VLDB 2026 Research / reviewers in the wild / expert
Song Fang 0001
dblp:150/3139-1
· DBLP profile ↗
22ranked-venue papers
7as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 8 since 2021Computer networks · 9 · 4 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PhantomMotion: Laser-Based Motion Injection Attacks on Wireless Security Surveillance Systems
Guanchong Huang, Song Fang 0001 |
NDSS | 3 |
| 2026 | SilhouetteTell: Practical Video Identification Leveraging Blurred Recordings of Video SubtitlesabstractVideo identification attacks pose a significant privacy threat that can reveal videos that victims watch, which may disclose their hobbies, religious beliefs, political leanings, sexual orientation, and health status. Also, video watching history can be used for user profiling or advertising and may result in cyberbullying, discrimination, or blackmail. Existing extensive video inference techniques usually depend on analyzing network traffic generated by streaming online videos. In this work, we observe that the content of a subtitle determines its silhouette displayed on the screen, and identifying each subtitle silhouette also derives the temporal difference between two consecutive subtitles. We then propose SilhouetteTell, a novel video identification attack that combines the spatial and time domain information into a spatiotemporal feature of subtitle silhouettes. SilhouetteTell explores the spatiotemporal correlation between recorded subtitle silhouettes of a video and its subtitle file. It can infer both online and offline videos. Comprehensive experiments on off-the-shelf smartphones confirm the high efficacy of SilhouetteTell for inferring video titles and clips under various settings, including from a distance of up to 40 meters. Guanchong Huang, Song Fang 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | MotionDecipher: General Video-assisted Passcode Inference In Virtual Reality
Guanchong Huang, Shangqing Zhao, Song Fang 0001 |
RAID | 5 |
| 2024 | Precise Wireless Camera Localization Leveraging Traffic-Aided Spatial AnalysisabstractWireless cameras nowadays commonly employ motion sensors to identify that something is occurring in their fields of vision before starting to record and notifying the property owner of the activity. In this paper, we discover that the motion sensing action can disclose the location of the camera through a novel wireless camera localization technique we call MotionCompass. By creating motion stimuli and sniffing wireless traffic for a response to that stimuli, a user can obtain the motion trajectories within the motion detection zone and then use them to calculate the camera's location. We also extend the camera localization algorithm to pinpoint cameras in always-active mode. We develop an Android app to implement MotionCompass. Our extensive experiments using the developed app and 18 popular wireless cameras demonstrate that for cameras with one motion sensor, MotionCompass can attain a mean localization error of around 5 cm with less than 140 seconds. We also discuss defenses against MotionCompass. Our localization technique builds upon existing work that detects the existence of hidden cameras, to pinpoint their exact location. Qiuye He, Song Fang 0001, Yao Liu 0007 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Revisiting Wireless Breath and Crowd Inference Attacks With Defensive DeceptionabstractBreathing rates and crowd counting can be used to verify the human presence, especially the former one can disclose a person’s physiological status. Many studies have demonstrated success in applying channel state information (CSI) to estimate the breathing rates of stationary individuals and count the number of people in motion. Due to the invisibility of radio signals, the ubiquitous deployment of wireless infrastructures, and the elimination of the line-of-sight (LOS) requirement, such wireless inference techniques can surreptitiously work and violate user privacy. However, little research has been conducted specifically in mitigating misuse of those techniques. This paper proposes new proactive countermeasures against all existing CSI-based vital signs and crowd counting inference methods. Specifically, we set up ambush locations with carefully designed wireless signals, allowing eavesdroppers to infer a false breathing rate or person count specified by the transmitter. The true breathing rate or person count is thus protected. Experimental results on software-defined radio platforms with 5 participants demonstrate the effectiveness of the proposed defenses. An eavesdropper can be misled into believing any desired breathing rate with an error of less than 1.2 bpm when the user lies on a bed in a bedroom, and 0.9 bpm when the user sits in a chair in an office room. Additionally, our proposed defense mechanisms can deceive an attacker into believing there are moving individuals in an empty room with a 100% success rate, using both Support Vector Machine (SVM) and Decision Tree (DT) classifiers. Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | When Free Tier Becomes Free to Enter: A Non-Intrusive Way to Identify Security Cameras with no Cloud SubscriptionabstractWireless security cameras may deter intruders. Accompanying the hardware, consumers may pay recurring monthly fees for recording videos to the cloud, or use the free tier offering motion alerts and sometimes live streams via the camera app. Many users may purchase the hardware without buying the subscription to save money, which inherently reduces their efficacy. We discover that the wireless traffic generated by a camera responding to stimulating motion may disclose whether or not video is being streamed. A malicious user such as a burglar may use such knowledge to target homes with a ''weak camera'' that does not upload video or turn on live view mode. In such cases, criminal activities would not be recorded though they are performed within the monitoring area of the camera. Accordingly, we describe a novel technique called WeakCamID that creates motion stimuli and sniffs resultant wireless traffic to infer the camera state. We perform a survey involving a total of 220 users, finding that all users think cameras have a consistent security guarantee regardless of the subscription status. Our discovery breaks such ''common sense''. We implement WeakCamID in a mobile app and experiment with 11 popular wireless cameras to show that WeakCamID can identify weak cameras with a mean accuracy of around 95% and within less than 19 seconds. Qiuye He, Song Fang 0001, Yao Liu 0007 |
CCS | 3 |
| 2023 | Phantom-CSI Attacks against Wireless Liveness DetectionabstractAll systems monitoring human behavior in real time are, by their nature, attractive targets for spoofing. For example, misdirecting live-feed security cameras or voice-controllable Internet-of-Things (IoT) systems (e.g., Amazon Alexa and Google Assistant) has immediately intuitive benefits, so there is a consequent need for detecting liveness of the human(s) whose behavior is being monitored. Emerging research lines have focused on analyzing changes in prevalent wireless signals to detect video or voice spoofing attacks, as wireless-based techniques do not require the user to carry any additional device or sensor for liveness detection. Video/voice streaming and coexisting wireless signals convey different aspects of the same overall contextual information related to human activities, and the presence of spoofing attacks on the former breaks this relationship, so the latter performs well as liveness detection to augment the former. However, we recognize and herein evaluate how to spoof the latter as well to defeat this liveness detection. In our attack, an adversary can easily create phantom wireless signals and synchronize them with spoofed video/voice signals, such that the legitimate user can no longer distinguish real from fake human activity. Real-world experimental results on top of software-defined radio platforms validate the possibility of generating fake CSI flows and demonstrate that with the phantom-CSI attack, the true positive rates (TPRs) of wireless liveness detection systems for video and voice decrease from 100% spoofing detection to just 4.4% and 0, respectively. Qiuye He, Song Fang 0001 |
RAID | 2 |
| 2023 | Proactive Anti-Eavesdropping With Trap Deployment in Wireless NetworksabstractDue to the open nature of the wireless medium, wireless communications are especially vulnerable to eavesdropping attacks. This article designs a new wireless communication system to deal with eavesdropping attacks. The proposed system can enable a legitimate receiver to get desired messages and meanwhile an eavesdropper to hear “fake” but meaningful messages by combining confidentiality and deception, thereby confusing the eavesdropper and achieving additional concealment that further protects exchanged messages. Towards this goal, we propose techniques that can conceal exchanged messages by utilizing wireless channel characteristics between the transmitter and the receiver, as well as techniques that can attract an eavesdropper to gradually approach a trap region, where the eavesdropper can get fake messages. We also provide both theoretical and empirical analysis of the established secure channel between the transmitter and the receiver. We develop a prototype system using Universal Software Defined Radio Peripherals (USRPs). Experimental results show that an eavesdropper at a trap location can receive fake information with a bit error rate (BER) close to 0, and the transmitter with multiple antennas can successfully deploy a trap area. Qiuye He, Song Fang 0001, Tao Wang 0026, Yao Liu 0007, Shangqing Zhao |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisabstractSensitive numbers play an unparalleled role in identification and authentication. Recent research has revealed plenty of side-channel attacks to infer keystrokes, which require either a training phase or a dictionary to build the relationship between an observed signal disturbance and a keystroke. However, training-based methods are unpractical as the training data about the victim are hard to obtain, while dictionary-based methods cannot infer numbers, which are not combined according to linguistic rules like letters are. We observe that typing a number creates not only a number of observed disturbances in space (each corresponding to a digit), but also a sequence of periods between each disturbance. Based upon existing work that utilizes inter-keystroke timing to infer keystrokes, we build a novel technique called WINK that combines the spatial and time domain information into a spatiotemporal feature of keystroke-disturbed wireless signals. With this spatiotemporal feature, WINK can infer typed numbers without the aid of any training. Experimental results on top of software-defined radio platforms show that WINK can vastly reduce the guesses required for breaking certain 6-digit PINs from 1 million to as low as 16, and can infer over 52% of user-chosen 6-digit PINs with less than 100 attempts. Edwin Yang, Qiuye He, Song Fang 0001 |
CCS | 3 |
| 2022 | HoneyBreath: An Ambush Tactic Against Wireless Breath Inference
Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao |
MobiQuitous | 3 |
| 2022 | Wireless Training-Free Keystroke Inference Attack and DefenseabstractExisting research work has identified a new class of attacks that can eavesdrop on the keystrokes in a non-invasive way without infecting the target computer to install malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from the wireless signal. To eavesdrop on keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. To defend against this attack, we propose a reactive jamming mechanism that launches the jamming only during the typing period. Experimental results on software-defined radio platforms validate the impact of the attack and the performance of the defense. Edwin Yang, Song Fang 0001, Ian D. Markwood, Yao Liu 0007, Shangqing Zhao, Haojin Zhu |
IEEE/ACM Trans. Netw. | 2 |
| 2021 | CommanderGabble: A Universal Attack Against ASR Systems Leveraging Fast SpeechabstractAutomatic Speech Recognition (ASR) systems are widely used in various online transcription services and personal digital assistants. Emerging lines of research have demonstrated that ASR systems are vulnerable to hidden voice commands, i.e., audio that can be recognized by ASRs but not by humans. Such attacks, however, often either highly depend on white-box knowledge of a specific machine learning model or require special hardware to construct the adversarial audio. This paper proposes a new model-agnostic and easily-constructed attack, called CommanderGabble, which uses fast speech to camouflage voice commands. Both humans and ASR systems often misinterpret fast speech, and such misinterpretation can be exploited to launch hidden voice command attacks. Specifically, by carefully manipulating the phonetic structure of a target voice command, ASRs can be caused to derive a hidden meaning from the manipulated, high-speed version. We implement the discovered attacks both over-the-wire and over-the-air, and conduct a suite of experiments to demonstrate their efficacy against 7 practical ASR systems. Our experimental results show that the over-the-wire attacks can disguise as many as 96 out of 100 tested voice commands into adversarial ones, and that the over-the-air attacks are consistently successful for all 18 chosen commands in multiple real-world scenarios. Zhaohe John Zhang, Edwin Yang, Song Fang 0001 |
ACSAC | 3 |
| 2021 | MotionCompass: pinpointing wireless camera via motion-activated trafficabstractWireless security cameras are integral components of security systems used by military installations, corporations, and, due to their increased affordability, many private homes. These cameras commonly employ motion sensors to identify that something is occurring in their fields of vision before starting to record and notifying the property owner of the activity. In this paper, we discover that the motion sensing action can disclose the location of the camera through a novel wireless camera localization technique we call MotionCompass. In short, a user who aims to avoid surveillance can find a hidden camera by creating motion stimuli and sniffing wireless traffic for a response to that stimuli. With the motion trajectories within the motion detection zone, the exact location of the camera can be then computed. We develop an Android app to implement MotionCompass. Our extensive experiments using the developed app and 18 popular wireless security cameras demonstrate that for cameras with one motion sensor, MotionCompass can attain a mean localization error of around 5 cm with less than 140 seconds. This localization technique builds upon existing work that detects the existence of hidden cameras, to pinpoint their exact location and area of surveillance. Qiuye He, Song Fang 0001, Yao Liu 0007 |
MobiSys | 3 |
| 2021 | Wireless-Assisted Key Establishment Leveraging Channel ManipulationabstractWireless communication is easily eavesdropped due to the broadcast nature of the wireless medium. This has spurred extensive research into secret key establishment using physical layer characteristics of wireless channels. In all these schemes, the secret keys directly originate from the physical features of the real wireless channel, which is highly dependent on the communication environment nearby. Also, previous schemes require performing information reconciliation, which increases both the costs and the risk of key leakage. In this paper, we exhibit a novel wireless key establishment method allowing the transmitter to specify arbitrary content as the key and cause the receiver to obtain the same key leveraging a channel manipulation technique. We furthermore enable the transmitter to apply error-correction code to the key, so that the receiver can automatically correct any mismatched bits without sending key-related information back to the transmitter over the public channel. Experimental results demonstrate that our key establishment method reaches a success rate as high as 91.0 percent for establishing a 168-bit key between the transmitter and the receiver, and meanwhile the chance that the eavesdropper can infer the key in meter-order range of the receiver is subdued into the range of 0~0.10 percent. Song Fang 0001, Ian D. Markwood, Yao Liu 0007 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | Virtual Step PIN Pad: Towards Foot-input Authentication Using GeophonesabstractThe use of personal identification numbers (PINs) for authentication is ubiquitous due to their simplicity and flexibility. In this work, we present virtual step PIN pad, a novel and practical PIN entry scheme that allows a user to enter a PIN through foot tapping on the ground. The virtual step PIN pad utilizes geophones to collect structural vibration signals caused by foot tapping. When a user generates the activation signals by performing a predetermined sequence of foot taps within the target area, the virtual step PIN pad will be launched, and takes the foot tapping input by the user. The system then demodulates the corresponding structural vibration signals into a PIN. We have developed a prototype of the virtual step PIN pad and conduct a suite of experiments to evaluate its practicality and security. Experimental results show that the virtual step PIN pad can achieve an average success rate of 96.5% for inputting a human-chosen 4-digit PIN. Meanwhile, the success rate for an adversary at a distance of more than 2.5 meters away from the PIN pad to infer the target PIN decreases to below 3%. Hanyan Zhang, Edwin Yang, Song Fang 0001 |
MASS | 4 |
| 2019 | Entrapment for Wireless EavesdroppersabstractDue to the open nature of wireless medium, wireless communications are especially vulnerable to eavesdropping attacks. This paper designs a new wireless communication system to deal with eavesdropping attacks. The proposed system can enable a legitimate receiver to get desired messages and meanwhile an eavesdropper to hear “fake” but meaningful messages, thereby confusing the eavesdropper and achieving additional concealment that further protects exchanged messages. Towards this goal, we propose techniques that can conceal exchanged messages by utilizing wireless channel characteristics between the transmitter and the receiver, as well as techniques that can attract an eavesdropper to gradually approach a trap region, where the eavesdropper can get fake messages. We also implement and evaluate the proposed system on top of Universal Software Defined Radio Peripherals (USRPs). Experimental results show that an eavesdropper at a trap location can receive fake information with a bit error rate (BER) that is close to 0, and the transmitter with multiple antennas can successfully deploy a trap area. Song Fang 0001, Tao Wang 0026, Yao Liu 0007, Shangqing Zhao |
INFOCOM | 1 |
| 2018 | No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your TypingabstractTraditional methods to eavesdrop keystrokes leverage some malware installed in a target computer to record the keystrokes for an adversary. Existing research work has identified a new class of attacks that can eavesdrop the keystrokes in a non-invasive way without infecting the target computer to install a malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from wireless signal. To eavesdrop keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. We implement this attack on software-defined radio platforms and conduct a suite of experiments to validate the impact of this attack. We point out that this paper does not propose to use wireless signal for inferring keystrokes, since such work already exists. Instead, the main goal of this paper is to propose new techniques to remove the training process, which can make existing work unpractical. Song Fang 0001, Ian D. Markwood, Yao Liu 0007, Shangqing Zhao, Haojin Zhu |
CCS | 1 |
| 2018 | Signal Entanglement Based Pinpoint Waveforming for Location-Restricted Service Access ControlabstractWe propose a novel wireless technique named pinpoint waveforming to achieve the location-restricted service access control, i.e., providing wireless services to users at eligible locations only. The proposed system is inspired by the fact that when two identical wireless signals arrive at a receiver simultaneously, they will constructively interfere with each other to form a boosted signal whose amplitude is twice of that of an individual signal. As such, the location-restricted service access control can be achieved through transmitting at a weak power, so that receivers at undesired locations (where the constructive interference vanishes), will experience a low signal-to-noise ratio (SNR), and hence a high bit error rate that retards the correct decoding of received messages. At the desired location (where the constructive interference happens), the receiver obtains a boosted SNR that enables the correct message decoding. To solve the difficulty of determining an appropriate transmit power, we propose to entangle the original transmit signals with jamming signals of opposite phase. The jamming signals can significantly reduce the SNR at the undesired receivers but cancel each other at the desired receiver to cause no impact. With the jamming entanglement, the transmit power can be any value specified by the system administrator. To enable the jamming entanglement, we create the channel calibration technique that allows the synchronization of transmit signals at the desired location. We develop a prototype system using the Universal Software Defined Radio Peripherals (USRPs). The evaluation results show that the receiver at the desired location obtains a throughput ranging between 0.9 and 0.93, whereas an eavesdropper that is 0.3 meter away from a desired location has a throughput approximately equal to 0. Tao Wang 0026, Yao Liu 0007, Tao Hou 0001, Qingqi Pei, Song Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2017 | Virtual Multipath Attack and Defense for Location Distinction in Wireless NetworksabstractIn wireless networks, location distinction aims to detect location changes or facilitate authentication of wireless users. To achieve location distinction, recent research has focused on investigating the spatial uncorrelation property of wireless channels. Specifically, differences in wireless channel characteristics are used to distinguish locations or identify location changes. However, we discover a new attack against all existing location distinction approaches that are built on the spatial uncorrelation property of wireless channels. In such an attack, the adversary can easily hide her location changes or impersonate movements by injecting fake wireless channel characteristics into a target receiver. To defend against this attack, we propose a detection technique that utilizes an auxiliary receiver or antenna to identify these fake channel characteristics. We also discuss such attacks and corresponding defenses in OFDM systems. Experimental results on our USRP-based prototype show that the discovered attack can craft any desired channel characteristic with a successful probability of 95.0 percent to defeat spatial uncorrelation based location distinction schemes and our novel detection method achieves a detection rate higher than 91.2 percent while maintaining a very low false alarm rate. Song Fang 0001, Yao Liu 0007, Wenbo Shen, Haojin Zhu, Tao Wang 0026 |
IEEE Trans. Mob. Comput. | 1 |
| 2016 | Wireless Communications under Broadband Reactive Jamming AttacksabstractA reactive jammer jams wireless channels only when target devices are transmitting; Compared to constant jamming, reactive jamming is harder to track and compensate against [2], [38]. Frequency hopping spread spectrum (FHSS) and direct sequence spread spectrum (DSSS) have been widely used as countermeasures against jamming attacks. However, both will fail if the jammer jams all frequency channels or has high transmit power. In this paper, we propose an anti-jamming communication system that allows communication in the presence of a broadband and high power reactive jammer. The proposed system transmits messages by harnessing the reaction time of a reactive jammer. It does not assume a reactive jammer with limited spectrum coverage and transmit power, and thus can be used in scenarios where traditional approaches fail. We develop a prototype of the proposed system using GNURadio. Our experimental evaluation shows that when a powerful reactive jammer is present, the prototype still keeps communication, whereas other schemes such as 802.11 DSSS fail completely. Song Fang 0001, Yao Liu 0007, Peng Ning |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Mimicry Attacks Against Wireless Link Signature and New Defense Using Time-Synched Link SignatureabstractWireless link signature is a physical layer authentication mechanism, using the multipath effect between a transmitter and a receiver to provide authentication of wireless signals. This paper identifies a new attack, called mimicry attack, against the existing wireless link signature schemes. An attacker can forge a legitimate transmitter's link signature as long as it knows the legitimate signal at the receiver's location, and the attacker does not have to be at exactly the same location as the legitimate transmitter. We also extend the mimicry attack to multiple-input multiple-output (MIMO) systems, and conclude that the mimicry attack is feasible only when the number of attacker' antennas is equal to or larger than that of the receiver's antennas. To defend against the mimicry attack, this paper proposes a novel construction for wireless link signature, called time-synched link signature, by integrating cryptographic protection and time factor into wireless physical layer features. Experimental results confirm that the mimicry attack is a real threat and the newly proposed time-synched link signatures are effective in physical layer authentication. Song Fang 0001, Yao Liu 0007, Peng Ning |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Where are you from?: confusing location distinction using virtual multipath camouflageabstractIn wireless networks, location distinction aims to detect location changes or facilitate authentication of wireless users. To achieve location distinction, recent research has been focused on investigating the spatial uncorrelation property of wireless channels. Specifically, the differences of wireless channel characteristics are used to distinguish locations or identify location changes. Song Fang 0001, Yao Liu 0007, Wenbo Shen, Haojin Zhu |
MobiCom | 1 |