VLDB 2026 Research / reviewers in the wild / expert
Junqing Zhang
dblp:121/9031
· DBLP profile ↗
85ranked-venue papers
10as first author
69since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 53 · 2 first-author · 40 since 2021Security and privacy · 18 · 2 first-author · 18 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lightweight Preprocessing and Feature Extraction for LoRa RF Fingerprint IdentificationabstractInternational audience Emma Bothereau, Robin Gerzaguet, Matthieu Gautier, Junqing Zhang, Alice Chillet, Olivier Berder |
ICC | 4 |
| 2026 | Channel Prediction-Based Physical Layer Authentication under Consecutive Spoofing Attacks
Yijia Guo, Junqing Zhang, Yao-Win Peter Hong |
ICC | 2 |
| 2026 | Triad-GAN: Feature-Level Generative Adversarial Network for Multi-Receiver Radio Frequency Fingerprint Identification
Shuo Wang 0035, Junqing Zhang, Jiahuai Mao, Alessandro Brighente, Guanxiong Shen, Mauro Conti |
ICC | 2 |
| 2026 | A Quantum-Optimized Training Framework for Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) offers a promising physical-layer method to authenticate devices based on unique hardware impairments. However, existing RFFI systems use deep learning (DL) models that are resource- intensive. Training is particularly demanding, requiring repeated updates to a large number of parameters. In this paper, we introduce a quantum-assisted training (QAST) framework to address training inefficiencies in RFFI. QAST integrates a quantum neural network (QNN) with a mapping network to generate parameters for a classical DL model. This indirect training strategy substantially reduces the number of trainable parameters and the overall memory requirements compared to direct training of the DL model. We achieve this by introducing a multimodal mapping network that effectively learns the QNN output. This network generates multiple classical parameters from a shared quantum representation, thereby reducing qubit requirements and lowering the risk of barren-plateau-related trainability degradation. We also propose a new embedding method that reduces the size of the embedding matrix and yields a 15% to 30% reduction in training time. The tailored QAST framework trains the RFFI model while requiring only 10% of the original number of parameters while maintaining comparable accuracy, thereby substantially reducing memory and computational overhead and enabling efficient training or retraining in resource-limited environments. To Truong An, Guolin Yin, Junqing Zhang, Yuan Ding 0001, Trung Quang Duong, Simon L. Cotton |
IEEE J. Sel. Areas Commun. | 3 |
| 2026 | RTGlassNet: Real-time glass segmentation with a lightweight Differentiable Conditional Random Field
Chenyi Zhu, Muddesar Iqbal, Junqing Zhang, Pablo Casaseca-de-la-Higuera, Xinheng Wang 0001 |
Pattern Recognit. | 5 |
| 2026 | Model-Driven Learning-Based Physical Layer Authentication for Mobile Wi-Fi DevicesabstractThe rise of wireless technologies has made the Internet of Things (IoT) ubiquitous, but the broadcast nature of wireless communications exposes IoT to authentication risks. Physical layer authentication (PLA) offers a promising solution by leveraging unique characteristics of wireless channels. As a common approach in PLA, hypothesis testing yields a theoretically optimal Neyman-Pearson (NP) detector, but its reliance on channel statistics limits its practicality in real-world scenarios. In contrast, deep learning-based PLA approaches are practical but tend to be not optimal. To address these challenges, we proposed a learning-based PLA scheme driven by hypothesis testing and conducted extensive simulations and experimental evaluations using Wi-Fi. Specifically, we incorporated conditional statistical models into the hypothesis testing framework to derive a theoretically optimal NP detector. Building on this, we developed LiteNP-Net, a lightweight neural network driven by the NP detector. Simulation results demonstrated that LiteNP-Net could approach the performance of the NP detector even without prior knowledge of the channel statistics. To further assess its effectiveness in practical environments, we deployed an experimental testbed using Wi-Fi IoT development kits in various real-world scenarios. Experimental results demonstrated that the LiteNP-Net outperformed the conventional correlation-based method as well as state-of-the-art Siamese-based methods. Yijia Guo, Junqing Zhang, Yao-Win Peter Hong, Stefano Tomasin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Toward Channel-Robust RF Fingerprint Identification Using Spectrum Averaging and High-Order Difference
Lingnan Xie, Linning Peng, Junqing Zhang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Toward a Practical Key Generation System for V2X CommunicationsabstractThe vehicle to everything (V2X) serves as a crucial foundation for future intelligent transportation systems. Security concerns within the V2X have garnered significant attention and key generation from wireless channels have emerged as a promising technique. However, applying key generation to V2X is quite challenging because the fast moving vehicles result in very small coherence time and impact channel measurements correlation. This paper designed a practical V2X key generation by enhancing channel state information (CSI) reciprocity and carried out extensive experimental evaluation. In particular, the designed key generation consists of channel probing, CSI preprocessing, CSI compensation and key establishment. In the channel probing, we deliberately reduced the time delay between uplink and downlink transmissions, to allow almost simultaneous measurements. We then carefully designed CSI preprocessing to remove hardware carrier leakage and eliminate noise effects. Furthermore, we devised CSI compensation by using interpolation or deep learning prediction to further improve the reciprocity. Finally, key establishment converted the measured CSI into binary sequences and reconcile on a common key via low-density parity-check (LDPC) code. We adopted universal software radio peripheral (USRP) X310 platforms for channel measurements and implemented the above algorithms. We carried out extensive experiments in real-road environments with various vehicle speeds. These carefully designed algorithms enabled our system working robustly even in high mobility scenarios, e.g., 40 km/h. Experimental results demonstrated common and random key can be generated with a key block error rate (BER) less than 0.1. Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Exploring Spatial-Temporal Representation via Star Graph for mmWave Radar-Based Human Activity RecognitionabstractHuman activity recognition (HAR) requires extracting accurate spatial-temporal features with human movements. A mmWave radar point cloud-based HAR system suffers from sparsity and variable-size problems due to the physical features of the mmWave signal. Existing works usually borrow the preprocessing algorithms for the vision-based systems with dense point clouds, which may not be optimal for mmWave radar systems. In this work, we proposed a graph representation with a discrete dynamic graph neural network (DDGNN) to explore the spatial-temporal representation of human movement-related features. Specifically, we designed a star graph to describe the high-dimensional relative relationship between a manually added static center point and the dynamic mmWave radar points in the same and consecutive frames. We then adopted DDGNN to learn the features residing in the star graph with variable sizes. Experimental results demonstrated that our approach outperformed other baseline methods using real-world HAR datasets. Our system achieved an overall classification accuracy of 94.27%, which gets the near-optimal performance with a vision-based skeleton data accuracy of 97.25%. We also conducted an inference test on Raspberry Pi 4 to demonstrate its effectiveness on resource-constraint platforms. We provided a comprehensive ablation study for variable DDGNN structures to validate our model design. Our system also outperformed three recent radar-specific methods without requiring resampling or frame aggregators. Senhao Gao, Junqing Zhang, Luoyu Mei, Shuai Wang 0008, Xuyu Wang |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | Adversarial Attacks Against Deep Learning-Based Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits deep learning models to extract hardware impairments to uniquely identify wireless devices. Recent studies show deep learning-based RFFI is vulnerable to adversarial attacks. However, effective adversarial attacks against different types of RFFI classifiers have not yet been explored. In this paper, we carried out a comprehensive investigations into different adversarial attack methods on RFFI systems using various deep learning models. Three specific algorithms, fast gradient sign method (FGSM), projected gradient descent (PGD), and universal adversarial perturbation (UAP), were analyzed. The attacks were launched to LoRa-RFFI and the experimental results showed the generated perturbations were effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU). We further used UAP to launch practical attacks. Special factors were considered for the wireless context, including implementing real-time attacks, the effectiveness of the attacks over a period of time, etc. Our experimental evaluation demonstrated that UAP can successfully launch adversarial attacks against the RFFI, achieving a success rate of 81.7% when the adversary almost has no prior knowledge of the victim RFFI systems. Junqing Zhang, Guanxiong Shen, Alan Marshall 0001, Chip-Hong Chang |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF FingerprintingabstractWhile supervised deep neural networks (DNNs) have proven effective for device authentication via radio frequency (RF) fingerprinting, they are hindered by domain shift issues and the scarcity of labeled data. The success of large language models has led to increased interest in self-supervised pre-trained models (PTMs), which offer better generalization and do not require labeled datasets, potentially addressing the issues mentioned above. However, the inherent vulnerabilities of PTMs in RF fingerprinting remain insufficiently explored. In this paper, we unveil the potential threat by thoroughly investigating data-free backdoor attacks on such PTMs for RF fingerprinting, focusing on a practical scenario where attackers lack access to downstream data, label information, and training processes. To realize the backdoor attack, we carefully design a set of triggers and predefined output representations (PORs) for the PTMs. By mapping triggers and PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream RF fingerprinting tasks without requiring prior knowledge. Extensive experiments demonstrate the wide applicability of our proposed backdoor attack to various input domains, protocols, and PTMs. Furthermore, we explore potential detection and defense methods, illustrating the difficulty of fully safeguarding against our proposed data-free backdoor attack. Tianya Zhao, Junqing Zhang, Jun Dai 0001, Xiaoyan Sun 0003, Xuyu Wang |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Polar-Domain Multi-User Key Generation in Near-Field CommunicationsabstractWith the substantial increase in the number of antennas, polar-domain channel modeling for extremely large-scale antenna array (ELAA) systems has been introduced to capture both angular and distance information in near-field environments. The fine-grained polar-domain channel provides additional sources of randomness, making it well-suited for physical layer key generation (PLKG). To minimize the pilot overhead in multi-user key generation and leverage the randomness from the polar-domain channel paths, we herein design a zero-forcing (ZF)-based precoding scheme to mitigate inter-path and inter-user interference. Using ZF precoding, we derive an analytical expression for the sum secret key rate (SKR) as a function of power allocation variables, and then optimize these variables in the presence of eavesdroppers. Our simulations validate the proposed precoding design and power allocation methods in terms of sum SKR versus the transmit power, antenna configurations, and spatial correlation between legitimate and eavesdropping channels. Tianyu Lu, Liquan Chen, Junqing Zhang, Weicheng Zhang, Michail Matthaiou |
GLOBECOM | 3 |
| 2025 | Radiation and Directivity Analysis of a Vibrating Dome-Shaped Radiator Mounted on an Infinite BaffleabstractAccurate modeling and analysis of a radiator mounted on an infinite baffle are crucial for understanding its acoustic radiation characteristics. This paper investigates the radiation behavior of a convex dome-shaped radiator in such a condition, showing that, under the far-field approximation, the pressure field is the three-dimensional Fourier transform of the axisymmetric surface velocity distribution. The study includes a comparison of various typical velocity distributions in terms of their directivity factor (DF) and radiated sound power. Current velocity distributions often suffer from nulls in the DF, so we provide a detailed analysis to uncover the causes of this issue. To address this, we propose an equalization filter designed to smooth the DF across the entire frequency range. Simulations are performed to validate the theoretical findings and to showcase the improved performance of the proposed approach. Junqing Zhang, Wen Zhang 0002, Jingdong Chen, Jacob Benesty |
ICASSP | 1 |
| 2025 | Towards Robust RF Fingerprint Identification Using Spectral Regrowth and Carrier Frequency Offset
Lingnan Xie, Linning Peng, Junqing Zhang |
INFOCOM | 3 |
| 2025 | Protocol-Agnostic and Data-Free Backdoor Attacks on Pre-Trained Models in RF Fingerprinting
Tianya Zhao, Junqing Zhang, Xuyu Wang |
INFOCOM | 3 |
| 2025 | Capodoglio: Tackling Multi-Armed Bandit Jamming AttacksabstractJamming attacks present a significant security threat to wireless networks by exploiting the open wireless medium, causing not only a denial-of-service, but also overloading the network and interfering with signals. The jamming attack can enable more sophisticated disruptions, such as protocol-aware and learning-based jamming, where adversaries transmit selectively upon detecting legitimate network activity, and this selective transmission conserves attacker resources and complicates detection. Channel hopping is widely adopted as a mitigation strategy, allowing networks to move away from interfered channels dynamically. However, recent studies have demonstrated that intelligent jammers, such as the Multi-Armed Bandit (MAB)-based attack, can effectively learn and predict channel hopping patterns, thereby continuously jamming communications and severely degrading network performance. Designing robust countermeasures against such intelligent jamming remains an open and critical challenge. In this paper, we analyze a kind of MAB-based attack methodology and propose two refined variants employing online and offline paradigms. To counteract these advanced threats, we introduce three defense strategies: (i) speeding up, which modifies the frequency of channel-hopping decisions to avoid the jammer’s attack, (ii) deploying a helper node, diversify the communication patterns to affect the attacker’s learning process, and (iii) employing a mirror Multi-Armed Bandit (mirror MAB) approach to predict and bypass channels of highest jamming probability. Comprehensive evaluations demonstrate the effectiveness of our proposed defenses, significantly mitigating MAB-based attacks. Specifically, our strategies achieve a PDR exceeding 90% under persistent attack conditions, while effectively preserving robust and dynamic channel hopping behaviors. Shuo Wang 0035, Alessandro Brighente, Valeria Loscrì, Junqing Zhang, Mauro Conti |
TrustCom | 4 |
| 2025 | Towards Channel-Robust Radio Frequency Fingerprint Identification Using Contrastive LearningabstractRadio frequency fingerprint identification (RFFI) is an emerging device authentication technique that is based on intrinsic hardware impairments. Internet of things (IoT) devices can be identified and classified based on their wireless signals using RFFI. Developing a robust RFFI system that can maintain high classification accuracy across diverse communication scenarios is a critical challenge. In this paper, we proposed a contrastive learning-based RFFI approach to establish a channel-robust system using the spectrogram. Specifically, we leverage contrastive learning in the training stage, which has been implemented with data augmentation techniques to mitigate the influence of channels on RFFI. We carried out extensive experimental evaluations involving a public dataset and a self-collected dataset, both with ten LoRa devices. Utilizing these datasets, the performance of the system has been tested in various channel environments, including stationary, mobile, line-of-sight (LOS) and non-line-of-sight (NLOS) scenarios. The results demonstrated that our approach is effective and robust to channel variation, achieving 93% and 82% on static and dynamic channels. respectively. Junqing Zhang, Guanxiong Shen, Linning Peng, Alan Marshall 0001 |
WCNC | 2 |
| 2025 | Noise-Robust Radio Frequency Fingerprint Identification Using Denoise Diffusion ModelabstractSecuring Internet of Things (IoT) devices presents increasing challenges due to their limited computational and energy resources. Radio Frequency Fingerprint Identification (RFFI) emerges as a promising authentication technique to identify wireless devices through hardware impairments. RFFI performance under low signal-to-noise ratio (SNR) scenarios is significantly degraded because the minute hardware features can be easily swamped in noise. In this paper, we leveraged the diffusion model to effectively restore the RFF under low SNR scenarios. Specifically, we trained a powerful noise predictor and tailored a noise removal algorithm to effectively reduce the noise level in the received signal and restore the device fingerprints. We used Wi-Fi as a case study and created a testbed involving 6 commercial off-the-shelf Wi-Fi dongles and a USRP N210 software-defined radio (SDR) platform. We conducted experimental evaluations on various SNR scenarios. The experimental results show that the proposed algorithm can improve the classification accuracy by up to 34.9%. Guolin Yin, Junqing Zhang, Yuan Ding 0001, Simon L. Cotton |
WCNC | 2 |
| 2025 | Robust Radio Frequency Fingerprint Identification for Bluetooth Low Energy Under Low SNR and Channel VariationsabstractRadio frequency fingerprint identification (RFFI) is a promising technique for authenticating Internet of Things (IoT) devices by leveraging unique RF hardware impairments. However, RFFI is vulnerable to channel variations and low signal- to- noise ratio (SNR) conditions. In this paper, we proposed a robust RFFI system specifically designed to tackle these issues for Bluetooth Low Energy (BLE), which is a popular IoT technology. Our system integrated a denoising autoencoder (DAE) to enhance feature robustness under low SNR conditions and employed data augmentation to mitigate the impact of channel and noise effects. We created a testbed consisting of 18 commercial off-the-shelf (COTS) BLE devices and a USRP N210 software-defined radio (SDR) platform and then carried out extensive experimental evaluation under various channel conditions. The experiments involved line-of-sight (LOS) and non-line-of-sight (NLOS) propagation as well as dynamic and static channels. The results demonstrated that our approach consistently achieved over 95 % accuracy in high SNR environments and maintained strong performance with over 75% accuracy at low SNR levels (10 dB). Ningze Yuan, Junqing Zhang, Yuan Ding 0001, Simon L. Cotton |
WCNC | 2 |
| 2025 | Viewpoint planning optimization for structure from motion-based 3D reconstruction of industrial products with sim-to-real proximal policy optimization
Ruxin Xiao, Xinheng Wang 0001, Junqing Zhang |
Expert Syst. Appl. | 4 |
| 2025 | Channel2Channel: Toward Robust Radio Frequency Fingerprint Extraction and IdentificationabstractIn radio frequency fingerprint identification (RFFI) systems, mitigating channel interference remains a critical challenge. This paper introduces a robust RFFI system to tackle this issue effectively. Specifically, taking the IEEE 802.11 signal as the case study, a signal representation is designed based on the logarithmic spectrum, while an RFF extractor based on the U-Net neural network is employed which is guided by a proposed Channel2Channel (C2C) algorithm and powered by a designed data augmentation method. Furthermore, a collaborative identification mechanism is proposed based on a support vector machine (SVM) classifier, where a multi-frame RFF fusion method is designed to exploit the diversity across different frames of received signal. Extensive experimental evaluations are performed in various real-world scenarios using 7 mobile phones and a universal software radio peripheral (USRP) X310 receiver, where an average classification accuracy of 95.72% is obtained with a single frame of received signal, outperforming the neural network-based benchmarks, and an average accuracy of 99.46% is acquired with 10 signal frames based on the proposed collaborative identification method. In addition, the deployability of the system on a resource-constrained computing platform is also validated. Lingnan Xie, Linning Peng, Junqing Zhang, Junxian Shi |
IEEE J. Sel. Areas Commun. | 3 |
| 2025 | Practical Physical Layer Authentication for Mobile Scenarios Using a Synthetic Dataset Enhanced Deep Learning ApproachabstractThe Internet of Things (IoT) is ubiquitous thanks to the rapid development of wireless technologies. However, the broadcast nature of wireless transmissions results in great vulnerability to device authentication. Physical layer authentication emerges as a promising approach by exploiting the unique channel characteristics. However, a practical scheme applicable to dynamic channel variations is still missing. In this paper, we proposed a deep learning-based physical layer channel state information (CSI) authentication for mobile scenarios and carried out comprehensive simulation and experimental evaluation using IEEE 802.11n. Specifically, a synthetic training dataset was generated based on the WLAN TGn channel model and the autocorrelation and the distance correlation of the channel, which can significantly reduce the overhead of manually collecting experimental datasets. A convolutional neural network (CNN)-based Siamese network was exploited to learn the temporal and spatial correlation between the CSI pair and output a score to measure their similarity. We adopted a synergistic methodology involving both simulation and experimental evaluation. The experimental testbed consisted of WiFi IoT development kits and a few typical scenarios were specifically considered. Both simulation and experimental evaluation demonstrated excellent generalization performance of our proposed deep learning-based approach and excellent authentication performance. Demonstrated by our practical measurement results, our proposed scheme improved the area under the curve (AUC) by 0.03 compared to the fully connected network-based (FCN-based) Siamese model and by 0.06 compared to the correlation-based benchmark algorithm. Yijia Guo, Junqing Zhang, Yao-Win Peter Hong |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Precoding Design for Key Generation in Extremely Large-Scale MIMO Near-Field Multi-User Systems
Tianyu Lu, Liquan Chen, Junqing Zhang, Chen Chen 0071, Trung Quang Duong, Michail Matthaiou |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Multi-User Key Rate Optimization for Near-Field Extremely Large-Scale Antenna Array CommunicationsabstractExtremely large-scale antenna arrays (ELAA) require near-field spherical wave modeling due to the substantial increase in the number of antennas, which introduces new spatial dimensions to physical layer key generation (PLKG). We investigate multi-user PLKG in near-field environments, where a base station with an ELAA simultaneously generates secret keys with multiple users. We derive an analytical expression for the key rate (KR). By utilizing spatial dimensions of distance and angle in near-field environments, we apply eigenvalue decomposition and singular value decomposition to design precoding matrices to reduce interference among user equipments (UEs) and extract uncorrelated subchannels. Given that the KR is non-convex, we approximate it and optimize the precoding matrix to increase the KR. After precoding design, the KR depends on the transmit power allocated to the subchannels. Two optimization problems are formulated to further optimize transmit power allocation. The first problem focuses on maximizing the sum KR. We apply the Lagrange multiplier method to determine the optimal power allocation variables by searching the Lagrange multiplier. To reduce computational complexity, a supervised feedforward neural network (FNN) is designed to capture the relationship between the power allocation variables and the Lagrange multiplier. The second optimization problem focuses on KR fairness. By introducing a slack variable that is smaller than the KRs of all users, we use the CVX toolbox to find optimal power allocation variables that maximize this slack variable. To further reduce complexity, the Lagrange multiplier method offers an analytical solution for power allocation variables in terms of Lagrange multipliers determined by the slack variable in the high-power case. We employ a bisection algorithm to find the slack variable. Furthermore, we propose an FNN to map transmit power to the slack variable. Simulations demonstrate that the proposed methods efficiently leverage near-field effects for multi-user PLKG, reducing pilot overhead. Tianyu Lu, Liquan Chen, Junqing Zhang, Trung Quang Duong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Polar-Domain Multi-User Key Generation in Near-Field Communications
Tianyu Lu, Liquan Chen, Junqing Zhang, Weicheng Zhang, Michail Matthaiou |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Toward Channel-Robust and Receiver-Independent Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) is an emerging method for authenticating Internet of Things (IoT) devices. RFFI exploits the intrinsic and unique hardware imperfections for classifying IoT devices. Deep learning-based RFFI has shown excellent performance. However, there are still remaining research challenges, such as limited public training datasets as well as impacts of channel and receive effects. In this paper, we proposed a three-stage RFFI approach involving contrastive learning-enhanced pretraining, Siamese network-based classification network training, and inference. Specifically, we employed spectrogram as signal representation to decouple the transmitter impairments from channel effects and receiver impairments. We proposed an unsupervised contrastive learning method to pretrain a channel-robust RFF extractor. In addition, the Siamese network-based scheme is enhanced by data augmentation and contrastive loss, which is capable of jointly mitigating the effects of channel and receiver impairments. We carried out a comprehensive experimental evaluation using three public LoRa datasets and one self-collected LoRa dataset. The results demonstrated that our approach can effectively and simultaneously mitigate the effects of channel and receiver impairments. We also showed that pretraining can significantly reduce the required amount of the fine-tuning data. Our proposed approach achieved an accuracy of over 90% in dynamic non-line-of-sight (NLOS) scenarios when there are only 20 packets per device. Junqing Zhang, Guanxiong Shen, Linning Peng, Alan Marshall 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Physical Layer-Based Device Fingerprinting for Wireless Security: From Theory to PracticeabstractThe identification of the devices from which a message is received is part of security mechanisms to ensure authentication in wireless communications. Conventional authentication approaches are cryptography-based, which, however, are usually computationally expensive and not adequate in the Internet of Things (IoT), where devices tend to be low-cost and with limited resources. This paper provides a comprehensive survey of physical layer-based device fingerprinting, which is an emerging device authentication for wireless security. In particular, this article focuses on hardware impairment-based identity authentication and channel features-based authentication. They are passive techniques that are readily applicable to legacy IoT devices. Their intrinsic hardware and channel features, algorithm design methodologies, application scenarios, and key research questions are extensively reviewed here. The remaining research challenges are discussed, and future work is suggested that can further enhance the physical layer-based device fingerprinting. Junqing Zhang, Francesco Ardizzon, Mattia Piana, Guanxiong Shen, Stefano Tomasin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Evasion Attacks and Countermeasures in Deep Learning-Based Wi-Fi Gesture RecognitionabstractDeep learning-based Wi-Fi sensing has received massive interest thanks to the prevalence of Wi-Fi technology. While deep learning techniques provide promising results in Wi-Fi sensing, there are only very few studies on the vulnerabilities against Wi-Fi ensing. In this paper, we studied evasion attacks against deep learning-based Wi-Fi sensing and the countermeasure and conducted an extensive experimental evaluation using two publicly available datasets, namely SignFi and Widar. Accordingly, we proposed three white-box and two black-box attacks and revealed that even with an undetectable power change, evasion attacks can achieve a remarkable attack success rate (ASR) of 97.0% and 95.6% in white-box and black-box settings, respectively. These results highlight the urgent need for countermeasures against evasion attacks in Wi-Fi sensing systems. We introduced adversarial training and randomised smoothing, which notably improved the robustness of the Wi-Fi sensing model. The ASRs for white-box and black-box attacks were reduced to a minimum of around 6% and 2%, respectively. Moreover, randomised smoothing also introduced certifiable robustness, achieving 70.1% of samples certified for our model. The certification method provides an additional layer of reliability, ensuring that the model's performance remains consistent and predictable even under adversarial conditions. Guolin Yin, Junqing Zhang, Xinping Yi, Xuyu Wang |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Explanation-Guided Backdoor Attacks Against Model-Agnostic RF Fingerprinting SystemsabstractDespite the proven capabilities of deep neural networks (DNNs) in identifying devices through radio frequency (RF) fingerprinting, the security vulnerabilities of these deep learning models have been largely overlooked. While the threat of backdoor attacks is well-studied in the image domain, few works have explored this threat in the context of RF signals. In this paper, we thoroughly analyze the susceptibility of DNN-based RF fingerprinting to backdoor attacks, focusing on a more practical scenario where attackers lack access to control model gradients and training processes. We propose leveraging explainable machine learning techniques and autoencoders to guide the selection of trigger positions and values, allowing for the creation of effective backdoor triggers in a model-agnostic manner. To comprehensively evaluate this backdoor attack, we employ four diverse datasets with two protocols (Wi-Fi and LoRa) across various DNN architectures. Given that RF signals are often transformed into the frequency or time-frequency domains, this study also assesses attack efficacy in the time-frequency domain. Furthermore, we experiment with potential detection and defense methods, demonstrating the difficulty of fully safeguarding against our proposed backdoor attack. Additionally, we consider the attack performance in the domain shift case. Tianya Zhao, Junqing Zhang, Shiwen Mao, Xuyu Wang |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Explainable Adversarial Learning Framework on Physical Layer Key Generation Combating Malicious Reconfigurable Intelligent SurfaceabstractReconfigurable intelligent surfaces (RIS) can both help and hinder the physical layer secret key generation (PL-SKG) of communications systems. Whilst a legitimate RIS can yield beneficial impacts, including increased channel randomness to enhance PL-SKG, a malicious RIS can poison legitimate channels and crack almost all existing PL-SKGs. In this work, we propose an adversarial learning framework that addresses Man-in-the-middle RIS (MITM-RIS) eavesdropping which can exist between legitimate parties, namely Alice and Bob. First, the theoretical mutual information gap between legitimate pairs and MITM-RIS is deduced. From this, Alice and Bob leverage adversarial learning to learn a common feature space that assures no mutual information overlap with MITM-RIS. Next, to explain the trained legitimate common feature generator, we aid signal processing interpretation of black-box neural networks using a symbolic explainable AI (xAI) representation. These symbolic terms of dominant neurons aid the engineering of feature designs and the validation of the learned common feature space. Simulation results show that our proposed adversarial learning- and symbolic-based PL-SKGs can achieve high key agreement rates between legitimate users, and is further resistant to an MITM-RIS Eve with the full knowledge of legitimate feature generation (NNs or formulas). This therefore paves the way to secure wireless communications with untrusted reflective devices in future 6G. Zhuangkun Wei, Wenxiu Hu, Junqing Zhang, Weisi Guo, Julie A. McCann |
IEEE Trans. Wirel. Commun. | 3 |
| 2024 | Explanation-Guided Backdoor Attacks on Model-Agnostic RF FingerprintingabstractDespite the proven capabilities of deep neural networks (DNNs) for radio frequency (RF) fingerprinting, their security vulnerabilities have been largely overlooked. Unlike the extensively studied image domain, few works have explored the threat of backdoor attacks on RF signals. In this paper, we analyze the susceptibility of DNN-based RF fingerprinting to backdoor attacks, focusing on a more practical scenario where attackers lack access to control model gradients and training processes. We propose leveraging explainable machine learning techniques and autoencoders to guide the selection of positions and values, enabling the creation of effective backdoor triggers in a model-agnostic manner. To comprehensively evaluate our backdoor attack, we employ four diverse datasets with two protocols (Wi-Fi and LoRa) across various DNN architectures. Given that RF signals are often transformed into the frequency or time-frequency domains, this study also assesses attack efficacy in the time-frequency domain. Furthermore, we experiment with potential defenses, demonstrating the difficulty of fully safeguarding against our attacks. Tianya Zhao, Xuyu Wang, Junqing Zhang, Shiwen Mao |
INFOCOM | 3 |
| 2024 | ST-GCN: A Spatiotemporal Graph Convolution Neural Network for EEG Motor Imagery Signal DecodingabstractMotor imagery (MI) is a mental process extensively used in the experimental paradigm for brain-computer interfaces (BCIs) across various basic science and clinical research studies. Despite its widespread use, accurately decoding intentions from MI poses significant challenges due to the complex nature of brain patterns and the limited sample sizes typically available for machine learning. This paper introduces a Spatiotemporal Graph Neural Network (ST-GCN) designed for MI classification. First, the spatial-temporal convolution layer is used to extract features from raw EEG data, where mixed depthwise convolution extracts temporal features, followed by spatial filtering convolution that decomposes the EEG signal. A graph convolution module employing the max relative aggregator is then utilized to explore the relationships between the spatially decomposed EEG components. In the final step, under the combined supervision of cross-entropy and our proposed channel selection loss, the ST-GCN achieves feature extraction that enhances interclass dispersion and intraclass compactness. We compare ST-GCN with several benchmark EEG decoding methods on two MI datasets: the BCI Competition III Dataset IVa and the BCI Competition IV Dataset 1. ST-GCN outperforms the deep learning benchmark methods by achieving an accuracy of 78.11% and 71.94%, respectively, in 10-fold cross-validation. Jingzhou Xu, Jun Qi 0001, Junqing Zhang, Yong Yue 0001 |
ISPA | 3 |
| 2024 | LoRa Radio Frequency Fingerprinting Identification Using a Hybrid Quantum-Classical Neural NetworkabstractRadio frequency fingerprint identification is a promising technique for device authentication that relies on the unique radio frequency fingerprint features caused by hardware impairments. Existing radio frequency fingerprint identification models usually contain a significant number of trainable parameters, making them undesirable for Internet of Things applications. In this paper, we augment a classical neural network by introducing an intermediary quantum neural network stage to enhance the authentication of Internet of Things devices using radio frequency fingerprint features. The model is based on the combination of quantum and classical machine learning and benefits from a significantly smaller number of trainable parameters. Empirical results show that our proposed model not only achieves a much smaller footprint (in terms of device memory) but also delivers competitive accuracy to conventional deep learning approaches. It therefore shows much promise as a solution for securing networks which feature resource-constrained Internet of Things devices. To Truong An, Simon L. Cotton, Junqing Zhang, Yuan Ding 0001, Trung Quang Duong |
VTC Fall | 3 |
| 2024 | The Self-Detection Method of the Puppet Attack in Biometric FingerprintingabstractFingerprint authentication has become a staple in securing access to personal devices and sensitive information in our daily lives, with the security level of such systems being paramount. Recent attention has been drawn to the puppet attack, a forced fingerprint unlocking scenario that exploits legitimate user fingerprints for unauthorized access. Traditional authentication methods are constrained by their reliance on additional sensors and are typically limited to static authentication scenarios, lacking versatility in dynamic or mobile contexts. In this study, we employ physical modeling to elucidate puppet attack, unraveling the distinctive stress patterns, and points of application associated with forced interactions. By scrutinizing the physical alterations induced during such attacks, our investigation unveils discernible changes in the texture of fingerprints, specifically reflecting variations linked to different force patterns. Consequently, we introduce a detection system that operates without the need for external sensors, solely utilizing fingerprint images to extract texture features, thereby offering a broadly applicable solution. To address the challenge posed by the absence of puppet attack samples in existing data sets, we constructed a comprehensive database, incorporating a substantial number of puppet attack fingerprints collected from 70 volunteers aged between 20 and 75. This database facilitates a more robust detection of puppet attack. Our system demonstrates accuracy rates of 85.5%, 97.2%, 86.5%, and 78.1% across four distinct scenarios within our puppet attack database. Guyue Li, Yiyun Ma, Junqing Zhang, Hongyi Luo |
IEEE Internet Things J. | 4 |
| 2024 | On the Design of Robust Differential Beamformers From the Beampattern Error PerspectiveabstractDifferential microphone arrays (DMAs), which enhance acoustic signals of interest by measuring both the acoustic pressure field and its spatial derivatives, find extensive use in various practical systems and acoustic products. A critical element of DMAs is the differential beamformer, traditionally designed to ensure that the designed beampattern closely matches the desired target directivity pattern. However, such beamformers may lack sufficient robustness in practice. To address the balance between robustness and beampattern accuracy, this letter proposes two types of beamformers: one prioritizes maximizing the white noise gain (WNG) while maintaining a specified mean-squared beampattern error (MSBE), and the other aims to minimize MSBE while adhering to a specified level of WNG. By transforming these design challenges into quadratic eigenvalue problems (QEPs), we derive explicit solutions for the proposed beamformers. Simulations are conducted to illustrate the performance characteristics of these beamformers. Jingli Xie, Junqing Zhang, Jacob Benesty, Jingdong Chen |
IEEE Signal Process. Lett. | 3 |
| 2024 | Secret Key Generation for IRS-Assisted Multi-Antenna Systems: A Machine Learning-Based ApproachabstractPhysical-layer key generation (PKG) based on wireless channels is a lightweight technique to establish secure keys between legitimate communication nodes. Recently, intelligent reflecting surfaces (IRSs) have been leveraged to enhance the performance of PKG in terms of secret key rate (SKR), as it can reconfigure the wireless propagation environment and introduce more channel randomness. In this paper, we investigate an IRS-assisted PKG system, taking into account the channel spatial correlation at both the base station (BS) and the IRS. Based on the considered system model, the closed-form expression of SKR is derived analytically considering correlated eavesdropping channels. Aiming to maximize the SKR, a joint design problem of the BS’s precoding matrix and the IRS’s phase shift vector is formulated. To address this high-dimensional non-convex optimization problem, we propose a novel unsupervised deep neural network (DNN)-based algorithm with a simple structure. Different from most previous works that adopt iterative optimization to solve the problem, the proposed DNN-based algorithm directly obtains the BS precoding and IRS phase shifts as the output of the DNN. Simulation results reveal that the proposed DNN-based algorithm outperforms the benchmark methods with regard to SKR. Chen Chen 0071, Junqing Zhang, Tianyu Lu, Magnus Sandell, Liquan Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | PUF-Assisted Radio Frequency Fingerprinting Exploiting Power Amplifier Active Load-PullingabstractThis paper presents a novel radio frequency fingerprint (RFF) enhancement strategy by exploiting the physical unclonable function (PUF) to tune the RF hardware impairments in a unique and secure manner, which is exemplified by taking power amplifiers (PAs) in RF chains as an example. This is achieved by intentionally and slightly tuning the PA non-linearity characteristics using the active load-pulling technique. The motivation driving the proposed research is to enlarge the RFF feature differences among wireless devices of same vendor, in order to massively improve their RFF classification accuracy in low to medium signal to noise ratio (SNR) channel conditions. PUF is employed to dynamically tune the PA’s RFF feature which guarantees the security since the PUF response cannot be cloned. Specifically, a ring oscillator (RO)-based PUF is implemented to control the PA non-linearity by selecting unique but random configuration parameters. This approach is proposed to amplify the distinctions across same model PAs, thereby enhancing the RFF classification performance. In the meantime, our innovative strategy of PUF-assisted RFF does not noticeably compromise communication link performance which is experimentally tested. The resulting RFF features can be extracted from the received distorted constellation diagrams with the help of image recognition-based machine learning classification algorithms. Extensive experimental evaluations are carried out using both cable-connected and over-the-air (OTA) measurements. Our proposed approach, when classifying eight PAs from a same vendor, achieves 11% to 24% average classification accuracy improvement by enlarging the RFF feature differences arising from the PA non-linearity. Yuepei Li, Junqing Zhang, Chongyan Gu, Yuan Ding 0001, George Goussetis, Symon K. Podilchak |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Reconfigurable Intelligent Surface-Assisted Key Generation for Millimeter-Wave Multi-User SystemsabstractPhysical layer key generation (PLKG) leverages wireless channels to produce secret keys for legitimate users. However, in millimetre-wave (mmWave) frequency bands, the presence of blockage significantly reduces the key rate (KR) of a PLKG system. To address this issue, we introduce reconfigurable intelligent surfaces (RISs) as a potential solution for constructing RIS-reflected channels, thereby enhancing the KR. Our study focuses on the beam-domain channel model and exploits the sparsity of mmWave bands to enhance the randomness of secret keys. To relieve pilot overhead in multi-user systems, we employ a compressed sensing (CS) algorithm to estimate angular information and propose a channel probing protocol with the full-array configuration for acquiring the beam-domain channel. We derive the analytical expressions for the KR in the case of full-array configuration. To optimize the KR, we design the phase shift and precoding vectors based on the obtained angular information. Furthermore, we employ a water-filling algorithm that relies on the Karush-Kuhn-Tucker (KKT) conditions to optimize power allocation for estimating the beam-domain channel with the same channel variance. When channel variances of the beam-domain channel differ, we design a deep-learning-based power allocation method for a more complex problem. What is more, we design a sub-array configuration scheme that exploits the difference in spatial angles between users to reduce pilot overhead and derive the analytical expression for the KR. Through extensive simulations, we demonstrate that our proposed PLKG schemes outperform existing methods. Tianyu Lu, Liquan Chen, Junqing Zhang, Chen Chen 0071, Trung Quang Duong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Federated Radio Frequency Fingerprint Identification Powered by Unsupervised Contrastive LearningabstractRadio frequency fingerprint identification (RFFI) is a promising physical layer authentication technique that utilizes the unique impairments within the analog front-end of transmitters as distinct identifiers. State-of-the-art RFFI systems are frequently powered by deep learning, which requires extensive training data to ensure satisfactory performance. However, current RFFI studies suffer from a severe lack of training data, which poses challenges in achieving high identification accuracy. In this paper, we propose a federated RFFI system that is particularly suitable for Internet of Things (IoT) networks, which holds a high potential to address the data scarcity challenge in RFFI development. Specifically, all the receivers in an IoT network can pre-train a deep learning-driven feature extractor in a federated and unsupervised manner. Subsequently, a new client can perform fine-tuning on the basis of the pre-trained feature extractor to activate its RFFI functionality. Extensive experimental evaluation was carried out, involving 60 commercial off-the-shelf (COTS) LoRa transmitters and six software-defined radio (SDR) receivers. The experimental results demonstrate that the federated RFFI protocol can effectively improve the identification accuracy from 63% to 95%, and is robust to receiver hardware and location variations. Guanxiong Shen, Junqing Zhang, Xuyu Wang, Shiwen Mao |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Towards Receiver-Agnostic and Collaborative Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) is an emerging device authentication technique, which exploits the hardware characteristics of the RF front-end as device identifiers. The receiver hardware impairments interfere with the feature extraction of transmitter impairments, but their effect and mitigation have not been comprehensively studied. In this paper, we propose a receiver-agnostic RFFI system by employing adversarial training to learn the receiver-independent features. Moreover, when there are multiple receivers, collaborative inference are designed to enhance classification accuracy. Finally, we show how it is possible to leverage fine-tuning for further improvement with fewer collected signals. To validate the approach, we have conducted extensive experimental evaluation by applying the approach to a LoRaWAN case study involving ten LoRa devices and 20 software-defined radio (SDR) receivers. The results show that receiver-agnostic training enables the trained neural network to become robust to changes in receiver characteristics. The collaborative inference improves classification accuracy by up to 20% beyond a single-receiver RFFI system and fine-tuning can bring a 40% improvement for underperforming receivers. The system is further evaluated on a more practical testbed. By making additional use of online augmentation and multi-packet inference, the identification accuracy is improved from 50% to 90% at 10 dB. Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Roger F. Woods, Joseph R. Cavallaro, Liquan Chen |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | FewSense, Towards a Scalable and Cross-Domain Wi-Fi Sensing System Using Few-Shot LearningabstractWi-Fi sensing can classify human activities because each activity causes unique changes to the channel state information (CSI). Existing WiFi sensing suffers from limited scalability as the system needs to be retrained whenever new classes are added, which causes overheads of data collection and retraining. Cross-domain sensing may fail because the mapping between activities and CSI variations is destroyed when a different environment or user (domain) is involved. This paper proposed a few-shot learning-based WiFi sensing system, named FewSense, which can recognise novel classes in unseen domains with only a few samples. Specifically, a feature extractor was pre-trained offline using the source domain data. When the system was applied in the target domain, a few samples were used to fine-tune the feature extractor for domain adaptation. Inference was made by computing the cosine similarity. FewSense can further boost the classification accuracy by collaboratively fusing inference from multiple receivers. We evaluated the performance of FewSense using three public datasets, i.e., SignFi, Widar, and Wiar. The results show that FewSense with five-shot learning recognised novel classes in unseen domains with an accuracy of 93.9%, 96.5%, and 82.7% on the SignFi, Widar, and Wiar datasets, respectively. Our collaborative sensing model improved system performance by an average of 29.2%. Guolin Yin, Junqing Zhang, Guanxiong Shen, Yingying Chen 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Deep Learning-Enhanced Physical Layer Authentication for Mobile DevicesabstractThe Internet of Things (IoT) is ubiquitous thanks to the rapid development of wireless technology. However, the broadcast nature of wireless transmission results in great challenges to the security authentication for large-scale IoT. In this paper, we propose a novel physical layer authentication approach for mobile scenarios employing deep learning and channel state information (CSI). Specifically, the convolution neural network (CNN) is designed to learn the temporal and spatial similarity between CSIs and output a score to measure the difference between the input CSIs. Device authentication is achieved by comparing the score to an empirically obtained threshold. We build a WiFi-based testbed and carry out a comprehensive experimental evaluation. The performance of using the CSI magnitude and real & imaginary parts is compared. The effect of the distance between legitimate and rogue devices on authentication performance is studied. The generalization performance of the CNN model in different test scenarios is also evaluated. Experiment results demonstrate the effectiveness of the proposed CNN-based authentication over conventional correlation-based authentication schemes. Yijia Guo, Junqing Zhang, Yao-Win Peter Hong |
GLOBECOM | 2 |
| 2023 | Machine Learning-Based Secret Key Generation for IRS-Assisted Multi-Antenna SystemsabstractPhysical-layer key generation (PKG) based on wireless channels is a lightweight technique to establish secure keys between legitimate communication nodes. Recently, intelligent reflecting surfaces (IRSs) have been leveraged to enhance the performance of PKG in terms of secret key rate (SKR), as it can reconfigure the wireless propagation environment and introduce more channel randomness. In this paper, we investigate an IRS-assisted PKG system, taking into account the channel spatial correlation at both the base station (BS) and the IRS. Based on the considered system model, the closed-form expression of SKR is derived analytically. Aiming to maximize the SKR, a joint design problem of the BS's precoding matrix and the IRS's reflecting coefficient vector is formulated. To address this high-dimensional non-convex optimization problem, we propose a novel unsupervised deep neural network (DNN) based algorithm with a simple structure. Different from most previous works that adopt the iterative optimization to solve the problem, the proposed DNN based algorithm directly obtains the BS precoding and IRS phase shifts as the output of the DNN. Simulation results reveal that the proposed DNN-based algorithm outperforms the benchmark methods with regard to SKR. Chen Chen 0071, Junqing Zhang, Tianyu Lu, Magnus Sandell, Liquan Chen |
ICC | 2 |
| 2023 | RelativeRFF: Multi-Antenna Device Identification in Multipath Propagation ScenariosabstractRadio frequency fingerprinting (RFF) is a promising solution for realizing secure and efficient device authentication. The multipath channel overshadows and disrupts the RFF extraction, which causes difficulties in training new models in the presence of fading. Existing approaches attempt to deal with this challenge by traversing channels through simulated channel models. However, this solution requires a large amount of data for training and it is difficult to guarantee that the training covers all possible channels. To mitigate the multipath channel effect on RFF with less training data, we propose a new method in a multi-antenna system, named Relative-RFF (R-RFF), which utilizes channel state information (CSI) feedback to counteract the multipath channel. The RFF imperfection relation between the different antenna chains of the device is proved to be retained after the counteraction of the multipath channel. Numerical results demonstrate that the proposed R-RFF can achieve an identification accuracy of 95.9% for 30 UEs in Tapped Delay Line channel with a signal-to-noise ratio of 20 dB. Hongyi Luo, Guyue Li, Yuexiu Xing, Junqing Zhang, Aiqun Hu, Xianbin Wang 0001 |
ICC | 4 |
| 2023 | White-Box Adversarial Attacks on Deep Learning-Based Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits unique hardware impairments as device identifiers, and deep learning is widely deployed as the feature extractor and classifier for RFFI. However, deep learning is vulnerable to adversarial attacks, where adversarial examples are generated by adding perturbation to clean data for causing the classifier to make wrong predictions. Deep learning-based RFFI has been shown to be vulnerable to such attacks, however, there is currently no exploration of effective adversarial attacks against a diversity of RFFI classifiers. In this paper, we report on investigations into white-box attacks (non-targeted and targeted) using two approaches, namely the fast gradient sign method (FGSM) and projected gradient descent (PGD). A LoRa testbed was built and real datasets were collected. These adversarial examples have been experimentally demonstrated to be effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU). Junqing Zhang, Guanxiong Shen, Alan Marshall 0001, Chip-Hong Chang |
ICC | 2 |
| 2023 | PLSR: Unstructured Pruning with Layer-Wise Sparsity RatioabstractIn the current era of multi-modal and large models gradually revealing their potential, neural network pruning has emerged as a crucial means of model compression. It is widely recognized that models tend to be over-parameterized, and pruning enables the removal of unimportant weights, leading to improved inference speed while preserving accuracy. From early methods such as gradient-based, and magnitude-based pruning to modern algorithms like iterative magnitude pruning, lottery ticket hypothesis, and pruning at initialization, researchers have strived to increase the compression ratio of model parameters while maintaining high accuracy. Currently, mainstream algorithms focus on the global pruning of neural networks using various scoring functions, followed by different pruning strategies to enhance the accuracy of sparse model. Recent studies have shown that random pruning with varying layer-wise sparsity ratio has achieved robust results for large models and out-of-distribution data. Based on this discovery, we propose a new score called FeatIO, which is based on module input and output feature map sizes. As a score function used in PaI, FeatIO surpasses the performance of other PaI score functions. Additionally, we propose a novel pruning strategy called Pruning with Layer-wise Sparsity Ratio (PLSR), which conbines the layer-wise sparsity ratios and magnitude-based score function, resulting in optimal evaluation performance. Almost all algorithms exhibit improved performance when using our novel pruning strategy. The combination of PLSR and FeatIO consistently outperforms other algorithms in testing, demonstrating the significant potential of our proposed approach. Our code will be available here. Haocheng Zhao, Limin Yu, Runwei Guan, Liye Jia, Junqing Zhang, Yutao Yue |
ICMLA | 5 |
| 2023 | Reconfigurable Intelligent Surface-Assisted Key Generation for Millimeter Wave CommunicationsabstractPhysical layer key generation (PLKG) exploits the distributed entropy source of wireless channels to generate secret keys for legitimate users. When the millimeter wave (mmWave) channel is blocked, reconfigurable intelligent surfaces (RISs) have emerged as a prospective approach to constructing reflected channels and improving the secret key rate (SKR). This paper investigates the key generation scheme for the RIS-aided mmWave system. We study the beam domain channel model and exploit the sparsity of mmWave bands to reduce the pilot overhead. We propose a channel probing method to acquire the reciprocal angular information and channel gains. To analyze the SKR, we investigate the channel covariance matrix of beam domain channels. We find that the channel gains of beams are uncorrelated which increases the randomness of secret keys. Considering an eavesdropper, we derive the analytical expressions of SKR when the eavesdropping channel has overlapping clusters with the legitimate channel. Simulations validate that the proposed PLKG scheme outperforms existing schemes. Tianyu Lu, Liquan Chen, Junqing Zhang, Chen Chen 0071, Trung Quang Duong |
WCNC | 3 |
| 2023 | Design of a Channel Robust Radio Frequency Fingerprint Identification SchemeabstractRadio frequency fingerprint (RFF) identification is an emerging device authentication technique that exploits the hardware imperfections resulting from the manufacturing process. Due to the varying impact of the wireless channel during RFF training and test stages, it is challenging to design channel-independent RFF techniques. This article designs a channel robust RFF identification scheme by leveraging the different spectrum of adjacent signal symbols, named the Difference of the Logarithm of the Spectrum (DoLoS), which does not rely on a single RFF feature or requires additional manipulation of the devices under test. Specifically, DoLoS exploits the fact that two different symbols in a packet exhibit different RFF features but have a similar channel response during the channel coherence time. We implemented the DoLoS with the IEEE 802.11 orthogonal frequency division multiplexing (OFDM) system as a case study. We carried out extensive experiments using seven Wi-Fi devices of the same model in different wireless channel environments, including 12 data collection positions in two completely different environments. Compared with conventional RFF identification schemes that do not eliminate channel effects, our scheme is robust to channel variations and the highest identification accuracy is 99.02% in the single-environment evaluation and 97.05% in the cross-environment evaluation. Yuexiu Xing, Aiqun Hu, Junqing Zhang, Linning Peng, Xianbin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2023 | CGMM-Based Sound Zone Generation Using Robust Pressure Matching With ATF Perturbation ConstraintsabstractPersonal sound zone (PSZ) refers to the technique that uses an array of loudspeakers and digital signal processing tools to achieve spatial soundfield control. To generate the target sound zones, this technique generally requires to know the acoustic transfer functions (ATFs) between the loudspeakers and the spots where soundfields are to be controlled. In practical applications, however, the true ATFs are never accessible and they have to be measured or estimated. Due to many sophisticated reasons, the measured ATFs generally deviate from the true ones, which may lead to significant degradation in performance of sound zone reproduction. In this work, a robust pressure matching (RPM) algorithm is presented for sound zone generation. It exploits a complex Gaussian mixture model (CGMM) to model the ATFs and their perturbations. The CGMM parameters are estimated using the expectation-maximization (EM) algorithm. To improve the robustness of the pressure matching method, an uncertainty constraint is applied to the ATF estimates and the pressure matching problem is then formulated as one of biconvex optimization. The coordinate descent algorithm is subsequently used to solve the optimization problem, thereby obtaining the optimal control filter. In comparison with the existing pressure matching methods without considering the effect of ATF perturbations, the presented algorithm is able to achieve lower normalized signal distortion energy and higher signal to interference ratio. Numerical simulations justify the effectiveness of the presented algorithm as well as its advantages over the traditional methods. Junqing Zhang, Liming Shi, Mads Græsbøll Christensen, Wen Zhang 0002, Lijun Zhang 0004, Jingdong Chen |
IEEE ACM Trans. Audio Speech Lang. Process. | 1 |
| 2023 | Joint Precoding and Phase Shift Design in Reconfigurable Intelligent Surfaces-Assisted Secret Key GenerationabstractPhysical layer key generation (PLKG) is a promising technique to establish symmetric keys between resource-constrained legitimate users. However, PLKG suffers from a low key rate in harsh environments where channel randomness is limited. To address the problem, reconfigurable intelligent surfaces (RISs) are introduced to reshape the channels by controlling massive reflecting elements, which can provide more channel diversity. In this paper, we design a channel probing protocol to fully extract the randomness from the cascaded channel, i.e., the channels through reflecting elements. We derive the analytical expressions of the key rate and design a water-filling algorithm based on the Karush-Kuhn-Tucker (KKT) conditions to find the upper bound. To find the optimal precoding and phase shift matrices, we propose an algorithm based on the Grassmann manifold optimization methods. The system is evaluated in terms of the key rate, bit disagreement rate (BDR) and randomness. Simulation results show that our protocols significantly improve the key rate as compared to existing protocols. Compared to multiple-antennas systems without a RIS, our proposed method achieves an average 9.51 dB performance gain when the side length of an element is 1/4 wavelength and the Rician factor is 0 dB. Tianyu Lu, Liquan Chen, Junqing Zhang, Chen Chen 0071, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Toward Length-Versatile and Noise-Robust Radio Frequency Fingerprint IdentificationabstractRadio frequency fingerprint identification (RFFI) can classify wireless devices by analyzing the signal distortions caused by intrinsic hardware impairments. Recently, state-of-the-art neural networks have been adopted for RFFI. However, many neural networks, e.g., multilayer perceptron (MLP) and convolutional neural network (CNN), require fixed-size input data. In addition, many IoT devices work in low signal-to-noise ratio (SNR) scenarios but the RFFI performance in such scenarios is often unsatisfactory. In this paper, we analyze the reason why MLP- and CNN-based RFFI systems are constrained by the input size. To overcome this, we propose four neural networks that can process signals of variable lengths, namely flatten-free CNN, long short-term memory (LSTM) network, gated recurrent unit (GRU) network, and transformer. We adopt data augmentation during training which can significantly improve the model’s robustness to noise. We compare two augmentation schemes, namely offline and online augmentation. The results show the online one performs better. During the inference, a multi-packet inference approach is further leveraged to improve the classification accuracy in low SNR scenarios. We take LoRa as a case study and evaluate the system by classifying 10 commercial-off-the-shelf LoRa devices in various SNR conditions. The online augmentation can boost the low-SNR classification accuracy by up to 50% and the multi-packet inference approach can further increase the accuracy by over 20%. Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Mikko Valkama, Joseph R. Cavallaro |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | H2K: A Heartbeat-Based Key Generation Framework for ECG and PPG SignalsabstractWireless body area network is a key enabler for connected healthcare but recent cyberattacks have compromised its security and trustworthiness. This paper investigates heartbeat-based key generation to secure body area networks. The interpulse intervals (IPIs) between any two adjacent peaks of heartbeat signals are random and state-of-the-art literature has demonstrated that IPI is a good random source to be extracted as cryptographic keys. Heartbeat signals can be measured by electrocardiography (ECG) and photoplethysmography (PPG) sensors. A general heartbeat-based key generation framework applicable to both ECG and PPG signals is proposed. A robust peak detection algorithm is designed to capture noisy peaks and a simple yet efficient IPI alignment algorithm to align the common IPIs. A key establishment protocol is used to convert analog IPIs to digital binaries and reconcile them between legitimate devices. We evaluate the performance for both ECG signals from an online public database, MIT PhysioBank, and PPG signals collected from our testbed. The results demonstrate that our algorithm is robust and heartbeat-based key generation can be completed for both ECG and PPG signals. We finally create a PPG-based prototype and a demonstration video to show the practicality of our framework. Junqing Zhang, Yushi Zheng, Weitao Xu, Yingying Chen 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2022 | Signal-independent RFF Identification for LTE Mobile Devices via Ensemble Deep LearningabstractRadio frequency fingerprint (RFF)-based wireless device authentication is an emerging technique to prevent potential spoofing attacks in wireless communications. The random access preamble of the physical random access channel (PRACH) in Long Term Evolution (LTE) systems is the first message sent from a user equipment (UE). However, PRACH preambles change under different evolved Node B (eNB), which will affect the RFF extraction. In this paper, a signal-independent RFF extraction method is first proposed to extract varying LTE PRACH preambles under different LTE eNBs. Residual transient segment (RTS) features from the varying PRACH preambles are extracted for RFF identification. A convolutional neural network (CNN) based ensemble deep learning scheme is proposed to integrate benefits from different RFF features. An experimental system under real operator LTE eNB is designed to capture and identify real UE signals. Experimental results show that the classification accuracy of five UEs can reach more than 95% under the same eNB and 85% under different eNBs. Furthermore, longtime evaluations show that the UE RTS feature is robust over time. Yanjin Qiu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
GLOBECOM | 3 |
| 2022 | Robust Pressure Matching with ATF Perturbation Constraints for Sound Field ControlabstractSound field control systems deployed in room acoustic environments require knowing the acoustic channel impulse responses between the loudspeakers and matching microphones, which are challenging to estimate accurately due to perturbations caused by such factors as temperature changes and sensors’ position mismatches. To deal with this issue, a robust pressure matching algorithm is developed in this work where a perturbation term of the acoustic transfer function (ATF) is modeled as a Gaussian process, based on which an uncertainty constraint is applied to limit the impact of perturbation on pressure matching. This constrained problem is formulated as one of biconvex optimization, and a coordinate descent algorithm is adopted to estimate the optimal control filter. Simulations are performed and results show that the proposed method is able to achieve more accurate control as compared to the standard pressure matching algorithm in the presence of ATF perturbations. Junqing Zhang, Liming Shi, Mads Græsbøll Christensen, Wen Zhang 0002, Lijun Zhang 0004, Jingdong Chen |
ICASSP | 1 |
| 2022 | Colluding RF Fingerprint Impersonation Attack Based on Generative Adversarial NetworkabstractRadio frequency fingerprint (RFF) is an effective way to improve the security of wireless communications. Existing research mainly focused on the classification capability and the robustness of RFFs but overlooked malicious attacks. In this paper, a colluding impersonation attack framework is proposed to emulate the RFF of legitimate users. A colluding attacker is introduced to observe the signal features of the impersonation attacker and the legitimate user and compare their difference. The difference is fed back to the impersonation attacker to help improve its RFF impersonation method. With this idea, the impersonation attack is realized by the Generative Adversarial Network (GAN) structure. The RFF impersonation is formulated as the generator whose objective is to output the signal with RFF similar to the legitimate user, viewed from the colluding attacker’s perspective. Simulation results show that the proposed method can effectively impersonate the legitimate user’s RFF under the dynamic block fading channel. Ming Liu 0010, Linning Peng, Junqing Zhang |
ICC | 4 |
| 2022 | Fast and Secure Key Generation with Channel Obfuscation in Slowly Varying EnvironmentsabstractPhysical-layer secret key generation has emerged as a promising solution for establishing cryptographic keys by leveraging reciprocal and time-varying wireless channels. However, existing approaches suffer from low key generation rates and vulnerabilities under various attacks in slowly varying environments. We propose a new physical-layer secret key generation approach with channel obfuscation, which improves the dynamic property of channel parameters based on random filtering and random antenna scheduling. Our approach makes one party obfuscate the channel to allow the legitimate party to obtain similar dynamic channel parameters, yet prevents a third party from inferring the obfuscation information. Our approach allows more random bits to be extracted from the obfuscated channel parameters by a joint design of the K-L transform and adaptive quantization. Results from a testbed implementation show that our approach, compared to the existing ones that we evaluate, performs the best in generating high entropy bits at a fast rate and is able to resist various attacks in slowly varying environments. Specifically, our approach can achieve a significantly faster secret bit generation rate at roughly 67 bit/pkt, and the key sequences can pass the randomness tests of the NIST test suite. Guyue Li, Haiyu Yang, Junqing Zhang, Hongbo Liu 0002, Aiqun Hu |
INFOCOM | 3 |
| 2022 | Authorized and Rogue LTE Terminal Identification Using Wavelet Coefficient Graph with Auto-encoderabstractThe wide popularity of 4G/5G mobile terminals increase the requirements of wireless security. Radio frequency fingerprint (RFF) technology can strengthen 4G/5G air interface accessing security at the physical layer. In this paper, a wavelet transform (WT) coefficient graphs RFF extraction with auto-encoder (AE) based rogue terminal detection scheme is proposed. At first, WT coefficients at 48 scales are extracted from the transient-power-off part of LTE physical random access channel (PRACH) preamble. Then, an AE network structure aimed for 2D WT coefficient graph is designed for rogue terminal detection. We successfully distinguish 7 mobile phones and 1 USRP under the proposed mechanism, where the authorized terminals from the same manufacturer can be identified with an accuracy of 90.08%. In addition, extensive experiments are carried out at LOS and NOLS scenarios, respectively, the proposed LTE identification scheme has demonstrated robustness in dynamic environments. Zhenni Wu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
VTC Fall | 3 |
| 2022 | A channel perceiving attack and the countermeasure on long-range IoT physical layer key generation
Yansong Gao 0001, Junqing Zhang, Seyit Ahmet Çamtepe, Dhammika Jayalath |
Comput. Commun. | 3 |
| 2022 | Physical-Layer-Based Secure Communications for Static and Low-Latency Industrial Internet of ThingsabstractThis article proposes a wireless key generation solution for secure low-latency communications with active jamming attack prevention in wireless networked control systems (WNCSs) of Industrial Internet of Things (IIoT) applications. We first identify a new vulnerability in physical-layer key generation schemes using wireless channel and random pilots (RPs) in static environments. We derive a closed-form expression for the probability that the RP-based key is successfully attacked by a long-term eavesdropper at a fixed location. To prevent such attacks, we propose a one-time pad (OTP) encrypted transmission solution assisted by one-way self-interference (SI), which has low-latency, high-security benefits, and active attack detection capability. The performance of the proposed scheme is analytically compared with two benchmark RP-based schemes, and its advantages are verified in a ray-tracing-based simulation environment. We further investigate the impact of critical design parameters, which reveal fundamental insights for the deployment and implementation of our proposed secure communications scheme. Zijie Ji, Phee Lep Yeoh, Gaojie Chen 0001, Junqing Zhang, Yan Zhang 0041, Zunwen He, Yonghui Li 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Deep-Learning-Based Physical-Layer Secret Key Generation for FDD SystemsabstractPhysical-layer key generation (PKG) establishes cryptographic keys from highly correlated measurements of wireless channels, which relies on reciprocal channel characteristics between uplink and downlink, is a promising wireless security technique for Internet of Things (IoT). However, it is challenging to extract common features in frequency-division duplexing (FDD) systems as uplink and downlink transmissions operate at different frequency bands whose channel frequency responses are not reciprocal anymore. Existing PKG methods for FDD systems have many limitations, i.e., high overhead and security problems. This article proposes a novel PKG scheme that uses the feature mapping function between different frequency bands obtained by deep learning to make two users generate highly similar channel features in FDD systems. In particular, this is the first time to apply deep learning for PKG in FDD systems. We first prove the existence of the band feature mapping function for a given environment and a feedforward network with a single hidden layer can approximate the mapping function. Then, a key generation neural network (KGNet) is proposed for reciprocal channel feature construction, and a key generation scheme based on the KGNet is also proposed. Numerical results verify the excellent performance of the KGNet-based key generation scheme in terms of randomness, key generation ratio, and key error rate. Besides, the overhead analysis shows that the method proposed in this article can be used for resource-constrained IoT devices in FDD systems. Xinwei Zhang 0002, Guyue Li, Junqing Zhang, Aiqun Hu, Zongyue Hou, Bin Xiao 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Towards Scalable and Channel-Robust Radio Frequency Fingerprint Identification for LoRaabstractRadio frequency fingerprint identification (RFFI) is a promising device authentication technique based on transmitter hardware impairments. The device-specific hardware features can be extracted at the receiver by analyzing the received signal and used for authentication. In this paper, we propose a scalable and channel-robust RFFI framework achieved by deep learning powered radio frequency fingerprint (RFF) extractor and channel independent features. Specifically, we leverage deep metric learning to train an RFF extractor, which has excellent generalization ability and can extract RFFs from previously unseen devices. Any devices can be enrolled via the pre-trained RFF extractor and the RFF database can be maintained efficiently for allowing devices to join and leave. Wireless channel impacts the RFF extraction and is tackled by exploiting channel independent features and data augmentation. We carried out extensive experimental evaluation involving 60 commercial off-the-shelf LoRa devices and a USRP N210 software defined radio platform. The results have successfully demonstrated that our framework can achieve excellent generalization abilities for rogue device detection and device classification as well as effective channel mitigation. Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Joseph R. Cavallaro |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | LTE Device Identification Based on RF Fingerprint with Multi-Channel Convolutional Neural NetworkabstractRadio frequency fingerprint (RFF) identification technique has drawn great attention to wireless terminal authentication. Long-Term Evolution (LTE) has been widely deployed all over the world. RFF-based LTE terminal identifications can prevent the potential impersonation or denial of service (DoS) attacks in the physical layer. This paper proposes a novel multi-channel convolutional neural network (MCCNN) for LTE terminal identification. Differential constellation trace figure (DCTF) is extracted from the random access preamble of the physical random access channel (PRACH). To the best knowledge of the authors, this is the first work dedicated to RFF-based LTE terminal identification. The proposed scheme is evaluated in the hardware experimental system consisting of the LTE eNodeB implemented on the software-defined radio (SDR) platform and six LTE mobile phones. Experimental results show that the classification accuracy can reach 98.96% at the SNR level of 30 dB with the line-of-sight (LOS) scenarios. Furthermore, long-time evaluations show that the proposed DCTF-MCCNN scheme is robust over time. Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
GLOBECOM | 3 |
| 2021 | Radio Frequency Fingerprint Identification for LoRa Using Spectrogram and CNNabstractRadio frequency fingerprint identification (RFFI) is an emerging device authentication technique that relies on intrin-sic hardware characteristics of wireless devices. We designed an RFFI scheme for Long Range (LoRa) systems based on spectrogram and convolutional neural network (CNN). Specifically, we used spectrogram to represent the fine-grained time-frequency characteristics of LoRa signals. In addition, we revealed that the instantaneous carrier frequency offset (CFO) is drifting, which will result in misclassification and significantly compromise the system stability; we demonstrated CFO compensation is an effective mitigation. Finally, we designed a hybrid classifier that can adjust CNN outputs with the estimated CFO. The mean value of CFO remains relatively stable, hence it can be used to rule out CNN predictions whose estimated CFO falls out of the range. We performed experiments in real wireless environments using 20 LoRa devices under test (DUTs) and a Universal Software Radio Peripheral (USRP) N210 receiver. By comparing with the IQ-based and FFT-based RFFI schemes, our spectrogram-based scheme can reach the best classification accuracy, i.e., 97.61% for 20 LoRa DUTs. Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Linning Peng, Xianbin Wang 0001 |
INFOCOM | 2 |
| 2021 | Encrypting Wireless Communications on the Fly Using One-Time Pad and Key GenerationabstractThe one-time pad (OTP) secure transmission relies on the random keys to achieve perfect secrecy, while the unpredictable wireless channel is shown to be a good random source. There is very few work of the joint design of OTP and key generation from wireless channels. This article provides a comprehensive and quantitative investigation on secure transmission achieved by OTP and wireless channel randomness. We propose two OTP secure transmission schemes, i.e., identical key-based physical-layer secure transmission (IK-PST) and un-IK-PST (UK-PST). We quantitatively analyze the performance of both schemes and prove that UK-PST outperforms IK-PST. We extend the pairwise schemes to a group of users in networks with star and chain topologies. We implement prototypes of both schemes and evaluate the proposed schemes through both simulations and experiments. The results verify that UK-PST has a higher effective secret transmission rate than that of IK-PST for scenarios with both pairwise and group users. Guyue Li, Zheying Zhang, Junqing Zhang, Aiqun Hu |
IEEE Internet Things J. | 3 |
| 2021 | Radio Frequency Fingerprint Identification for LoRa Using Deep LearningabstractRadio frequency fingerprint identification (RFFI) is an emerging device authentication technique that relies on the intrinsic hardware characteristics of wireless devices. This paper designs a deep learning-based RFFI scheme for Long Range (LoRa) systems. Firstly, the instantaneous carrier frequency offset (CFO) is found to drift, which could result in misclassification and significantly compromise the stability of the deep learning-based RFFI system. CFO compensation is demonstrated to be effective mitigation. Secondly, three signal representations for deep learning-based RFFI are investigated in time, frequency, and time-frequency domains, namely in-phase and quadrature (IQ) samples, fast Fourier transform (FFT) results and spectrograms, respectively. For these signal representations, three deep learning models are implemented, i.e., multilayer perceptron (MLP), long short-term memory (LSTM) network and convolutional neural network (CNN), in order to explore an optimal framework. Finally, a hybrid classifier that can adjust the prediction of deep learning models with the estimated CFO is designed to further increase the classification accuracy. The CFO will not change dramatically over several continuous days, hence it can be used to correct predictions when the estimated CFO is much different from the reference one. Experimental evaluation is performed in real wireless environments involving 25 LoRa devices and a Universal Software Radio Peripheral (USRP) N210 platform. The spectrogram-CNN model is found to be optimal for classifying LoRa devices which can reach an accuracy of 96.40% with the least complexity and training time. Guanxiong Shen, Junqing Zhang, Alan Marshall 0001, Linning Peng, Xianbin Wang 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2021 | Spatial Active Noise Control in Rooms Using Higher Order SourcesabstractAll spatial active noise control (ANC) systems, when deployed in typical room environments, have time-varying acoustic channels between the secondary sources and the error microphones. The conventional online secondary path modeling techniques, which introduces additive auxiliary random noise to estimate the secondary paths, become challenging especially in a multichannel setup. In this work, we propose to use higher-order variable-directivity sound sources as secondary sources for spatial ANC, in which both the interior residual noise field within the control region and exterior sound field due to secondary source radiation are jointly controlled. The aim of controlling the exterior sound field is to minimize room reverberation generated by the secondary sources so that the secondary paths in the proposed algorithm can be approximated as free-field propagation and thus can be pre-calibrated. The system is implemented in an adaptive manner to track noise variations. The results show that the proposed method can effectively cancel spatial noise field and control exterior sound field at an acceptable low level in time-varying room environments. Junqing Zhang, Wen Zhang 0002, Jihui Zhang 0006, Thushara D. Abhayapala, Lijun Zhang 0004 |
IEEE ACM Trans. Audio Speech Lang. Process. | 1 |
| 2021 | NISA: Node Identification and Spoofing Attack Detection Based on Clock Features and Radio Information for Wireless Sensor NetworksabstractNode identification based on unique hardware features like clock skews has been considered an efficient technique in wireless sensor networks (WSNs). Spoofing attacks imitating unique hardware features, however, could significantly impair or break down conventional clock-skew-based node identification due to exposed clock information through broadcasting. To defend against Spoofing attacks, we propose a new node identification scheme callednode identification against Spoofing attack(NISA). It utilizes the reverse time synchronization framework, where sensor nodes’ clock skews are estimated at the head of a WSN, and the spatially-correlated radio link information to achieve simultaneous node identification and attack detection. We further provide centralized and distributed NISA for covering both single-hop and multi-hop scenarios, the former of which employs a single-input and multiple-output convolutional neural network. With a real WSN testbed consisting of TelosB sensor nodes running TinyOS, we investigate the identifiability of clock skews under temperature and voltage variations and evaluate the performance of both centralized and distributed NISA. Experimental results demonstrate that both centralized and distributed NISA could provide accurate node identification and Spoofing attack detection. Xintao Huan, Kyeong Soo Kim, Junqing Zhang |
IEEE Trans. Commun. | 3 |
| 2021 | Sum Secret Key Rate Maximization for TDD Multi-User Massive MIMO Wireless NetworksabstractPhysical-layer key generation (PKG) based on channel reciprocity has recently emerged as a new technique to establish secret keys between devices. Most works focus on pairwise communication scenarios with single or small-scale antennas. However, the fifth generation (5G) wireless communications employ massive multiple-input multiple-output (MIMO) to support multiple users simultaneously, bringing serious overhead of reciprocal channel acquisition. This paper presents a multi-user secret key generation in massive MIMO wireless networks. We provide a beam domain channel model, in which different elements represent the channel gains from different transmit directions to different receive directions. Based on this channel model, we analyze the secret key rate and derive a closed-form expression under independent channel conditions. To maximize the sum secret key rate, we provide the optimal conditions for the Kronecker product of the precoding and receiving matrices and propose an algorithm to generate these matrices with pilot reuse. The proposed optimization design can significantly reduce the pilot overhead of the reciprocal channel state information acquisition. Furthermore, we analyze the security under the channel correlation between user terminals (UTs), and propose a low overhead multi-user secret key generation with non-overlapping beams between UTs. Simulation results demonstrate the near-optimal performance of the proposed precoding and receiving matrices design and the advantages of the non-overlapping beam allocation. Guyue Li, Chen Sun 0004, Eduard A. Jorswieck, Junqing Zhang, Aiqun Hu, You Chen 0004 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Radio Frequency Fingerprint Identification for Narrowband Systems, Modelling and ClassificationabstractDevice authentication is essential for securing Internet of things. Radio frequency fingerprint identification (RFFI) is an emerging technique that exploits intrinsic and unique hardware impairments as the device identifier. The existing RFFI literature focuses on experimental exploration but comprehensive modelling is missing. This paper systematically models impairments of transmitter and receiver in narrowband systems and carries out extensive experiments and simulations to evaluate their effects on RFFI. The modelled impairments include oscillator imperfections, imbalance of inphase (I) and quadrature (Q) branches of mixers and power amplifier (PA) nonlinearity. We then propose a convolutional neural network-based RFFI protocol. We carry out experimental measurements over three months and demonstrate that oscillator imperfections are not suitable for RFFI due to their unpredictable time variation caused by temperature change. Our simulation results show that our protocol can classify 50 and 200 devices with uniformly and randomly distributed IQ imbalances and PA nonlinearities with high accuracy, namely 99% and 89%, respectively. We also show that the RFFI has some tolerance on different receiver imbalances during training and classification. Specifically, the accuracy is shown to degrade less than 20% when the residual receiver's gain and phase imbalances are small. Based on the experimental and simulation results, we made recommendations for designing a robust RFFI protocol, namely compensate carrier frequency offset and calibrate IQ imbalances of receivers. Junqing Zhang, Roger F. Woods, Magnus Sandell, Mikko Valkama, Alan Marshall 0001, Joseph R. Cavallaro |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Beam-Domain Secret Key Generation for Multi-User Massive MIMO NetworksabstractPhysical-layer key generation (PKG) in multi-user massive MIMO networks faces great challenges due to the large length of pilots and the high dimension of channel matrix. To tackle these problems, we propose a novel massive MIMO key generation scheme with pilot reuse based on the beam domain channel model and derive close-form expression of secret key rate. Specifically, we present two algorithms, i.e., beam-domain based channel probing (BCP) algorithm and interference neutralization based multi-user beam allocation (IMBA) algorithm for the purpose of channel dimension reduction and multi-user pilot reuse, respectively. Numerical results verify that the proposed PKG scheme can achieve the secret key rate that approximates the perfect case, and significantly reduce the dimension of the channel estimation and pilot overhead. You Chen 0004, Guyue Li, Chen Sun 0004, Junqing Zhang, Eduard A. Jorswieck, Bin Xiao 0001 |
ICC | 4 |
| 2020 | Experimental Investigation on Wireless Key Generation for Low-Power Wide-Area NetworksabstractThe wireless key generation is a potential way to implement information-theoretically secure key refreshment for the Internet of Things devices. The state-of-the-art work on key generation mainly utilizes the wireless local area network technologies. However, they have not sufficiently considered the typical characteristics of low-power wide-area network (LPWAN), such as lengthy payloads, duty-cycled transmission and reception, or limitations for channel utilization. In this article, we carry out a comprehensive experimental investigation on key generation applied with LPWAN, taking LoRa/LoRaWAN as case studies. A key generation protocol optimized for typical LPWAN applications is proposed. According to the extensive evaluations with deep in-building and long distance (up to 7 km) outdoor LoRaWAN links, extraction of keys with high randomness becomes feasible. Moreover, we study the achievable AES128 key refreshment periods for different eavesdropper key disagreement rates (KDRs). As indicated by our measurement-based evaluations, the AES128 key can be renewed every 3 h with the proposed key generation protocol and with the maximum LoRaWAN spreading factor setting (longest range). A further interesting evaluation result demonstrates that a secure key refreshment is still possible even when the eavesdropper KDR is very close to the rate of the legitimate users. Henri Ruotsalainen, Junqing Zhang, Stepan Grebeniuk |
IEEE Internet Things J. | 2 |
| 2020 | Design of a Robust Radio-Frequency Fingerprint Identification Scheme for Multimode LFM RadarabstractRadar is an indispensable part of the Internet of Things (IoT). Specific emitter identification is essential to identify the legitimate radars and, more importantly, to reject the malicious radars. Conventional methods rely on pulse parameters that are not capable to identify the specific emitter as two radars may have the same configuration or a malicious radar can perform spoofing attacks. Radio-frequency fingerprint (RFF) is the unique and intrinsic hardware characteristic of devices resulted from hardware imperfection, which can be used as the device identity. This article proposes a robust and reliable radar identification scheme based on the RFF, taking linear frequency modulation (LFM) radar as a case study. This scheme first classifies the operation mode of the pulses, then eliminates the noise effect, and finally identifies the radar emitters based on the transient and modulation-based RFF features. The experimental results verify the effectiveness of our radar identification scheme among three real LFM radars (same model) operating at four modes, each mode with 2000 pulses from each radar. The identification rates of the four modes are all higher than 90% when the signal-to-noise ratio (SNR) is about 5 dB. In addition, mode 3 achieves almost 100% identification accuracy even when the SNR is as low as -10 dB. Yuexiu Xing, Aiqun Hu, Junqing Zhang, Jiabao Yu, Guyue Li, Ting Wang 0029 |
IEEE Internet Things J. | 3 |
| 2019 | 2.5D Multizone Reproduction with Active Control of Scattered Sound FieldsabstractMultizone reproduction has been focused on reproducing sounds in an empty listening space. However, there are always scatterers such as human heads in sound zones, generating scattered sound fields and causing degraded system performance. In this work, we develop a modal-domain method for 2.5D multizone reproduction with a solid object in the bright zone. Analytical expressions of the incident and scattered fields are developed. We then propose an active control strategy to correct the scattering effect. In the reproduction stage, we use the weighted mode matching approach to achieve the optimal control over the entire region. Simulation results show that in comparison with the conventional method which does not consider the scattering effect, the proposed method can achieve higher acoustic contrast performance over a broadband frequency range. Junqing Zhang, Wen Zhang 0002, Thushara D. Abhayapala, Jingli Xie, Lijun Zhang 0004 |
ICASSP | 1 |
| 2019 | Machine Learning Based Attack Against Artificial Noise-Aided Secure CommunicationabstractPhysical layer security (PLS) technologies have attracted much attention in recent years for their potential to provide information-theoretically secure communications. Artificial Noise (AN)-aided transmission is considered as one of the most practicable PLS technologies, as it can realize secure transmission independent of the eavesdropper's channel status. In this paper, we reveal that AN transmission has the dependency of eavesdropper's channel condition by introducing our proposed attack method based on a supervised-learning algorithm which utilizes the modulation scheme, available from known packet preamble and/or header information, as supervisory signals of training data. Numerical simulation results with the comparison to conventional clustering methods show that our proposed method improves the success probability of attack from 4.8% to at most 95.8% for the QPSK modulation. It implies that the transmission to the receiver in the cell-edge with low order modulation will be cracked if the eavesdropper's channel is good enough by employing more antennas than the transmitter. This work brings new insights into the effectiveness of AN schemes and provides useful guidance for the design of robust PLS techniques for practical wireless systems. Yun Wen, Makoto Yoshida, Junqing Zhang, Zheng Chu 0001, Pei Xiao 0001, Rahim Tafazolli |
ICC | 3 |
| 2019 | Design of a Hybrid RF Fingerprint Extraction and Device Classification SchemeabstractRadio frequency (RF) fingerprint is the inherent hardware characteristics and has been employed to classify and identify wireless devices in many Internet of Things applications. This paper extracts novel RF fingerprint features, designs a hybrid and adaptive classification scheme adjusting to the environment conditions, and carries out extensive experiments to evaluate the performance. In particular, four modulation features, namely differential constellation trace figure, carrier frequency offset, modulation offset and I/Q offset extracted from constellation trace figure, are employed. The feature weights under different channel conditions are calculated at the training stage. These features are combined smartly with the weights selected according to the estimated signal to noise ratio at the classification stage. We construct a testbed using universal software radio peripheral platform as the receiver and 54 ZigBee nodes as the candidate devices to be classified, which are the most ZigBee devices ever tested. Extensive experiments are carried out to evaluate the classification performance under different channel conditions, namely line-of-sight (LOS) and nonline-of-sight scenarios. We then validate the robustness by carrying out the classification process 18 months after the training, which is the longest time gap. We also use a different receiver platform for classification for the first time. The classification error rate is as low as 0.048 in LOS scenario, and 0.1105 even when a different receiver is used for classification 18 months after the training. Our hybrid classification scheme has thus been demonstrated effective in classifying a large amount of ZigBee devices. Linning Peng, Aiqun Hu, Junqing Zhang, Yu Jiang 0020, Jiabao Yu |
IEEE Internet Things J. | 3 |
| 2019 | An Investigation of Using Loop-Back Mechanism for Channel Reciprocity Enhancement in Secret Key GenerationabstractPhysical layer security key generation exploits unpredictable features from wireless channels to achieve high security, which requires high reciprocity in order to set up symmetric keys between two users. This paper investigates enhancing the channel reciprocity using a loop-back scheme with multiple frequency bands in time-division duplex (TDD) communication systems, in order to mitigate the effect of hardware fingerprint interference and synchronization offset. The scheme is evaluated to be robust to passive eavesdropping and active Man-in-the-Middle attack through both theoretical analyses and practical measurements. A secret key generation protocol is subsequently designed. The performance of the proposed secret key generation method is then evaluated through both numerical simulation and experiments. Results demonstrate that the proposed scheme can effectively mitigate non-reciprocity and outperforms the classical TDD scheme in both key disagreement rate and key generation rate. Linning Peng, Guyue Li, Junqing Zhang, Roger F. Woods, Ming Liu 0010, Aiqun Hu |
IEEE Trans. Mob. Comput. | 3 |
| 2018 | 2.5D Multizone Reproduction Using Weighted Mode MatchingabstractThe mode matching based multizone reproduction has mainly been focused on a purely 2D theory which is inadequate to fit the 3D reality. Its extension to the 3D theory however requires many secondary sources and a high computational complexity. In this paper, a weighted mode matching approach is developed for 2.5D multizone reproduction. The multizone soundfield is reproduced in the horizontal plane within a circular control region using the loudspeakers modelled as 3D point sources. We propose weighting the Bessel-spherical harmonic modes for 2.5D reproduction and a matching between the desired and reproduced soundfields over the entire control region. Simulation results show that in comparison with the conventional 2.5D reproduction method a more accurate reproduction is achieved using the proposed weighting approach. Wen Zhang 0002, Junqing Zhang, Thushara D. Abhayapala, Lijun Zhang 0004 |
ICASSP | 2 |
| 2018 | High-Agreement Uncorrelated Secret Key Generation Based on Principal Component Analysis PreprocessingabstractRandom and high-agreement secret key generation from noisy wideband channels is challenging due to the autocorrelation inside the channel samples and compromised cross correlation between channel measurements of two keying parties. This paper studies the signal preprocessing algorithms to establish high-agreement uncorrelated secret key in the presence of channel independent eavesdroppers. We first propose a general mathematical model for various preprocessing schemes, including principal component analysis (PCA), discrete cosine transform (DCT) and wavelet transform (WT). Among preprocessing schemes, PCA is proved to achieve the optimal secret key rate. Next, PCA with common eigenvector has been found to outperform PCA with private eigenvector in terms of an overall consideration of key agreement, information leakage, and computational expense. Then, we propose a system level design of key generation, including quantization, information reconciliation, and privacy amplification. Numerical results verify that the key generation enhanced by PCA with common eigenvector can achieve secret key with high key generation rate, low key error rate, and good randomness. Guyue Li, Aiqun Hu, Junqing Zhang, Linning Peng, Chen Sun 0004, Daming Cao |
IEEE Trans. Commun. | 3 |
| 2018 | Security Optimization of Exposure Region-Based Beamforming With a Uniform Circular ArrayabstractThis paper investigates the impact of a uniform circular array (UCA) in the context of wireless security via exposure region-based beamforming. An improvement is demonstrated for the security metric proposed in our previous paper, namely, the spatial secrecy outage probability (SSOP), by optimizing the configuration of the UCA. Our previous paper focused on formalizing the SSOP concept and exploring its applicability using a uniform linear array example. This paper proposes the UCA as a superior candidate because it is more robust against the effects of mutual coupling. The UCA's SSOP configuration is explored and a special expression is derived from the general expression for the first time, and a closed-form upper bound is then generated to facilitate analysis. By carefully designing the UCA structure particularly the radius, an SSOP optimization algorithm is derived and explored for mutual coupling. It is shown that the information leakage to eavesdroppers is reduced while the legitimate user's received signal quality is enhanced due to the use of beamforming. Roger F. Woods, Youngwook Ko, Alan Marshall 0001, Junqing Zhang |
IEEE Trans. Commun. | 5 |
| 2017 | Security Analysis of a Novel Artificial Randomness Approach for Fast Key GenerationabstractWireless key generation in slow fading channels is challenging because of the limited channel variation and randomness. This paper proposes a novel artificial randomness (AR) assisted approach for fast key generation in slow fading environments. It integrates user-designed randomness into the channel probing to form a fast-changing combined channel to realize information-theory security. The analytical expressions of secret key capacity are derived. We find that it is possible to improve secret key capacity by introducing AR when legitimate users have a better channel condition than that of eavesdropper. We also find that the improved secret key capacity is proportional to the channel probing number and is bounded by the noise variance and channel condition. Simulation and experimental results show that AR approach can generate secret key effectively in slow fading environments by carefully designing probing numbers. Compared to existing work in literature, the proposed approach does not rely on multiple antennas or extra helpers, and it can be applied in both single antenna and multi-antenna systems. Guyue Li, Aiqun Hu, Junqing Zhang, Bin Xiao 0001 |
GLOBECOM | 3 |
| 2017 | Retrodirective-Assisted Secure Wireless Key EstablishmentabstractIn this paper, a new type of architecture for secure wireless key establishment is proposed. A retrodirective array (RDA) that is configured to receive and re-transmit at different frequencies is utilized as a relay node. The RDA is able to respond in “real time,” reducing the required number of time slots to two. More importantly, in this architecture, equivalent reciprocal wireless channels between legitimate keying nodes can be randomly updated within one channel coherence time period, leading to greatly increased key generation rates in slow fading environment. The secrecy performance of this RDA-assisted key generation system is evaluated under several eavesdropping strategies and it is shown that it outperforms previous relay key generation systems. Yuan Ding 0001, Junqing Zhang, Vincent F. Fusco |
IEEE Trans. Commun. | 2 |
| 2016 | Green two-tiered wireless multimedia sensor systems: an energy, bandwidth, and quality optimisation frameworkabstractIn wireless multimedia sensor systems (WMSSs), the devices are equipped with multiple energy‐constrained camera sensors (CSs) distributed over bandwidth‐constrained and lossy wireless channels, in catastrophe‐prone areas. Meanwhile, multimedia applications, e.g. video streaming, require considerable energy and bandwidth resources to gain long lifetime and high streaming quality. This study proposes an energy, bandwidth, and quality (EBQ) optimisation framework for green two‐tiered WMSSs. The first tier contains the CSs and the second tier includes cluster heads (CHs) selected from the CSs with higher available energy and processing capacity. In the EBQ optimisation framework, a rate allocation optimisation problem is formulated under given constraints of available backhaul bandwidth of the CHs and quality of received videos at base stations (BSs). This problem is solved for optimal encoding rates to packetise each video captured from different environments into multiple descriptions for transmission. Consequently, the average energy consumption per CS is minimised for long lifetime while conserving the bandwidth of the CHs and guaranteeing high quality of received videos for the purpose of monitoring at the BSs. Simulations demonstrate that the proposed EBQ optimisation framework can efficiently enhance the performance of green two‐tiered WMSSs in terms of minimum energy consumption, bandwidth efficiency, and high quality. Nguyen-Son Vo, Dac-Binh Ha, Berk Canberk, Junqing Zhang |
IET Commun. | 4 |
| 2016 | Impact of primary networks on the performance of energy harvesting cognitive radio networksabstractIn this paper, we investigate the effect of of the primary network on the secondary network when harvesting energy in cognitive radio in the presence of multiple power beacons and multiple secondary transmitters. In particular, the influence of the primary transmitter's transmit power on the energy harvesting secondary network is examined by studying two scenarios of primary transmitter's location, i.e., the primary transmitter's location is near to the secondary network and the primary transmitter's location is far from the secondary network. In the scenario where the primary transmitter locates near to the secondary network, although secondary transmitter can be benefit from the harvested energy from the primary transmitter, the interference caused by the primary transmitter suppresses the secondary network performance. Meanwhile, in both scenarios, despite the fact that the transmit power of the secondary transmitter can be improved by the support of powerful power beacons, the peak interference constraint at the primary receiver limits this advantage. In addition, the deployment of multiple power beacons and multiple secondary transmitters can improve the performance of the secondary network. The analytical expressions of the outage probability of the secondary network in the two scenarios are also provided and verified by numerical simulations. Nam-Phong Nguyen, Junqing Zhang, Emi Garcia-Palacios, Ngoc Phuc Le |
IET Commun. | 3 |
| 2016 | Efficient Key Generation by Exploiting Randomness From Channel Responses of Individual OFDM SubcarriersabstractKey generation from the randomness of wireless channels is a promising technique to establish a secret cryptographic key securely between legitimate users. This paper proposes a new approach to extract keys efficiently from the channel responses of individual orthogonal frequency-division multiplexing (OFDM) subcarriers. The efficiency is achieved by: 1) fully exploiting randomness from time and frequency domains and 2) improving the cross-correlation of the channel measurements. Through the theoretical modeling of the time and frequency autocorrelation relationship of the OFDM subcarrier's channel responses, we can obtain the optimal probing rate and use multiple uncorrelated subcarriers as random sources. We also study the effects of non-simultaneous measurements and noise on the cross-correlation of the channel measurements. We find that the cross-correlation is mainly impacted by noise effects in a slow fading channel and use a low-pass filter to reduce the key disagreement rate and extend the system's working signal-to-noise ratio range. The system is evaluated in terms of randomness, key generation rate, and key disagreement rate, verifying that it is feasible to extract randomness from both time and frequency domains of the OFDM subcarrier's channel responses. Junqing Zhang, Alan Marshall 0001, Roger F. Woods, Trung Quang Duong |
IEEE Trans. Commun. | 1 |
| 2015 | An effective key generation system using improved channel reciprocityabstractIn physical layer security systems there is a clear need to exploit the radio link characteristics to automatically generate an encryption key between two end points. The success of the key generation depends on the channel reciprocity, which is impacted by the non-simultaneous measurements and the white nature of the noise. In this paper, an OFDM subcarriers' channel responses based key generation system with enhanced channel reciprocity is proposed. By theoretically modelling the OFDM subcarriers' channel responses, the channel reciprocity is modelled and analyzed. A low pass filter is accordingly designed to improve the channel reciprocity by suppressing the noise. This feature is essential in low SNR environments in order to reduce the risk of the failure of the information reconciliation phase during key generation. The simulation results show that the low pass filter improves the channel reciprocity, decreases the key disagreement, and effectively increases the success of the key generation. Junqing Zhang, Roger F. Woods, Alan Marshall 0001, Trung Quang Duong |
ICASSP | 1 |