Richard Baker 0008

dblp:13/4585-8 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-8215-1053ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 7 since 2021
YearPublicationVenuePosition
2026 Finding Phones Fast: Low-Latency and Scalable Monitoring of Cellular Communications in Sensitive Areas
abstract
The widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. These threats can arise from user non-compliance or deliberate actions aimed at data exfiltration/infiltration via hidden devices, drones, etc. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision (e.g., geofencing or localization), and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency, operator-independent, and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink receivers and a distributed network of uplink receivers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection before the UE completes connection establishment. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any
Martin Kotuliak, Simon Erni, Jakub Polák, Marc Röschlin, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun
WISEC5
2025 GLaDoS: Location-aware Denial-of-Service of Cellular Networks
Simon Erni, Martin Kotuliak, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun
USENIX Security Symposium3
2023 Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic
NDSS2
2022 Signal Injection Attacks against CCD Image Sensors
abstract
Since cameras have become a crucial part in many safety-critical systems and applications, such as autonomous vehicles and surveillance, a large body of academic and non-academic work has shown attacks against their main component --- the image sensor. However, these attacks are limited to coarse-grained and often suspicious injections because light is used as an attack vector. Furthermore, due to the nature of optical attacks, they require the line-of-sight between the adversary and the target camera.
Sebastian Köhler 0005, Richard Baker 0008, Ivan Martinovic
AsiaCCS2
2022 Demo: End-to-End Wireless Disruption of CCS EV Charging
abstract
The shift from vehicles with internal combustion engines (ICE) to fully Electric Vehicles (EVs) is happening at a rapid pace. To be competitive with ICEs and ensure a smooth rollout, the charging process of EVs needs to be as fast and convenient as possible. Modern DC fast-charging standards achieve this by implementing a high-level charging communication (HLC), which enables a safe, efficient, and convenient charging experience.
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic
CCS2
2021 They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image Sensors
abstract
In this paper, we describe how the electronic rolling shutter in CMOS image sensors can be exploited using a bright, modulated light source (e.g., an inexpensive, off-the-shelf laser), to inject fine-grained image disruptions. We demonstrate the attack on seven different CMOS cameras, ranging from cheap IoT to semi-professional surveillance cameras, to highlight the wide applicability of the rolling shutter attack. We model the fundamental factors affecting a rolling shutter attack in an uncontrolled setting. We then perform an exhaustive evaluation of the attack’s effect on the task of object detection, investigating the effect of attack parameters. We validate our model against empirical data collected on two separate cameras, showing that by simply using information from the camera’s datasheet the adversary can accurately predict the injected distortion size and optimize their attack accordingly. We find that an adversary can hide up to 75% of objects perceived by state-of-the-art detectors by selecting appropriate attack parameters. We also investigate the stealthiness of the attack in comparison to a naïve camera blinding attack, showing that common image distortion metrics can not detect the attack presence. Therefore, we present a new, accurate and lightweight enhancement to the backbone network of an object detector to recognize rolling shutter attacks. Overall, our results indicate that rolling shutter attacks can substantially reduce the performance and reliability of vision-based intelligent systems.
Sebastian Köhler 0005, Giulio Lovisotto, Simon Birnbach, Richard Baker 0008, Ivan Martinovic
ACSAC4
2021 #PrettyFlyForAWiFi: Real-world Detection of Privacy Invasion Attacks by Drones
abstract
Drones are becoming increasingly popular for hobbyists and recreational use. But with this surge in popularity comes increased risk to privacy as the technology makes it easy to spy on people in otherwise-private environments, such as an individual’s home. An attacker can fly a drone over fences and walls to observe the inside of a house, without having physical access. Existing drone detection systems require specialist hardware and expensive deployment efforts, making them inaccessible to the general public. In this work, we present a drone detection system that requires minimal prior configuration and uses inexpensive commercial off-the-shelf hardware to detect drones that are carrying out privacy invasion attacks. We use a model of the attack structure to derive statistical metrics for movement and proximity that are then applied to received communications between a drone and its controller. We test our system in real-world experiments with two popular consumer drone models mounting privacy invasion attacks using a range of flight patterns. We are able both to detect the presence of a drone and to identify which phase of the privacy attack was in progress while being resistant to false positives from other mobile transmitters. For line-of-sight approaches using our kurtosis-based method, we are able to detect all drones at a distance of 6 m, with the majority of approaches detected at 25 m or farther from the target window without suffering false positives for stationary or mobile non-drone transmitters.
Simon Birnbach, Richard Baker 0008, Simon Eberz, Ivan Martinovic
ACM Trans. Priv. Secur.2
2019 Losing the Car Keys: Wireless PHY-Layer Insecurity in EV Charging
Richard Baker 0008, Ivan Martinovic
USENIX Security Symposium1
2018 EMPower: Detecting Malicious Power Line Networks from EM Emissions
Richard Baker 0008, Ivan Martinovic
SEC1
2017 Wi-Fly?: Detecting Privacy Invasion Attacks by Consumer Drones
Simon Birnbach, Richard Baker 0008, Ivan Martinovic
NDSS2