In this work, we present a novel user selection tool to build the optimal feature set that can characterize probing attacks. It consists of three modules: 1) feature correlation analyzer to remove highly correlated features for training efficiency; 2) coarse-grain feature selection to select key features that can describe the traffic patterns of probing attacks; 3) fine-grain feature refinement to understand temporal/spatial correlations among multiple packets to further improve the detection rate. In addition, we propose a fast hybrid training architecture that allows simultaneous training for both feature selection and attack detection to improve the overall training efficiency. In the experiment, we build a real-world network testbed to validate our design. The results show that the detection model can achieve a detection rate of up to 99.74% with the proposed fine-grain feature selection tool. Hamidah Alanazi, Shengping Bi, Tao Wang 0026, Tao Hou 0001 |
ICC | 3 |
| 2023 | Taking a Look into the Cookie Jar: A Comprehensive Study towards the Security of Web CookiesabstractCookies play a vital role in our Internet browsing experience, enabling various functions on websites. However, their significance also extends to potential vulnerabilities, especially in the face of cyber-attacks like cross-site scripting. As we interact with websites daily, it remains uncertain how well these platforms protect user data from such attacks or how efficiently they address vulnerabilities. To address these concerns, our research endeavors to conduct a comprehensive measurement study across the entire Internet landscape. Our goal is to shed light on the potential security risks and the extent to which protective measures are deployed on websites. We developed a customized toolkit to scrape a multitude of websites on the Internet, this objective can be assessed by analyzing the security flags of cookies. Through this study on web cookies, we obtained a better understanding of the current state of web security and identified potential areas of improvement. Sean Chen, Jaelyn McCracken, Tao Wang 0026, Tao Hou 0001 |
MobiHoc | 4 |
| 2023 | Proactive Anti-Eavesdropping With Trap Deployment in Wireless NetworksabstractDue to the open nature of the wireless medium, wireless communications are especially vulnerable to eavesdropping attacks. This article designs a new wireless communication system to deal with eavesdropping attacks. The proposed system can enable a legitimate receiver to get desired messages and meanwhile an eavesdropper to hear “fake” but meaningful messages by combining confidentiality and deception, thereby confusing the eavesdropper and achieving additional concealment that further protects exchanged messages. Towards this goal, we propose techniques that can conceal exchanged messages by utilizing wireless channel characteristics between the transmitter and the receiver, as well as techniques that can attract an eavesdropper to gradually approach a trap region, where the eavesdropper can get fake messages. We also provide both theoretical and empirical analysis of the established secure channel between the transmitter and the receiver. We develop a prototype system using Universal Software Defined Radio Peripherals (USRPs). Experimental results show that an eavesdropper at a trap location can receive fake information with a bit error rate (BER) close to 0, and the transmitter with multiple antennas can successfully deploy a trap area. Qiuye He, Song Fang 0001, Tao Wang 0026, Yao Liu 0007, Shangqing Zhao |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | MUSTER: Subverting User Selection in MU-MIMO NetworksabstractWiFi 5/6 relies on a key feature, Multi-User Multiple-In-Multiple-Out (MU-MIMO), to offer high-volume network throughput and spectrum efficiency. MU-MIMO uses a user selection algorithm, based on each user's channel state information (CSI), to schedule transmission opportunities for a group of users to maximize the service quality and efficiency. In this paper, we discover that such algorithm creates a subtle attack surface for attackers to subvert user selection in MU-MIMO, causing severe disruptions in today's wireless networks. We develop a system, named MU-MIMO user selection strategy inference and subversion (MUSTER), to systematically study the attack strategies and further to seek efficient mitigation. MUSTER is designed to include two major modules: (i) strategy inference, which leverages a new neural group-learning strategy named MC-grouping via combining Recurrent Neural Network (RNN) and Monte Carlo Tree Search (MCTS) to reverseengineer a user selection algorithm, and (ii) user selection subversion, which proactively fabricates CSI to manipulate user selection results for disruption. Experimental evaluation shows that MUSTER achieves a high accuracy rate around 98.6% in user selection prediction and effectively launches the attacks to disrupt the network performance. Finally, we create a Reciprocal Consistency Checking technique to defend against the proposed attacks to secure MU-MIMO user selection. Tao Hou 0001, Shengping Bi, Tao Wang 0026, Yao Liu 0007, Satyajayant Misra, Yalin E. Sagduyu |
INFOCOM | 3 |
| 2022 | DyWCP: Dynamic and Lightweight Data-Channel Coupling towards Confidentiality in IoT SecurityabstractAs Internet of Things (IoT) is more and more pervasive and deployed in critical applications, it's becoming increasingly important to preserve the confidentiality of sensitive data when IoT devices communicate with each other. However, traditional cryptography is usually time and energy consuming. It may not be applicable to IoT devices with limited computational capability or limited power. In this paper, we propose a lightweight encryption scheme named Dynamic Wireless Channel P ad (DyWCP) inspired by one-time pad encryption. One-time pad encryption achieves perfect secrecy but has been rarely used in practice due to the inconvenience of key negotiation. Our research discovers that in the wireless context it is possible to design a one-time pad encryption scheme without key negotiation. Towards the realization of DyWCP, we create techniques to utilize the additive feature of wireless channel to encrypt messages, to integrate modular operations at wireless physical layer, and to defend against multiple eavesdroppers. We implement a prototype of the proposed scheme using Universal Software Defined Radio Peripherals (USRP), and conduct a suite of experiments to evaluate the performance of the proposed scheme. Shengping Bi, Tao Hou 0001, Tao Wang 0026, Yao Liu 0007, Qingqi Pei |
WISEC | 3 |
| 2021 | Far Proximity Identification in Wireless SystemsabstractAs wireless mobile devices are more and more pervasive and adopted in critical applications, it is becoming increasingly important to measure the physical proximity of these devices in a secure way. Although various techniques have been developed to identify whether a device is close, the problem of identifying the far proximity (i.e., a target is at least a certain distance away) has been neglected by the research community. Meanwhile, verifying the far proximity is desirable and critical to enhance the security of emerging wireless applications. In this article, we propose a secure far proximity identification approach that determines whether or not a remote device is far away. The key idea of the proposed approach is to estimate the far proximity from the unforgeable “fingerprint” of the proximity. We have validated and evaluated the effectiveness of the proposed far proximity identification method through experiments on real measured channel data. The experiment results show that the proposed approach can detect the far proximity with a successful rate of 0.85 for the non-Line-of-sight (NLoS) scenario, and the successful rate can be further increased to 0.99 for the Line-of-sight (LoS) scenario. Tao Wang 0026, Jian Weng 0001, Jay Ligatti, Yao Liu 0007 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Combating Adversarial Network Topology Inference by Proactive Topology ObfuscationabstractThe topology of a network is fundamental for building network infrastructure functionalities. In many scenarios, enterprise networks may have no desire to disclose their topology information. In this paper, we aim at preventing attacks that use adversarial, active end-to-end topology inference to obtain the topology information of a target network. To this end, we propose a Proactive Topology Obfuscation (ProTO) system that adopts a detect-then-obfuscate framework: (i) a lightweight probing behavior identification mechanism based on machine learning is designed to detect any probing behavior, and then (ii) a topology obfuscation design is developed to proactively delay all identified probe packets in a way such that the attacker will obtain a structurally accurate yet fake network topology based on the measurements of these delayed probe packets, therefore deceiving the attacker and decreasing its appetency for future inference. We evaluate ProTO under different evaluation scenarios. Experimental results show that ProTO is able to (i) achieve a detection rate of 99.9% with a false alarm of 3%, (ii) effectively disrupt adversarial topology inference and lead to the topology inferred by the attacker close to a fake topology, and (iii) result in an overall network delay performance degradation of 1.3% - 2.0%. Tao Hou 0001, Tao Wang 0026, Yao Liu 0007 |
IEEE/ACM Trans. Netw. | 2 |
| 2020 | ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology InferenceabstractThe topology of a network is fundamental for building network infrastructure functionalities. In many scenarios, enterprise networks may have no desire to disclose their topology information. In this paper, we aim at preventing attacks that use adversarial, active end-to-end topology inference to obtain the topology information of a target network. To this end, we propose a Proactive Topology Obfuscation (ProTO) system that adopts a detect-then-obfuscate framework: (i) a lightweight probing behavior identification mechanism based on machine learning is designed to detect any probing behavior, and then (ii) a topology obfuscation design is developed to proactively delay all identified probe packets in a way such that the attacker will obtain a structurally accurate yet fake network topology based on the measurements of these delayed probe packets, therefore deceiving the attacker and decreasing its appetency for future inference. We show that ProTO is very effective against active topology inference with minimum performance disruption. Experimental results under different evaluation scenarios show that ProTO is able to (i) achieve a detection rate of 99.9% with a false alarm of 3%, (ii) effectively disrupt adversarial topology inference and lead to the topology inferred by the attacker close to a fake topology, and (iii) result in an overall network delay performance degradation of 1.3% - 2.0%. Tao Hou 0001, Tao Wang 0026, Yao Liu 0007 |
INFOCOM | 3 |
| 2019 | Entrapment for Wireless EavesdroppersabstractDue to the open nature of wireless medium, wireless communications are especially vulnerable to eavesdropping attacks. This paper designs a new wireless communication system to deal with eavesdropping attacks. The proposed system can enable a legitimate receiver to get desired messages and meanwhile an eavesdropper to hear “fake” but meaningful messages, thereby confusing the eavesdropper and achieving additional concealment that further protects exchanged messages. Towards this goal, we propose techniques that can conceal exchanged messages by utilizing wireless channel characteristics between the transmitter and the receiver, as well as techniques that can attract an eavesdropper to gradually approach a trap region, where the eavesdropper can get fake messages. We also implement and evaluate the proposed system on top of Universal Software Defined Radio Peripherals (USRPs). Experimental results show that an eavesdropper at a trap location can receive fake information with a bit error rate (BER) that is close to 0, and the transmitter with multiple antennas can successfully deploy a trap area. Song Fang 0001, Tao Wang 0026, Yao Liu 0007, Shangqing Zhao |
INFOCOM | 2 |
| 2018 | An over-the-air key establishment protocol using keyless cryptography
Yuexin Zhang, Yang Xiang 0001, Tao Wang 0026, Wei Wu 0001, Jian Shen 0001 |
Future Gener. Comput. Syst. | 3 |
| 2018 | Signal Entanglement Based Pinpoint Waveforming for Location-Restricted Service Access ControlabstractWe propose a novel wireless technique named pinpoint waveforming to achieve the location-restricted service access control, i.e., providing wireless services to users at eligible locations only. The proposed system is inspired by the fact that when two identical wireless signals arrive at a receiver simultaneously, they will constructively interfere with each other to form a boosted signal whose amplitude is twice of that of an individual signal. As such, the location-restricted service access control can be achieved through transmitting at a weak power, so that receivers at undesired locations (where the constructive interference vanishes), will experience a low signal-to-noise ratio (SNR), and hence a high bit error rate that retards the correct decoding of received messages. At the desired location (where the constructive interference happens), the receiver obtains a boosted SNR that enables the correct message decoding. To solve the difficulty of determining an appropriate transmit power, we propose to entangle the original transmit signals with jamming signals of opposite phase. The jamming signals can significantly reduce the SNR at the undesired receivers but cancel each other at the desired receiver to cause no impact. With the jamming entanglement, the transmit power can be any value specified by the system administrator. To enable the jamming entanglement, we create the channel calibration technique that allows the synchronization of transmit signals at the desired location. We develop a prototype system using the Universal Software Defined Radio Peripherals (USRPs). The evaluation results show that the receiver at the desired location obtains a throughput ranging between 0.9 and 0.93, whereas an eavesdropper that is 0.3 meter away from a desired location has a throughput approximately equal to 0. Tao Wang 0026, Yao Liu 0007, Tao Hou 0001, Qingqi Pei, Song Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | Virtual Multipath Attack and Defense for Location Distinction in Wireless NetworksabstractIn wireless networks, location distinction aims to detect location changes or facilitate authentication of wireless users. To achieve location distinction, recent research has focused on investigating the spatial uncorrelation property of wireless channels. Specifically, differences in wireless channel characteristics are used to distinguish locations or identify location changes. However, we discover a new attack against all existing location distinction approaches that are built on the spatial uncorrelation property of wireless channels. In such an attack, the adversary can easily hide her location changes or impersonate movements by injecting fake wireless channel characteristics into a target receiver. To defend against this attack, we propose a detection technique that utilizes an auxiliary receiver or antenna to identify these fake channel characteristics. We also discuss such attacks and corresponding defenses in OFDM systems. Experimental results on our USRP-based prototype show that the discovered attack can craft any desired channel characteristic with a successful probability of 95.0 percent to defeat spatial uncorrelation based location distinction schemes and our novel detection method achieves a detection rate higher than 91.2 percent while maintaining a very low false alarm rate. Song Fang 0001, Yao Liu 0007, Wenbo Shen, Haojin Zhu, Tao Wang 0026 |
IEEE Trans. Mob. Comput. | 5 |
| 2015 | Location-restricted Services Access Control Leveraging Pinpoint WaveformingabstractWe propose a novel wireless technique named pinpoint waveforming to achieve the location-restricted service access control, i.e., providing wireless services to users at eligible locations only. The proposed system is inspired by the fact that when two identical wireless signals arrive at a receiver simultaneously, they will constructively interfere with each other to form a boosted signal whose amplitude is twice of that of an individual signal. As such, the location-restricted service access control can be achieved through transmitting at a weak power, so that receivers at undesired locations (where the constructive interference vanishes), will experience a low signal-to-noise ratio (SNR), and hence a high bit error rate that retards the correct decoding of received messages. At the desired location (where the constructive interference happens), the receiver obtains a boosted SNR that enables the correct message decoding. To solve the difficulty of determining an appropriate transmit power, we propose to entangle the original transmit signals with jamming signals of opposite phase. The jamming signals can significantly reduce the SNR at the undesired receivers but cancel each other at the desired receiver to cause no impact. With the jamming entanglement, the transmit power can be any value specified by the system administrator. To enable the jamming entanglement, we create the channel calibration technique that allows the synchronization of transmit signals at the desired location. We develop a prototype system using the Universal Software Defined Radio Peripherals (USRPs). The evaluation results show that the receiver at the desired location obtains a throughput ranging between 0.9 and 0.93, whereas an eavesdropper that is 0.3 meter away from a desired location has a throughput approximately equal to 0. Tao Wang 0026, Yao Liu 0007, Qingqi Pei, Tao Hou 0001 |
CCS | 1 |
| 2015 | Survey on channel reciprocity based key establishment techniques for wireless systems
Tao Wang 0026, Yao Liu 0007, Athanasios V. Vasilakos |
Wirel. Networks | 1 |
| 2014 | Fingerprinting Far Proximity from Radio Emissions
Tao Wang 0026, Yao Liu 0007, Jay Ligatti |
ESORICS (1) | 1 |