VLDB 2026 Research / reviewers in the wild / expert
Tianbo Gu
dblp:124/2677
· DBLP profile ↗
17ranked-venue papers
5as first author
6since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 4 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | IoT-Enabled Supply Chain Management From a Customer Perspective: Challenges and OpportunitiesabstractSupply chain management (SCM), a critical factor in enhancing companies’ efficiency and competitiveness, has received significant attention from both industry and academia. Beyond the flow of products from supplier to customer, SCM also involves the flow of information necessary to monitor, track, and optimize the entire product lifecycle. Consequently, integrating the information flow in SCM with the Internet of Things (IoT) is imperative, as IoT provides the ability to onboard, interconnect, interact with, and sense products. However, IoT-enabled SCM also presents unique challenges, such as managing large volumes of data, ensuring credible and traceable data sources, and achieving low-cost, seamless connectivity. In this article, we systematically present recent advances in leveraging IoT to build robust and effective SCM systems. Unlike existing surveys and overviews, this article focuses on the customer side as customers are the destination of the information flow and tightly coupled with IoT networks. We offer deep insights into the principles, challenges, and research opportunities in IoT-enabled SCM, aiming to assist IoT practitioners in understanding and designing IoT solutions for SCM. Runyu Pan, Tianbo Gu, Xiuzhen Cheng, Huanle Zhang |
IEEE Internet Things J. | 3 |
| 2024 | Towards System-Level Security Analysis of IoT Using Attack GraphsabstractMost IoT systems involve IoT devices, communication protocols, remote cloud, IoT applications, mobile apps, and the physical environment. However, existing IoT security analyses only focus on a subset of all the essential components, such as device firmware or communication protocols, and ignore IoT systems' interactive nature, resulting in limited attack detection capabilities. In this work, we proposeIota, a logic programming-based framework to perform system-level security analysis for IoT systems.Iotagenerates attack graphs for IoT systems, showing all of the system resources that can be compromised and enumerating potential attack traces. In buildingIota, we design novel techniques to scan IoT systems for individual vulnerabilities and further create generic exploit models for IoT vulnerabilities. We also identify and model physical dependencies between different devices as they are unique to IoT systems and are employed by adversaries to launch complicated attacks. In addition, we utilize NLP techniques to extract IoT app semantics based on app descriptions.Iotaautomatically translates vulnerabilities, exploits, and device dependencies to Prolog clauses and invokes MulVAL to construct attack graphs. To evaluate vulnerabilities' system-wide impact, we propose three metrics based on the attack graph, which provide guidance on hardening IoT systems. Evaluation on 127 IoT CVEs (Common Vulnerabilities and Exposures) shows thatIota's exploit modeling module achieves over 80% accuracy in predicting vulnerabilities' preconditions and effects. We applyIotato 37 synthetic smart home IoT systems based on real-world IoT apps and devices. Experimental results show that our framework is effective and highly efficient. Among 27 shortest attack traces revealed by the attack graphs, 62.8% are not anticipated by the system administrator. It only takes 1.2 seconds to generate and analyze the attack graph for an IoT system consisting of 50 devices. Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Pengfei Hu 0001, Jinyue Song, Trent Jaeger, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | How BlockChain Can Help Enhance The Security And Privacy in Edge Computing?
Jinyue Song, Tianbo Gu, Prasant Mohapatra |
SEC | 2 |
| 2021 | Blockchain Meets COVID-19: A Framework for Contact Information Sharing and Risk Notification SystemabstractCOVID-19 is a severe global epidemic in human history. Even though there are particular medications and vaccines to curb the epidemic, tracing and isolating the infection source is the best option to slow the virus spread and reduce infection and death rates. There are three disadvantages to the existing contact tracing system: 1. User data is stored in a centralized database that could be stolen and tampered with, 2. User’s confidential personal identity may be revealed to a third party or organization, 3. Existing contact tracing systems [1][2] only focus on information sharing from one dimension, such as location-based tracing, which significantly limits the effectiveness of such systems.We propose a global COVID-19 information sharing and risk notification system that utilizes the Blockchain, Smart Contract, and Bluetooth. To protect user privacy, we design a novel Blockchain-based platform that can share consistent and non-tampered contact tracing information from multiple dimensions, such as location-based for indirect contact and Bluetooth-based for direct contact. Hierarchical smart contract architecture is also designed to achieve global agreements from users about how to process and utilize user data, thereby enhancing the data usage transparency. Furthermore, we propose a mechanism to protect user identity privacy from multiple aspects. More importantly, our system can notify the users about the exposure risk via smart contracts. We implement a prototype system to conduct extensive measurements to demonstrate the feasibility and effectiveness of our system. Jinyue Song, Tianbo Gu, Zheng Fang 0009, Xiaotao Feng, Yunjie Ge, Hao Fu 0003, Pengfei Hu 0001, Prasant Mohapatra |
MASS | 2 |
| 2021 | A model checking-based security analysis framework for IoT systemsabstractIoT systems are revolutionizing our life by providing ubiquitous computing, inter-connectivity, and automated control. However, the increasing system complexity poses huge challenges for security as IoT devices are distributed, highly heterogeneous, and can directly interact with the physical environment. In IoT systems, bugs in device firmware, defects in network protocols, and design flaws in automation rules can lead to system breach or failure. The challenge gets even more escalated as the possible attacks may be chained together in a long sequence across multiple layers, rendering the existing vulnerability analysis frameworks inapplicable. In this paper, we present ForeSee, a model checking-based framework to comprehensively evaluate IoT system security. It builds a multi-layer IoT hypothesis graph by simultaneously modeling all of the essential components in IoT systems, including the physical environment, devices, communication protocols, and applications. The model checker can then analyze the generated hypothesis graph to validate system security properties or generate attack paths if there are any violations. An optimization algorithm is further introduced to reduce the computational complexity of our analysis. Our framework verifies hypothesis graphs with millions of nodes in less than 100 seconds. The illustrative case studies show that our framework can detect more potential threats than the existing approaches. Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Zhiyun Qian, Trent Jaeger, Pengfei Hu 0001, Prasant Mohapatra |
High Confid. Comput. | 3 |
| 2021 | Towards Automatic Detection of Nonfunctional Sensitive Transmissions in Mobile ApplicationsabstractWhile mobile apps often need to transmit sensitive information out to support various functionalities, they may also abuse the privilege by leaking the data to unauthorized third parties. This makes us question: Is the given transmission required to fulfill the app functionality? In this paper, we make the first attempt to automatically identify suspicious transmissions from app visual interfaces, including app names, descriptions, and user interfaces. We design and implement a novel framework called FlowIntent to detect nonfunctional transmissions at both software and network levels. During the exercising of the given apps, FlowIntent automatically detects privacy-sharing transmissions and determines their purposes by utilizing the fact that mobile users rely on visible app interface to perceive the functionality of the app at certain context. The characterizations of nonfunctional network traffic are then summarized to provide network level protection. FlowIntent not only reduces the false alarms caused by traditional taint analysis, but also captures the sensitive transmissions missed by widely-used taint analysis system TaintDroid. Evaluation using 2125 sharing flows collected from more than a thousand running instances shows that our approach achieves about 94 percent accuracy in detecting nonfunctional transmissions. Hao Fu 0003, Pengfei Hu 0001, Zizhan Zheng, Aveek K. Das, Parth H. Pathak, Tianbo Gu, Sencun Zhu, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 6 |
| 2020 | IoTGaze: IoT Security Enforcement via Wireless Context AnalysisabstractInternet of Things (IoT) has become the most promising technology for service automation, monitoring, and interconnection, etc. However, the security and privacy issues caused by IoT arouse concerns. Recent research focuses on addressing security issues by looking inside platform and apps. In this work, we creatively change the angle to consider security problems from a wireless context perspective. We propose a novel framework called IoTGaze, which can discover potential anomalies and vulnerabilities in the IoT system via wireless traffic analysis. By sniffing the encrypted wireless traffic, IoTGaze can automatically identify the sequential interaction of events between apps and devices. We discover the temporal event dependencies and generate the Wireless Context for the IoT system. Meanwhile, we extract the IoT Context, which reflects user's expectation, from IoT apps' descriptions and user interfaces. If the wireless context does not match the expected IoT context, IoTGaze reports an anomaly. Furthermore, IoTGaze can discover the vulnerabilities caused by the inter-app interaction via hidden channels, such as temperature and illuminance. We provide a proof-of-concept implementation and evaluation of our framework on the Samsung SmartThings platform. The evaluation shows that IoTGaze can effectively discover anomalies and vulnerabilities, thereby greatly enhancing the security of IoT systems. Tianbo Gu, Zheng Fang 0009, Allaukik Abhishek, Hao Fu 0003, Pengfei Hu 0001, Prasant Mohapatra |
INFOCOM | 1 |
| 2020 | IoTSpy: Uncovering Human Privacy Leakage in IoT Networks via Mining Wireless ContextabstractInternet of Things (IoT) has been emerging as one of the most significant technologies that may change the world. The development and deployment of IoT systems significantly improve the efficiency of work, advance the development of productive force, and affect the human society's modes of production, working, and life deeply. The number of deployed IoT devices and applications has had explosive growth in the past years. While people enjoy the benefits brought by IoT, the addressing of its security and privacy issues does not keep pace with the development of IoT technologies. We find that encrypted wireless IoT traffic can still leak information about user privacy. We can infer what the user is doing at home by deploying a wireless sniffer outside the user's house. In this paper, we propose a method to eavesdrop different kinds of user privacy via analyzing the wireless context. First, we extract the packet sequence features to fingerprint and detect the IoT events. Then we analyze the detected IoT events and infer the user's activities and even the user's moods. Furthermore, by analyzing the wireless context, which is discovered by mining the IoT event dependencies, we can infer the user's living habits, routines, and even installed IoT applications. The leakage of such information not only exposes the user's privacy but also extends the attack surface that an attacker can utilize to control the smart home. We implement our eavesdropping approach and conduct extensive experiments on the SmartThings platform. The evaluation demonstrates the feasibility and effectiveness of our eavesdropping approach. Tianbo Gu, Zheng Fang 0009, Allaukik Abhishek, Prasant Mohapatra |
PIMRC | 1 |
| 2020 | Smart Contract-based Computing Resources Trading in Edge ComputingabstractIn recent years, there is an emerging trend that some computing services are moving from cloud to the edge of the networks. Compared to cloud computing, edge computing can provide services with faster response, lower expense, and more security. The massive idle computing resources closing to the edge also enhance the deployment of edge services. Instead of using cloud services from some primary providers, edge computing provides people a great chance to join the market of computing resources actively. However, edge computing also has some critical impediments that we have to overcome.In this paper, we design an edge computing service platform that can receive and distribute the computing resources from the end-users in a decentralized way. Without the centralized trade control, we propose a novel Blockchain-enabled decentralized technique to establish the trade trust among users and implement it with using embedded immutable intermediary smart contract. Our system also considers and resolves a variety of security and privacy challenges when utilizing the Blockchain technique. We implement our system and conduct extensive experiments to show the feasibility and effectiveness of our proposed system. Jinyue Song, Tianbo Gu, Yunjie Ge, Prasant Mohapatra |
PIMRC | 2 |
| 2020 | Towards Learning-automation IoT Attack Detection through Reinforcement LearningabstractAs a massive number of the Internet of Things (IoT) devices are deployed, the security and privacy issues in IoT arouse more and more attention. The IoT attacks are causing tremendous loss to the IoT networks and even threatening human safety. Compared to traditional networks, IoT networks have unique characteristics, which make the attack detection more challenging. First, the heterogeneity of platforms, protocols, software, and hardware exposes various vulnerabilities. Second, in addition to the traditional high-rate attacks, the low-rate attacks are also extensively used by IoT attackers to obfuscate the legitimate and malicious traffic. These low-rate attacks are challenging to detect and can persist in the networks. Last, the attackers are evolving to be more intelligent and can dynamically change their attack strategies based on the environment feedback to avoid being detected, making it more challenging for the defender to discover a consistent pattern to identify the attack. In order to adapt to the new characteristics in IoT attacks, we propose a reinforcement learning-based attack detection model that can automatically learn and recognize the transformation of the attack pattern. Therefore, we can continuously detect IoT attacks with less human intervention. In this paper, we explore the crucial features of IoT traffics and utilize the entropy-based metrics to detect both the high-rate and low-rate IoT attacks. Afterward, we leverage the reinforcement learning technique to continuously adjust the attack detection threshold based on the detection feedback, which optimizes the detection and the false alarm rate. We conduct extensive experiments over a real IoT attack data set and demonstrate the effectiveness of our IoT attack detection framework. Tianbo Gu, Allaukik Abhishek, Hao Fu 0003, Huanle Zhang, Debraj Basu 0002, Prasant Mohapatra |
WoWMoM | 1 |
| 2019 | ForeSee: A Cross-Layer Vulnerability Detection Framework for the Internet of ThingsabstractThe exponential growth of Internet-of-Things (IoT) devices not only brings convenience but also poses numerous challenging safety and security issues. IoT devices are distributed, highly heterogeneous, and more importantly, directly interact with the physical environment. In IoT systems, the bugs in device firmware, the defects in network protocols, and the design flaws in system configurations all may lead to catastrophic accidents, causing severe threats to people's lives and properties. The challenge gets even more escalated as the possible attacks may be chained together in a long sequence across multiple layers, rendering the current vulnerability analysis inapplicable. In this paper, we present ForeSee, a cross-layer formal framework to comprehensively unveil the vulnerabilities in IoT systems. ForeSee generates a novel attack graph that depicts all of the essential components in IoT, from low-level physical surroundings to high-level decision-making processes. The corresponding graph-based analysis then enables ForeSee to precisely capture potential attack paths. An optimization algorithm is further introduced to reduce the computational complexity of our analysis. The illustrative case studies show that our multilayer modeling can capture threats ignored by the previous approaches. Zheng Fang 0009, Hao Fu 0003, Tianbo Gu, Zhiyun Qian, Trent Jaeger, Prasant Mohapatra |
MASS | 3 |
| 2019 | BeamSniff: Enabling Seamless Communication under Mobility and Blockage in 60 GHz NetworksabstractRecently, millimeter-wave (mmWave) is augmenting popularity in wireless communications since it provides multi-Gbps throughput by exploiting the broad unlicensed 60 GHz spectrum. Highly directional adaptive beamforming antennas are inherently employed in 60GHz to counteract the severe propagation and penetration losses experienced in this spectrum. Compared to traditional omnidirectional antennas, beamforming introduces critical challenges in medium access control, especially in link establishment and maintenance. In particular, node mobility and object blockage become crucial, which necessitates frequent beam steering to re-establish links. The state-of-the-art protocols fail to jointly address both the mobility and blockage challenges. Their approaches trigger exhaustive beam search to pair antenna sectors on every link failure which produces an excessive delay that conceivably disrupts communication and lowers the quality-of-service(QoS). In this paper, we propose BeamSniff, a novel protocol that resolves the mobility and blockage issues jointly while sustaining a seamless communication. Upon link failure, it intelligently estimates the possible cause of link failure and instantly foresees plausible paths to recover the broken link, thereby eliminating the frequent exhaustive beam search which results in reducing the overhead for link maintenance. BeamSniff is assessed extensively in our custom-built 60GHz system platform with a ray-tracing based simulator under various indoor environments. The evaluation manifests the efficiency of the protocol in sustaining seamless communication along with multi-fold throughput gain compared to state-of-the-art protocols. We observe up to 14× throughput increase in typical scenarios involving motion and blockage. Tianbo Gu, Debraj Basu 0002, Prasant Mohapatra |
Networking | 1 |
| 2018 | BF-IoT: Securing the IoT Networks via Fingerprinting-Based Device AuthenticationabstractBluetooth low energy (BLE) based devices are already deployed in massive quantity as Internet-of-things (IoT) becomes prominent in the last two decades. In order to lower the energy consumption, BLE devices have to compromise with security and privacy problems. Existing research work shows that BLE devices can be easily spoofed and leveraged to gain access to a networking system. In this paper, we propose BF-IoT, the first IoT secure communication framework for BLE-based networks that guards against device spoofing via monitoring the work-life cycles of devices. We dig into the BLE protocol stack and extract the unique network-flow features from the link layer and ATT/GATT service layer so as to generate the fingerprints for device authentication. BF-IoT provides two-phase defense against malicious entities: continuously authenticating device identity before the connection setup and during session establishment. We build a customized system to validate the effectiveness of our mechanism. We extensively evaluate BF-IoT with a dozen of different off-the-shelf commodity IoT devices which shows that the devices can be accurately authenticated via only sniffing the transmission characteristics. Tianbo Gu, Prasant Mohapatra |
MASS | 1 |
| 2015 | Planning Battery Swapping Stations for Urban Electrical TaxisabstractDespite the clear benefits of electric vehicles (EVs) in terms of reducing greenhouse gas emissions and traditional energy consumptions, the popularization of EVs remains a challenge in the short run. When considering electric taxis, urban planners must face the additional issue of providing battery swapping services. While previous studies focused on planning battery swapping stations for private EVs, we investigate ways of supporting the upgrade of an entire urban taxi system, with demands differing both in scale and nature. With this insight, we analyze the historical sensing data of taxi routes, and evaluate the battery swapping demand profile, as well as the driving time between positions in the road network. Based on these inputs, we propose a method to calculate an optimized battery swapping station scheme. Our strategies are then evaluated via a real world 366-day, 3,976-taxi dataset. The results show that compared to uniform deployment, our planning scheme reduces the average time-cost by 67.2%. Yang Wang 0015, Liusheng Huang, Wei Zheng 0011, Tianbo Gu, Hengchang Liu |
ICDCS | 5 |
| 2014 | Data-driven traffic flow analysis for vehicular communicationsabstractDue to high mobility and frequent disconnections in a vehicular network, reliable and efficient vehicular communication is very challenging. Previous studies focus on predicting the trajectories of single vehicles. Due to many random factors, however, there is little regularity in the movements of a single vehicle in an urban area, and this motivates us to take a holistic network perspective. With this insight, we model the time varying regularities of road traffic flows in road segments and intersections by mining statistic trajectories of all vehicles in the network. Based on these regularities and local real-time traffic information, we propose a new method to calculate the expected transfer delay from a current position to a given destination. We also propose a method to collect updated destination information. By combining the above two methods, we design a routing algorithm for vehicle-to-vehicle data transmission in vehicular networks, and then prove that it is a linear-time algorithm. Finally, we evaluate our algorithm by using information of real taxi vehicles. The results show that the performance of our algorithm is significantly better than other solutions in terms of packet delay. Yang Wang 0015, Liusheng Huang, Tianbo Gu, Junshan Zhang |
INFOCOM | 3 |
| 2013 | Approaching reliable realtime communications? A novel system design and implementation for roadway safety oriented vehicular communicationsabstractThough there exist ready-made DSRC/WiFi/3G/4G cellular systems for roadway communications, there are common defects in these systems for roadway safety oriented applications and the corresponding challenges remain unsolved for years, i.e., WiFi cannot work well in vehicular networks due to the high probability of packet loss caused by burst communications, which is a common phenomenon in roadway networks; 3G/4G cannot well support real-time communications due to the nature of their designs; DSRC lacks the support to roadway safety oriented applications with hard realtime and reliability requirements [1]. To solve the conflict between the capability limitations of existing systems and the ever-growing demands of roadway safety oriented communication applications, we propose a novel system design and implementation for realtime reliable roadway communications, aiming at providing safety messages to users in a realtime and reliable manner. In our extensive experimental study, the latency is well controlled within the hard realtime requirement (100ms) for roadway safety applications given by NHTSA [2], and the reliability is proved to be improved by two orders of magnitude compared with existing experimental results [1]. Our experiments show that the proposed system for roadway safety communications can provide guaranteed highly reliable packet delivery ratio (PDR) of 99% within the hard realtime requirement 100ms under various scenarios, e.g., highways, city areas, rural areas, tunnels, bridges. Our design can be widely applied for roadway communications and facilitate the current research in both hardware and software design and further provide an opportunity to consolidate the existing work on a practical and easy-configurable low-cost roadway communication platform. Tianbo Gu, Lei Shi 0011, Yunhao Liu 0001, Pengfei Hu 0001, Yuepeng Wang 0001, Shuo Zhang 0011, Yang Wang 0015, Liusheng Huang |
INFOCOM | 2 |
| 2012 | A novel system design and implementation for realtime sensing and warning of roadway hazards round-the-clockabstractThough there exist ready-made DSRC/WiFi/3G/4G cellular systems for roadway communications, there are common defects in these systems for roadway safety oriented applications and the corresponding challenges remain unsolved for years, i.e., WiFi cannot work well in vehicular networks due to the high probability of packet loss caused by burst communications, which is a common phenomenon in roadway networks; 3G/4G cannot well support real-time communications due to the nature of their designs; DSRC lacks the support to roadway safety oriented applications with hard real-time and reliability requirements in the most recent study [1]. Tianbo Gu, Yang Wang 0015, Bowu Zhang, Liusheng Huang |
SenSys | 2 |