VLDB 2026 Research / reviewers in the wild / expert
Fan Dang 0001
dblp:167/4171
· DBLP profile ↗
47ranked-venue papers
8as first author
40since 2021 · last 2026
0000-0002-9949-6987ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 30 · 5 first-author · 24 since 2021Systems, architecture and hardware · 11 · 1 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SpecOffload: Unlocking Latent GPU Capacity for LLM Inference on Resource-Constrained DevicesabstractEfficient LLM inference on resource-constrained devices presents significant challenges in compute and memory utilization. Due to limited GPU memory, existing systems offload model weights to CPU memory, incurring substantial I/O overhead between the CPU and GPU. This leads to two major inefficiencies: (1) GPU cores are underutilized, often remaining idle while waiting for data to be loaded; and (2) GPU memory has low impact on performance, as reducing its capacity has minimal effect on overall throughput.In this paper, we propose SpecOffload, a high-throughput inference engine that embeds speculative decoding into offloading. Our key idea is to unlock latent GPU resources for storing and executing a draft model used for speculative decoding, thus accelerating inference at near-zero additional cost. To support this, we carefully orchestrate the interleaved execution of target and draft models in speculative decoding within the offloading pipeline, and propose a planner to manage tensor placement and select optimal parameters. Compared to the best baseline, SpecOffload improves GPU core utilization by 4.49x and boosts inference throughput by 2.54x. Our code is available at https://github.com/MobiSense/SpecOffload-public . Xiangwen Zhuge, Fan Dang 0001, Danyang Li 0005, Tianxiang Hao 0001, Qiang Ma 0007, Yahui Han, Zheng Yang 0002 |
IWQoS | 3 |
| 2026 | QUIDS: Quality-Informed Incentive-Driven Multiagent Dispatching System for Mobile CrowdsensingabstractThis paper addresses the challenges of achieving optimal quality of information (QoI) in non-dedicated vehicular mobile crowdsensing (NVMCS) system, where vehicles not originally designed for sensing are leveraged to collect real-time data as they traverse urban environments. These challenges are exacerbated by the interrelated issues of sensing coverage, sensing reliability, and the inherently dynamic nature of participating vehicles. To tackle these challenges, we propose QUIDS, a QUality-informed Incentive-driven multi-agent Dispatching System, which ensures high sensing coverage and sensing reliability under budget constraints in NVMCS systems. QUIDS improves QoI by introducing a novel metric, Aggregated Sensing Quality (ASQ), designed to quantitatively capture the concept of QoI by integrating both sensing coverage and sensing reliability. Moreover, we develop a Mutually Assisted Belief-aware Vehicle Dispatching algorithm that estimates sensing reliability and allocates monetary incentives under uncertain vehicle conditions, thereby further improving ASQ. Evaluation using real-world data collected from a deployed NVMCS system in a metropolitan area demonstrates the effectiveness of QUIDS. The ASQ metric shows a 38% improvement over non-dispatching scenarios and a 10% enhancement over state-of-the-art methods. Additionally, QUIDS reduces reconstruction map errors by 39–74% across various reconstruction algorithms, validating its efficacy in improving QoI within NVMCS systems. Addressing the often-overlooked issue of sensing reliability in existing studies, the QUIDS system leverages non-dedicated vehicles and incorporates a quality-informed incentive-driven dispatching system to jointly optimize sensing coverage and sensing reliability. This enables low-cost, high-quality, and scalable urban environmental monitoring without the need for dedicated sensing infrastructure, and makes the system applicable to diverse smart-city scenarios such as traffic monitoring and environmental sensing. Zuxin Li, Fanhang Man, Xuecheng Chen, Susu Xu, Fan Dang 0001, Chaopeng Hong, Yunhao Liu 0001, Xiao-Ping Zhang 0002, Xinlei Chen |
IEEE Internet Things J. | 6 |
| 2026 | BlueKey: Exploiting Bluetooth Low Energy for Enhanced Physical-Layer Key GenerationabstractBluetooth Low Energy (BLE) is a prevalent technology in various applications due to its low power consumption and wide device compatibility. Despite its numerous advantages, the encryption methods of BLE often expose devices to potential attacks. To fortify security, we investigate the application of Physical-layer Key Generation (PKG), a promising technology that enables devices to generate a shared secret key from their shared physical environment. Although extensively investigated, PKG is generally discussed in the context of Wi-Fi, and existing solutions for BLE demonstrate significantly lower performance. To bridge this gap, we propose a distinctive approach that capitalizes on the inherent characteristics of BLE to facilitate efficient PKG. We utilize the constant tone extension within BLE protocols to extract comprehensive physical layer information and introduce an innovative method that employs Legendre polynomial quantization for PKG. This method facilitates the exchange of secret keys with a high key matching rate and a high key generation rate. The efficacy of our approach is validated through extensive experiments on a software-defined radio platform, underscoring its potential to enhance security in the rapidly expanding field of BLE applications. A pilot study on commercial off-the-shelf BLE devices further validates the system's practicality, revealing important trade-offs between performance and hardware constraints in real-world deployments. Fan Dang 0001, Jinyan Jiang, Xu Wang 0018, Lin Wang 0023, Kebin Liu 0001, Xinlei Chen, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | SURGEON: Memory-Adaptive Fully Test-Time Adaptation via Dynamic Activation SparsityabstractDespite the growing integration of deep models into mobile terminals, the accuracy of these models declines significantly due to various deployment interferences. Test-time adaptation (TTA) has emerged to improve the performance of deep models by adapting them to unlabeled target data online. Yet, the significant memory cost, particularly in resource-constrained terminals, impedes the effective deployment of most backward-propagation-based TTA methods. To tackle memory constraints, we introduce Surgeon, a method that substantially reduces memory cost while preserving comparable accuracy improvements during fully test-time adaptation (FTTA) without relying on specific network architectures or modifications to the original training procedure. Specifically, we propose a novel dynamic activation sparsity strategy that directly prunes activations at layer-specific dynamic ratios during adaptation, allowing for flexible control of learning ability and memory cost in a data-sensitive manner. Among this, two metrics, Gradient Importance and Layer Activation Memory, are considered to determine the layer-wise pruning ratios, reflecting accuracy contribution and memory efficiency, respectively. Experimentally, our method surpasses the baselines by not only reducing memory usage but also achieving superior accuracy, delivering SOTA performance across diverse datasets, architectures, and tasks. Jiaqi Tang 0005, Bin Guo 0001, Fan Dang 0001, Sicong Liu 0005, Zhui Zhu, Ying-Cong Chen, Zhiwen Yu 0001, Yunhao Liu 0001 |
CVPR | 4 |
| 2025 | SwiftReTaKe: Quick and Accurate Redundancy Reduction for Cloud-Edge Collaborative Video-Language UnderstandingabstractVision Language Models (VLMs) can enhance Internet of Things (IoT) applications by efficiently extracting valuable information from excessively long videos captured by IoT cameras. Due to the large volume of video data and the high computation overhead of VLMs, a practical deployment strategy is to transmit the video to the cloud only on demand and also deploy the VLMs on the cloud for video analytics. Yet, the interaction experience between humans and VLMs is degraded by the high latency in such cloud-edge collaboration applications. The latency is caused by both the video transmission process and the heavy VLM inference process. We propose SwiftReTaKe, a two-round transmission framework coupled with a low-latency pre-pruning strategy to reduce both network and inference latency. By first sending keyframes for relevance estimation and then adaptively transmitting informative frames, SwiftReTaKe minimizes data transfer and LLM computation. Compared to the state-of-the-art (SOTA) long video processing method, SwiftReTaKe reduces the latency by 6 times with only 3.33% accuracy drop. Xinqi Jin, Fan Dang 0001, Kebin Liu 0001, Jiangchuan Liu, Jingao Xu |
ICPADS | 2 |
| 2025 | 6Loda: Pattern Filtering and Ensemble Learning for IPv6 Target Generation and Scanning
Xikai Sun, Fan Dang 0001, Xinqi Jin, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2025 | DoMo: Rethinking Downscaling For Mobile Neural-Enhanced Video Streaming
Zhui Zhu, Xu Wang 0018, Jingao Xu, Weichen Zhang 0001, Yankun Yuan, Lin Wang 0023, Fan Dang 0001, Yunhao Liu 0001 |
INFOCOM | 7 |
| 2025 | Palantir: Towards Efficient Super Resolution for Ultra-high-definition Live StreamingabstractNeural enhancement through super-resolution (SR) deep neural networks (DNNs) opens up new possibilities for ultra-high-definition (UHD) live streaming. Yet, the heavy SR DNN inference overhead leads to severe deployment challenges. To reduce the overhead, existing systems propose to apply DNN-based SR only on carefully selected anchor frames while upscaling non-anchor frames via the lightweight reusing-based SR approach. However, frame-level scheduling is coarse-grained and fails to deliver optimal efficiency. In this work, we propose Palantír, the first neural-enhanced UHD live streaming system with fine-grained patch-level scheduling. Xinqi Jin, Zhui Zhu, Xikai Sun, Fan Dang 0001, Jiangchuan Liu, Jingao Xu, Kebin Liu 0001, Xinlei Chen, Yunhao Liu 0001 |
MMSys | 4 |
| 2025 | Embodied navigationabstractAbstract Navigation is a fundamental component of modern information application systems, ranging from military, transportations, and logistic, to explorations. Traditional navigations are based on an absolute coordination system that provides a precise map of the physical world, the locations of the moving objects, and the optimized navigation routes. In recent years, many new emerging applications have presented new demands for navigation, e.g., underwater/underground navigations where no GPS or other localizations are available, an un-explored area with no maps, and task-oriented navigations without specific routes. The advances in IoT and AI enable us to design new navigation paradigms, embodied navigation that allows the moving object to interact with the physical world to obtain the local map, localize the objects, and optimize the navigation routes accordingly. We make a systematic and comprehensive review of research in embodied navigation, encompassing key aspects on perceptions, navigation and efficiency optimization. Beyond advancements in these areas, we also examine the emerging tasks enabled by embodied navigation which require flexible mobility in diverse and evolving environments. Moreover, we identify the challenges associated with deploying embodied navigation systems in the real world and extend them to substantial areas. We aim for this article to provide valuable insights into this rapidly developing field, fostering future research to close existing gaps and advance the development of general-purpose autonomous systems grounded in embodied navigation. Yunhao Liu 0001, Li Liu 0048, Yunhuai Liu, Fan Dang 0001 |
Sci. China Inf. Sci. | 5 |
| 2025 | CaaS: Enabling Control-as-a-Service for Real-Time Industrial NetworkingabstractFlexible manufacturing is one of the core goals of Industry 4.0 and brings new challenges to current industrial control systems. Our detailed field study on auto glass industry revealed that existing production lines are laborious to reconfigure, difficult to upscale, and costly to upgrade during production switching. Such inflexibility arises from the tight coupling of devices, controllers, and control tasks. In this work, we propose a new architecture for industrial control systems named Control-as-a-Service (CaaS). CaaS transfers and distributes control tasks from dedicated controllers into network switches. By combining control and transmission functions in switches, CaaS virtualizes the whole industrial network to one Programmable Logic Controller (PLC). We propose a set of techniques that realize end-to-end determinism for in-network industrial control and a joint task and traffic scheduling algorithm. We evaluate the performance of CaaS on testbeds based on real-world networked control systems. The results show that the idea of CaaS is feasible and effective, and CaaS achieves absolute packet delivery, 42-45% lower latency, and three orders of magnitude lower jitter. We believe CaaS is a meaningful step towards the distribution, virtualization, and servitization of industrial control. Zheng Yang 0002, Zeyu Wang 0015, Xiaowu He, Yi Zhao 0016, Fan Dang 0001, Jiahang Wu, Yunhao Liu 0001, Qiang Ma 0007 |
IEEE J. Sel. Areas Commun. | 5 |
| 2025 | Hinge: An Environment-Varying Adaptive Physical-Layer Key Generation SchemeabstractOn low-power, low-cost Internet of Things (IoT) edges, coarse-grained entropy source-based physical-layer key generation (PKG) is often used, which results in a very low bit generation rate (BGR). In this paper, a novel PKG scheme, Hinge, designed to adapt to varying environmental conditions is introduced to optimize the trade-off between the bit mismatch rate (BMR) and BGR using fine-grained entropy sources on IoT devices. Hinge predicts channel reciprocity levels from one side and dynamically adjusts the quantization strategy, maintaining a low BMR while maximizing BGR. Compared with existing PKG solutions on Bluetooth devices, Hinge yields significant improvements in BGR, with a comparable BMR. Through extensive experiments, Hinge showcases its potential for providing a secure and efficient key generation mechanism for IoT devices in complex real-world scenarios. Lin Wang 0023, Fan Dang 0001, Xikai Sun, Zijuan Liu, Yunhao Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | CatUA: Catalyzing Urban Air Quality Intelligence Through Mobile Crowd-SensingabstractMobile air pollution sensing methods have emerged to collect air quality data with improved spatial and temporal resolutions. However, existing methodologies struggle to effectively process spatially mixed gas samples due to the highly dynamic fluctuations experienced by sensors, resulting in significant measurement deviations. We identify an opportunity to address this issue by exploring potential patterns within sensor measurements. To this end, we propose CatUA, a novel city-scale fine-grained air quality estimation system designed to deliver accurate mobile air quality data. First, we design AirBERT, a representation learning model specifically aimed at discerning mixed gas concentrations from sensor data. Second, we implement a Prompt-informed Training Strategy that leverages extensive unlabeled and minimal labeled city-scale data to enhance the performance of CatUA. Notably, the Auto-Prompt mechanism allows CatUA to conveniently acquire new knowledge tailored to specific downstream tasks. To ensure the practicality of CatUA, we have invested considerable effort in developing the software stack on our meticulously crafted Sensing Front-end, which has successfully gathered city-scale air quality data for over 1,200 hours. Experiments conducted on the collected data demonstrate that CatUA reduces sensing errors by 96.9% with a latency of only 44.9ms, outperforming the state-of-the-art baseline by 42.6%. Yuxuan Liu 0010, Haoyang Wang 0012, Fanhang Man, Jingao Xu, Fan Dang 0001, Chaopeng Hong, Yunhao Liu 0001, Xiao-Ping Zhang 0002, Yali Song, Qiuhua Wang, Xinlei Chen |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | TSNCard: Bridging the Gap in TSN Diagnostics via Protocol, Algorithm, and HardwareabstractTime-Sensitive Networking (TSN) is foreseen as a foundational technology that enables Industry 4.0. It offers deterministic data transmission over Ethernet for critical applications such as industrial control and automotive systems. However, TSN is susceptible to hardware and software errors, necessitating an effective diagnostic system. Traditional network diagnostic tools are inadequate for TSN fault localization and classification due to the tightly coupled traffic and high precision requirements in TSN. In response, this paper presents TSNCard, a cross-cycle postcard-based diagnostic system tailored for Time-Aware Shaper (IEEE 802.1 Qbv) in TSN. TSNCard introduces a novel telemetry protocol that leverages the cyclical nature of TSN networks for data collection at each node. This protocol, coupled with dedicated analytic algorithms and hardware innovations within switches, forms a comprehensive system for TSN monitoring, fault localization and classification. Extensive experiments on both simulation and physical testbeds show that TSNCard can 100% detect fault location and type of the TSN misbehavior while adhering to industrial bandwidth restrictions. TSNCard not only bridges the gap in the TSN protocol stack, but also serves as a versatile toolkit for time-synchronized network analysis, paving the way for future research. The code is available athttps://github.com/MobiSense/TSNCard Xiangwen Zhuge, Zeyu Wang 0015, Xiaowu He, Fan Dang 0001, Jingao Xu, Zheng Yang 0002, Qiang Ma 0007 |
IEEE Trans. Netw. | 5 |
| 2024 | BreathPass: Ultrasounic Authentication by Chest and Abdomen Movement while BreathingabstractIn this study, we propose BreathPass, a non-invasive authentication system that characterizes the chest/abdomen movement incurred by human breath to enable unlocking smart devices while wearing various types of face covers, clothing, in different postures, and dynamic status such as walking or running. To capture the breathing pattern, BreathPass uses speakers to emit ultrasound signals. The signals are reflected off the chest wall and abdomen and then back to the microphone, which records the reflected signals. The system then extracts the breathing pattern from the reflected signals, and further extracts fingerprints from the breathing pattern, and use these fingerprints to perform authentication. We carefully design a Deep Neural Network model and explore its capacity for feature abstraction in order to address the challenges associated with tiny position changes resulting in different breathing patterns and the extremely narrow bandwidth of breathing. We implement a prototype and conduct extensive experiments. BreathPass achieves an overall accuracy of 83%, a true positive rate of 73%, and a false positive rate of 5%, according to performance evaluation results. Lingkun Li, Fan Dang 0001, Zhichao Cao 0001 |
ICPADS | 2 |
| 2024 | Flexible LAN-WAN Orchestration for Communication Efficient Federated Learning over Large-Scale Mobile DevicesabstractFederated learning (FL) has been widely adopted as a privacy-preserving model training paradigm. However, traditional FL protocol heavily relies on data transmission between clients and servers across the wide-area network (WAN), which is tightly constrained and unreliable, therefore causing expensive communication and slow convergence. To this end, we propose a LAN-aware FL (LanFL) protocol, which can efficiently leverage the network capacity of the local-area network (LAN). By frequent model aggregation among the devices within the same LAN, we can significantly reduce the global aggregation across WAN, thus accelerating the training process. However, due to the unique challenges introduced by LAN, it’s not easy to efficiently utilize LAN resources while preserving the original dignity of FL performance. Therefore, LanFL also incorporates several critical techniques: LAN-aware hierarchical aggregation, intraLAN device topology construction, and inter-LAN heterogeneous bandwidth coordination. Extensive real-world experiments are conducted and the experimental results show that LanFL can significantly accelerate FL training up to $6.0 \times$, while preserving the model accuracy. Jinliang Yuan, Qing Li 0028, Fan Dang 0001, Xiaofang Mu, Mengwei Xu 0001, Shangguang Wang |
ICPADS | 3 |
| 2024 | A QoE-Aware Adaptive Energy-Efficient Transmission Scheduling MethodabstractIn this paper, we propose a dynamic data transmission strategy for smart home environments that aims to optimize the Quality of Experience (QoE) by adaptively adjusting the data upload frequency based on the predicted trends in sensor data. Using the home wireless sensors monitoring dataset, we implement a deep learning model for accurate time series forecasting. In addition, an anomaly detection mechanism is used to identify critical events, requiring more frequent data uploads when important changes are detected. The QoE is quantified through a weighted average of several influencing factors, including data timeliness, timely upload of critical events, and transmission frequency. Our optimization objective is to maximize QoE while minimizing the number of transmissions, with an emphasis on reducing energy consumption through intelligent scheduling. The results demonstrate that our approach effectively balances data timeliness, transmission efficiency, and energy savings, leading to improved user satisfaction in smart home applications. Yankun Yuan, Lin Wang 0023, Chonghui Xiao, Zijuan Liu, Fan Dang 0001, Xu Wang 0018, Haitian Zhao |
ICPADS | 5 |
| 2024 | A Comprehensive Evaluation of Bluetooth Low Energy MeshabstractBluetooth Low Energy (BLE) Mesh is a pivotal multi-hop self-organizing network in the Internet of Things (IoT) domain, offering low power consumption, low cost, and robustness. This paper presents a comprehensive study on the communication performance of BLE-Mesh using commercial off-the-shelf devices, focusing on the impact of key mesh parameters such as transmission power, packet interval, and network structure on performance. Through extensive indoor and outdoor experiments, we quantify the impact of these parameters and conduct a detailed study. Our findings provide insights into the actual communication range of BLE-Mesh, the effect of node design on overall network performance, and the configuration for optimal performance. The research contributes to the establishment of a BLE-Mesh network in real-world environments, answering critical questions for practitioners, and offering a reference for future BLE-Mesh deployments. This work furthers our understanding of the characteristics, challenges, and future directions of BLE-Mesh, setting the stage for advancements in IoT applications such as smart offices and homes. Yize Zhao, Lin Wang 0023, Zijuan Liu, Yifan Xu 0023, Fan Dang 0001, Xu Wang 0018, Haitian Zhao |
ICPADS | 5 |
| 2024 | Enhancing Large Language Models with Knowledge Graphs for Robust Question AnsweringabstractIn recent years, large language models (LLMs) have shown rapid development, becoming one of the most popular topics in the field of artificial intelligence. LLMs have demonstrated powerful generalization and learning capabilities, and their performance on various language tasks has been remarkable. Despite their successes, LLMs face significant challenges, particularly in domain-specific tasks that require structured knowledge, often leading to issues such as hallucinations. To mitigate these challenges, we propose a novel system, SynaptiQA, which integrates LLMs with Knowledge Graphs (KGs) to answer more questions about knowledge. Our approach leverages the generative capabilities of LLMs to create and optimize KG queries, thereby improving the accuracy and contextual relevance of responses. Experimental results in an industrial data set demonstrate that SynaptiQA outperforms baseline models and naive retrieval-augmented generation (RAG) systems, demonstrating improved accuracy and reduced hallucinations. This integration of KGs with LLMs paves the way for more reliable and interpretable domain-specific question answering systems. Zhui Zhu, Guangpeng Qi, Guangyong Shang, Qingfeng He, Weichen Zhang 0001, Yunzhi Chen, Lijun Hu, Fan Dang 0001 |
ICPADS | 10 |
| 2024 | BlueKey: Exploiting Bluetooth Low Energy for Enhanced Physical-Layer Key GenerationabstractBluetooth Low Energy (BLE) is a prevalent technology in various applications due to its low power consumption and wide device compatibility. Despite its numerous advantages, the encryption methods of BLE often expose devices to potential attacks. To fortify security, we investigate the application of Physical-layer Key Generation (PKG), a promising technology that enables devices to generate a shared secret key from their shared physical environment. We propose a distinctive approach that capitalizes on the inherent characteristics of BLE to facilitate efficient PKG. We harness the constant tone extension within BLE protocols to extract comprehensive physical layer information and introduce an innovative method that employs Legendre polynomial quantization for PKG. This method facilitates the exchange of secret keys with a high key matching rate and a high key generation rate. The efficacy of our approach is validated through extensive experiments on a software-defined radio platform, underscoring its potential to enhance security in the rapidly expanding field of BLE applications. Fan Dang 0001, Jinyan Jiang, Xu Wang 0018, Lin Wang 0023, Kebin Liu 0001, Xinlei Chen, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2024 | InNetScheduler: In-network scheduling for time- and event-triggered critical traffic in TSNabstractTime-Sensitive Networking (TSN) is an enabling technology for Industry 4.0. Traffic scheduling plays a key role for TSN to ensure low-latency and deterministic transmission of critical traffic. As industrial network scales, TSN networks are expected to support a rising number of both time-triggered and event-triggered critical traffic (TCT and ECT). In this work, we present InNetScheduler, the first in-network TSN scheduling paradigm that boosts the throughput, i.e., number of scheduled data flows, of both traffic types. Different from existing approaches that conduct entire scheduling on the server, InNetScheduler leverages the computation resources on switches to promptly schedule latency-critical ECT, and delegate the computational-intensive TCT scheduling to server. The key innovation of InNetScheduler includes a Load-Aware Optimizer to mitigate ECT conflicts, a Relaxated ECT Scheduler to accelerate in-network computation, and End-to-End Determinism Guarantee to lower scheduling jitter. We fully implement a suite of InNetScheduler-compatible TSN switches with hardwaresoftware co-design. Extensive experiments are conducted on both simulation and physical testbeds, and the results demonstrate InNetScheduler’s superior performance. By unleashing the power of in-network computation, InNetScheduler points out a direction to extend the capacity of existing industrial networks. Xiangwen Zhuge, Xinjun Cai, Xiaowu He, Zeyu Wang 0015, Fan Dang 0001, Zheng Yang 0002 |
INFOCOM | 5 |
| 2024 | Enabling Network Diagnostics in Time-Sensitive Networking: Protocol, Algorithm, and HardwareabstractTime-Sensitive Networking (TSN) is foreseen as a foundational technology that enables Industry 4.0. It offers deterministic data transmission over Ethernet for critical applications such as industrial control and automotive systems. However, TSN is susceptible to hardware and software errors, necessitating an effective diagnostic system. Traditional network diagnostic tools are inadequate for TSN fault localization due to the unique characteristics of TSN. In response, this paper presents TSNCard, a cross-cycle postcard-based diagnostic system tailored for TSN. TSNCard introduces a novel telemetry protocol that leverages the cyclical nature of TSN networks for data collection at each node. This protocol, coupled with dedicated analytic algorithms and hardware innovations within switches, forms a comprehensive system for TSN monitoring and fault localization. Extensive experiments on both simulation and physical testbeds show that TSNCard can 100% localize the root cause of the TSN misbehavior while adhering to industrial bandwidth restrictions. TSNCard not only bridges the gap in the TSN protocol stack, but also serves as a versatile toolkit for time-synchronized network analysis, paving the way for future research. Zeyu Wang 0015, Xiaowu He, Xiangwen Zhuge, Fan Dang 0001, Jingao Xu, Zheng Yang 0002 |
IWQoS | 5 |
| 2024 | MobiAir: Unleashing Sensor Mobility for City-scale and Fine-grained Air-Quality Monitoring with AirBERTabstractMobile air pollution sensing methods are developed to collect air quality data with higher spatial-temporal resolutions. However, existing methods cannot process the spatially mixed gas samples effectively due to the highly dynamic temporal and spatial fluctuations experienced by the sensor, leading to significant measurement deviations. We find an opportunity to tackle the problem by exploring the potential patterns from sensor measurements. In light of this, we propose MobiAir, a novel city-scale fine-grained air quality estimation system to deliver accurate mobile air quality data. First, we design AirBERT, a representation learning model to discern mixed gas concentrations. Second, we design a knowledge-informed training strategy leveraging massive unlabeled city-scale data to enhance the AirBERT performance. To ensure the practicality of MobiAir, we have invested significant efforts in implementing the software stack on our meticulously crafted Sensing Front-end, which has successfully gathered air quality data at a city-scale for more than 1200 hours. Experiments conducted on collected data show that MobiAir reduces sensing errors by 96.7% with only 44.9ms latency, outperforming the SOTA baseline by 39.5%. Yuxuan Liu 0010, Haoyang Wang 0012, Fanhang Man, Jingao Xu, Fan Dang 0001, Yunhao Liu 0001, Xiao-Ping Zhang 0002, Xinlei Chen |
MobiSys | 5 |
| 2024 | SOScheduler: Toward Proactive and Adaptive Wildfire Suppression via Multi-UAV Collaborative SchedulingabstractMulti-UAV systems have shown immense potential in handling complex tasks in large-scale, dynamic, and cold-start (i.e., limited prior knowledge) scenarios, such as wildfire suppression. Due to the dynamic and stochastic environmental conditions, the scheduling for sensing tasks (i.e., fire monitoring) and operation tasks (i.e., fire suppression) should be executed concurrently to enable real-time information collection and timely intervention of the environment. However, the planning inclinations of sensing and operation tasks are typically inconsistent and evolve over time, complicating the task of identifying the optimal strategy for each UAV. To solve this problem, this paper proposes SOScheduler, a collaborative multi-UAV scheduling framework for integrated sensing and operation in large-scale and dynamic wildfire environments. We introduce a spatio-temporal confidence-aware assessment model to dynamically and directly pinpoint locations that can optimally enhance the understanding of environmental dynamics and operational effectiveness, as well as a priority graph-instructed scalable scheduler to coordinate multi-UAV in an efficient manner. Experiments on real multi-UAV testbeds and large-scale physical feature-based simulations show that our SOScheduler reduces the fire expansion ratio by 59% and enhances the fire coverage ratio by 190% compared to state-of-the-art (SOTA) solutions. Xuecheng Chen, Zijian Xiao, Yuhan Cheng, Chen-Chun Hsia, Haoyang Wang 0012, Jingao Xu, Susu Xu, Fan Dang 0001, Xiao-Ping Zhang 0002, Yunhao Liu 0001, Xinlei Chen |
IEEE Internet Things J. | 8 |
| 2024 | StreamingTag: A Scalable Piracy Tracking Solution for Mobile Streaming ServicesabstractStreaming services have billions of mobile subscribers, yet video piracy has cost service providers billions. Digital Rights Management (DRM), however, is still far from satisfactory. Unlike DRM, which attempts to prohibit the creation of pirated copies, fingerprinting may be used to track out the source of piracy. Nevertheless, existing fingerprinting-based streaming systems are not widely used since they fail to serve numerous users. In this paper, we present the design and evaluation of StreamingTag, a scalable piracy tracing system for mobile streaming services. StreamingTag adopts a segment-level fingerprint embedding scheme to remove the need of re-embedding the fingerprint into the video for each new viewer. The key innovations of StreamingTag include a scalable and CDN-friendly delivery framework, an accurate and lightweight temporal synchronization scheme, a polarized and randomized SVD watermarking scheme, and a collusion-resistant fingerprinting scheme. Experiment results show the good QoS of StreamingTag in terms of preparation latency, bandwidth consumption, and video fidelity. Compared with existing methods, the proposed three schemes improve the re-identification accuracy by 4-49x, the watermark extraction accuracy by 2.25x at most and 1.5x on average, and the recall rate of catching colluders by 26%. Fan Dang 0001, Xinqi Jin, Qi-An Fu, Lingkun Li, Guanyan Peng, Xinlei Chen, Kebin Liu 0001, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | LSync: A Universal Timeline-Synchronizing Solution for Live StreamingabstractThe widespread use of intelligent devices and the development of mobile networks have led to the increasing popularity of live-streaming services worldwide. In addition to video and audio transmissions, a wide range of media content is also sent to audiences, such as player statistics for sports streams and subtitles for live news. However, due to the diverse transmission process between live streams and other media content, synchronizing them has become a significant challenge. Unfortunately, existing commercial solutions are not universal, requiring specific server cloud services or CDNs and limiting users’ free choices of web infrastructures. To address this issue, we propose a lightweight and universal solution called LSync, which inserts a series of audio signals containing metadata into the original audio stream. Based on the embedded metadata, a well-designed timeline-synchronizing solution helps to synchronize the information stream to the live stream. It brings no modifications to the original live broadcast process and thus fits prevalent live broadcast infrastructures. Evaluations show that the proposed solution reduces the signal processing delay to around 5% of an audio buffer length in mobile phones and ensures real-time signal processing. It achieves a channel utilization of more than 150 bps/kHz in a specific configuration, greatly outperforming recent works. Furthermore, the proposed synchronization mechanism reaches a precision of 24.84 ms on average, which matches people’s viewing habits. Fan Dang 0001, Yifan Xu 0023, Rongwu Xu, Xinlei Chen, Yunhao Liu 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2024 | BEANet: An Energy-efficient BLE Solution for High-capacity Equipment Area NetworkabstractThe digital transformation of factories has greatly increased the number of peripherals that need to connect to a network for sensing or control, resulting in a growing demand for a new network category known as the Equipment Area Network (EAN). The EAN is characterized by its cable-free, high-capacity, low-latency, and low-power features. To meet these expectations, we presentBEANet, a novel solution designed specifically for EAN that combines a two-stage synchronization mechanism with a time division protocol. We implemented the system using commercially available Bluetooth Low Energy (BLE) modules and evaluated its performance. Our results show that the network can support up to 150 peripherals with a packet reception rate of 95.4%, which is only 0.9% lower than collision-free BLE transmission. When the cycle time is set to 2 s, the average transmission latency for all peripherals is 0.1 s, while the power consumption is 18.9 μW, which is only half that of systems using LLDN or TSCH. Simulation results also demonstrate that BEANet has the potential to accommodate over 30,000 peripherals under certain configurations. Yifan Xu 0023, Fan Dang 0001, Kebin Liu 0001, Zhui Zhu, Xinlei Chen, Xu Wang 0018, Haitian Zhao |
ACM Trans. Sens. Networks | 2 |
| 2023 | FingerBLE: A Device Fingerprint Identification Scheme for BLE devicesabstractWith the increasing popularity of industrial networks, driven by the development of the Internet of Things, cloud computing, and big data, there are still security threats when it comes to using wireless communication technologies, including BLE, in these networks. This is primarily due to the heterogeneity and resource limitations of the devices. To address the issues of device cloning and enhance BLE device access authentication, a device authentication mechanism based on physical features can be employed. By leveraging the uniqueness and nonreplicability of physical attributes, such as fingerprints, this mechanism effectively mitigates attacks. Therefore, this paper proposes a BLE device authentication scheme called FingerBLE, which relies on the physical fingerprints of devices at the physical-layer. In terms of system design, this article also introduces a fingerprint database authentication mechanism that utilizes the aforementioned fingerprints for node recognition and legitimacy authentication. Experimental results demonstrate that FingerBLE is capable of successfully extracting corresponding device fingerprints and accurately identifying nodes across a wide range of tests. Xikai Sun, Fan Dang 0001 |
ICPADS | 2 |
| 2023 | A Framework for Industrial Identifier Addressing Considering Compatibility and EfficiencyabstractIndustrial Identifiers (IID), such as GS1, Handle, and OID are fundamental to device identification in growing industrial networks. Appropriate resolution and addressing methods for those identifiers are designed for wide area networks (WAN). However, due to compatibility, efficiency, and security considerations, they are not suitable for local area networks (LANs) environments. Therefore, we propose a new industrial identification framework to handle LAN scenarios by industrial address. It mainly includes the Industrial Identifier Resolution Protocol (IIRP), which combines the IIRP table lookup, the IIRP request, and the response based on the data link layer frame transmission. It is implemented as a software plug-in on LAN devices without changing any network protocol or hardware, ensuring compatibility with existing network infrastructure. Our experiments also test the efficiency of the IIRP protocol. Yifan Xu 0023, Fan Dang 0001, Jingao Xu, Xu Wang 0018, Yunhao Liu 0001 |
ICPADS | 2 |
| 2023 | DeepScheduler: Enabling Flow-Aware Scheduling in Time-Sensitive NetworkingabstractTime-Sensitive Networking (TSN) has been considered the most promising network paradigm for time-critical applications (e.g., industrial control) and traffic scheduling is the core of TSN to ensure low latency and determinism. With the demand for flexible production increases, industrial network topologies and settings change frequently due to pipeline switches. As a result, there is a pressing need for a more efficient TSN scheduling algorithm. In this paper, we propose DeepScheduler, a fast and scalable flow-aware TSN scheduler based on deep reinforcement learning. In contrast to prior work that heavily relies on expert knowledge or problem-specific assumptions, DeepScheduler automatically learns effective scheduling policies from the complex dependency among data flows. We design a scalable neural network architecture that can process arbitrary network topologies with informative representations of the problem, and decompose the problem decision space for efficient model training. In addition, we develop a suite of TSN-compatible testbeds with hardware-software co-design and DeepScheduler integration. Extensive experiments on both simulation and physical testbeds show that DeepScheduler runs >150/5 times faster and improves the schedulability by 36%/39% compared to state-of-the-art heuristic/expert-based methods. With both efficiency and effectiveness, DeepScheduler makes scheduling no longer an obstacle towards flexible manufacturing. Xiaowu He, Xiangwen Zhuge, Fan Dang 0001, Zheng Yang 0002 |
INFOCOM | 3 |
| 2023 | CaaS: Enabling Control-as-a-Service for Time-Sensitive NetworkingabstractFlexible manufacturing is one of the core goals of Industry 4.0 and brings new challenges to current industrial control systems. Our detailed field study on auto glass industry revealed that existing production lines are laborious to reconfigure, difficult to upscale, and costly to upgrade during production switching. Such inflexibility arises from the tight coupling of devices, controllers, and control tasks. In this work, we propose a new architecture for industrial control systems named Control-as-a-Service (CaaS). CaaS transfers and distributes control tasks from dedicated controllers into Time-Sensitive Networking (TSN) switches. By combining control and transmission functions in switches, CaaS virtualizes the industrial TSN network to one Programmable Logic Controller (PLC). We propose a set of techniques that realize end-to-end determinism for in-network industrial control and a joint task and traffic scheduling algorithm. We evaluate the performance of CaaS on testbeds based on real-world networked control systems. The results show that the idea of CaaS is feasible and effective, and CaaS achieves absolute packet delivery, 42-45% lower latency, and three orders of magnitude lower jitter. We believe CaaS is a meaningful step towards the distribution, virtualization, and servitization of industrial control. Zheng Yang 0002, Yi Zhao 0016, Fan Dang 0001, Xiaowu He, Jiahang Wu, Zeyu Wang 0015, Yunhao Liu 0001 |
INFOCOM | 3 |
| 2023 | LSTM-Driven Scheduling for Energy-Efficient Crop Monitoring in Wireless NetworksabstractLow-power wireless networks are widely used to monitor crop growth in smart agriculture. However, there is a growing need for more fine-grained monitoring to improve the yield of certain fruits and vegetables. The system must maintain low power consumption of peripheral devices while still providing a satisfactory quality of experience (QoE) for more frequent queries. Conventional fixed-time communication between central and peripheral devices fails to offer a well-rounded solution to this trade-off problem. To achieve a better balance, we propose an LSTM-driven transmission scheduling method. By learning the user’s past query patterns, the LSTM predicts the time of future queries initiated by the users, allowing the system to plan data transmission between the central and peripheral nodes ahead of time. Our method also predicts the future pattern of collected data to ensure that significant changes are actively recorded, even if not queried. Compared to other machine learning methods, our LSTM prediction results have a smaller error. The simulation results demonstrate that our approach can greatly improve QoE while achieving lower power consumption. Ziyue Dang, Fan Dang 0001, Yankun Yuan |
SECON | 2 |
| 2023 | A Survey on Clock Synchronization in the Industrial Internet
Fan Dang 0001, Xikai Sun, Kebin Liu 0001, Yi-Fan Xu, Yunhao Liu 0001 |
J. Comput. Sci. Technol. | 1 |
| 2022 | E-TSN: Enabling Event-triggered Critical Traffic in Time-Sensitive Networking for Industrial ApplicationsabstractTime-Sensitive Networking (TSN) is the most promising network technology for Industry 4.0. A series of IEEE standards on TSN introduce deterministic transmission into standard Ethernet. Under the current paradigm, TSN can only schedule the deterministic transmission of time-triggered critical traffic (TCT), neglecting the other type of traffic in industrial cyber physical systems, i.e., event-triggered critical traffic (ECT). So in this work, we propose a new paradigm for TSN scheduling named E-TSN, which can provide deterministic transmission for both TCT and ECT. The three techniques of E-TSN, i.e., probabilistic stream, prioritized slot sharing, and prudent reservation, enable the deterministic transmission of ECT in TSN, and at the same time, protect TCT from the impacts of ECT. We also develop and make public a TSN evaluation toolkit to fill the gap in TSN study between algorithm design and experimental validation. The experiments show that E-TSN can reduce the latency and jitter of ECT by at least an order of magnitude compared to state-of-the-art methods. By enabling reliable and timely delivery of ECT in TSN for the first time, E-TSN can broaden the application scope of TSN in industry. Yi Zhao 0016, Zheng Yang 0002, Xiaowu He, Jiahang Wu, Fan Dang 0001, Yunhao Liu 0001 |
ICDCS | 7 |
| 2022 | Optimization of Ultrasonic Respiratory Signals based on Supervised LearningabstractThere are various methods to monitor human respiration. Traditional methods of monitoring the human respiratory process often rely on complex medical equipment, which makes it difficult for users to operate. Nowadays, more and more researchers are focusing on smartphone-based systems that use mobile phones to transmit ultrasound to the chest and abdomen of the human body and use the unique reverse echo of ultrasound to collect respiratory signals. However, this method is easily disturbed by the environment, clothing, equipment, and other factors. Thus, the accuracy is unsatisfactory. This paper presents a method to optimize the respiratory signals collected by ultrasound. This method is based on supervised learning. Piezoelectric sensors and mobile phones are used to monitor human respiratory signals. A Long-Short Term Memory (LSTM) is established to learn the expression from ultrasonic signals to piezoelectric signals to improve the accuracy of signal acquisition. The results show that the model has good performance in both the time and frequency domains, achieving less than 0.05 mean absolute error (MAE) and 0.8779 intersections over union (IoU). The model can be used to optimize the ultrasound respiratory signals. Ziyue Dang, Lingkun Li, Fan Dang 0001 |
ICPADS | 4 |
| 2022 | LSync: A Universal Event-synchronizing Solution for Live StreamingabstractThe widespread of smart devices and the development of mobile networks brings the growing popularity of live streaming services worldwide. In addition to the video and audio transmission, a lot more media content is sent to the audiences as well, including player statistics for a sports stream, subtitles for living news, etc. However, due to the diverse transmission process between live streams and other media content, the synchronization of them has grown to be a great challenge. Unfortunately, the existing commercial solutions are not universal, which require specific server cloud services or CDN and limit the users’ free choices of web infrastructures. To address the issue, we propose a lightweight universal event-synchronizing solution for live streaming, called LSync, which inserts a series of audio signals containing metadata into the original audio stream. It brings no modification to the original live broadcast process and thus fits prevalent live broadcast infrastructure. Evaluations on real system show that the proposed solution reduces the signal processing delay by at most 5.62% of an audio buffer length in mobile phones and ensures real-time signal processing. It also achieves a data rate of 156.25 bps in a specific configuration and greatly outperforms recent works. Yifan Xu 0023, Fan Dang 0001, Rongwu Xu, Xinlei Chen, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2022 | StreamingTag: a scalable piracy tracking solution for mobile streaming servicesabstractStreaming services have billions of mobile subscribers, yet video piracy has cost service providers billions. Digital Rights Management (DRM), however, is still far from satisfactory. Unlike DRM, which attempts to prohibit the creation of pirated copies, fingerprinting may be used to track out the source of piracy. Nevertheless, the idea of piracy tracing is not widely used at the moment, since existing fingerprinting-based streaming systems fail to serve numerous users. In this paper, we present the design and evaluation of StreamingTag, a scalable piracy tracing system for mobile streaming services. StreamingTag adopts a segment-level fingerprint embedding scheme to remove the need of re-embedding the fingerprint into the video for each new viewer. The key innovations of StreamingTag include a scalable and CDN-friendly delivery framework, a polarized and randomized SVD watermarking scheme suitable for short segments, and a collusion-resistant fingerprinting scheme optimized for large-scale streaming services. Experiment results show the good QoS of StreamingTag in terms of preparation latency, bandwidth consumption, and video fidelity. Compared with existing SVD watermarking schemes, the proposed watermarking scheme improves the watermark extraction accuracy by 2.25x at most and 1.5x on average. Compared with existing collusion-resistant fingerprinting schemes, the proposed scheme catches more colluders and improves the recall rate by 26%. Xinqi Jin, Fan Dang 0001, Qi-An Fu, Lingkun Li, Guanyan Peng, Xinlei Chen, Kebin Liu 0001, Yunhao Liu 0001 |
MobiCom | 2 |
| 2022 | ST-ICM: spatial-temporal inference calibration model for low cost fine-grained mobile sensingabstractIn order to reduce the measurement error of low cost sensor in the real-time mobile sensing network, rendezvous calibration mechanism is widely used. To tackle the sparsity of reference data and the lack of calibration opportunities, we propose ST-ICM: a Spatial-Temporal Inference Calibration Model based on Gaussian Process Regression, assisting the calibration task by creating more calibration grids in both spatial and temporal dimensions. By using the GPR, the inferred grids generated by ST-ICM are associated with various confidence levels. Based on this property, we propose to make use of a hyperparameter, i.e., variance threshold, to balance the tradeoff between the quantity and quality of the inferred grids. Specifically, only the grids with variances below the threshold will be employed. We conducted experiments using a real-world dataset collected in Nanjing, China, to evaluate the performance of the proposed ST-ICM. The experimenal results show that our model achieves 24% improvement on error calibration compared to the baseline. Chengzhao Yu, Rongye Shi, Xinyu Liu 0003, Fan Dang 0001, Xinlei Chen |
MobiCom | 5 |
| 2022 | H-SwarmLoc: Efficient Scheduling for Localization of Heterogeneous MAV Swarm with Deep Reinforcement LearningabstractEmergency rescue scenarios are considered to be high-risk scenarios. Using a micro air vehicle (MAV) swarm to explore the environment can provide valuable environmental information. However, due to the absence of localization infrastructure and the limited on-board capabilities, it's challenging for the low-cost MAV swarm to maintain precise localization. In this paper, a collaborative localization system for the low-cost heterogeneous MAV swarm is proposed. This system takes full advantage of advanced MAV to effectively achieve accurate localization of the heterogeneous MAV swarm through collaboration. Subsequently, H-SwarmLoc, a reinforcement learning-based planning method is proposed to plan the advanced MAV with a non-myopic objective in real-time. The experimental results show that the localization performance of our method improves 40% on average compared with baselines. Haoyang Wang 0012, Xuecheng Chen, Yuhan Cheng, Chenye Wu, Fan Dang 0001, Xinlei Chen |
SenSys | 5 |
| 2021 | xRSA: Construct Larger Bits RSA on Low-Cost DevicesabstractAs the most widely applied public-key cryptographic algorithm, RSA is now integrated into many low-cost devices such as IoT devices. Due to the limited resource, most low-cost devices only ship a 2048-bit multiplier, making the longest supported private key length as 2048 bits. Unfortunately, 2048-bit RSA keys are gradually considered insecure. Utilizing the existing 2048-bit multiplier is challenging because a 4096-bit message cannot be stored in the multiplier. In this paper, we perform a thorough study of RSA and propose a new method that achieves the 4096-bit RSA cryptography with the existing hardware. We use the Montgomery modular multiplication and the Chinese Remainder Theorem to reduce the computational cost and construct the necessary components to compute the RSA private key operation. To further validate the correctness of the method and evaluate its performance, we implement this method on a micro-controller and build a testbed named CanoKey with three commonly used cryptography protocols. The result shows that our method is over 200x faster than the naive method, a.k.a., software-based big number multiplications. Fan Dang 0001, Lingkun Li |
ICPADS | 1 |
| 2021 | Long-range ambient LoRa backscatter with parallel decodingabstractLoRa backscatter is a promising technology to achieve low-power and long-distance communication for connecting millions of devices in the Internet of Things. We present P2LoRa, the first ambient LoRa backscatter system with parallel decoding and long-range communication. The high level idea of P2LoRa is to modulate data by shifting ambient LoRa packets with a small frequency. To achieve long distance communication, we enhance the SNR of the backscatter signal by concentrating leaked energy in both the frequency domain and time domain. We propose a method to accurately reconstruct and cancel the in-band excitation signal, which is orders of magnitude higher than the backscatter signal. For parallel decoding, we propose a method to cancel inter-tag interference with very low overhead and address the signal misalignment problem due to different time of flight. We prototype the P2LoRa tag with customized low-cost hardware and implement the P2LoRa gateway on USRP. Through extensive evaluations, we show that P2LoRa achieves a long communication distance of 2.2 km with ambient LoRa, and supports 101 parallel tag transmissions. Jinyan Jiang, Zhenqiang Xu, Fan Dang 0001, Jiliang Wang |
MobiCom | 3 |
| 2020 | Enabling RFID-Based Tracking for Multi-Objects with Visual Aids: A Calibration-Free SolutionabstractIdentification and tracking of multiple objects are essential in many applications. As a key enabler of automatic ID technology, RFID has got widespread adoption with item-level tagging in everyday life. However, restricted to the computation capability of passive RFID systems, locating or tracking tags has always been a challenging task. Meanwhile, as a fundamental problem in the field of computer vision, object tracking in images has progressed to a remarkable state especially with the rapid development of deep learning in the past few years. To enable lightweight tracking of a specific target, researchers try to complement computer vision to existing RFID architecture and achieves fine granularity. However, such solution requires calibration of the cameras extrinsic parameters at each new setup, which is not convenient for usage. In this work, we propose Tagview, a pervasive identifying and tracking system that can work in various settings without repetitive calibration efforts. It addresses the challenge by skillfully deploying the RFID antenna and video camera at the identical position and devising a multi-target recognition schema with only the image-level trajectory information. We have implemented Tagview with commercial RFID and camera devices and evaluated it extensively. Experimental results show that our method can archive high accuracy and robustness. Chunhui Duan, Wenlei Shi, Fan Dang 0001 |
INFOCOM | 3 |
| 2020 | Patronus: preventing unauthorized speech recordings with support for selective unscramblingabstractThe widespread adoption and ubiquity of smart devices equipped with microphones (e.g., cellphones, smartwatches, etc.) unfortunately create many significant privacy risks. In recent years, there have been several cases of people's conversations being secretly recorded, sometimes initiated by the device itself. Although some manufacturers are trying to protect users' privacy, to the best of our knowledge, there is not any effective technical solution available. In this work, we present Patronus, a system that can both prevent unauthorized devices from making secret recordings while allowing authorized devices to record conversations. Patronus prevents unauthorized speech recording by emitting what we call a scramble, a low-frequency noise generated by inaudible ultrasonic waves. The scramble prevents unauthorized recordings by leveraging the nonlinear effects of commercial off-the-shelf microphones. The frequency components of the scramble are randomly determined and connected with linear chirps, and the frequency period is fine-tuned so that the scramble pattern is hard to attack. Patronus allows authorized speech recording by secretly delivering the scramble pattern to authorized devices, which can use an adaptive filter to cancel out the scramble. We implement a prototype system and conduct comprehensive experiments. Our results show that only 19.7% of words protected by Patronus' scramble can be recognized by unauthorized devices. Furthermore, authorized recordings have 1.6x higher perceptual evaluation of speech quality (PESQ) score and, on average, 50% lower speech recognition error rates than unauthorized recordings. Lingkun Li, Manni Liu, Yuguang Yao, Fan Dang 0001, Zhichao Cao 0001, Yunhao Liu 0001 |
SenSys | 4 |
| 2019 | Understanding Fileless Attacks on Linux-based IoT Devices with HoneyCloudabstractWith the wide adoption, Linux-based IoT devices have emerged as one primary target of today's cyber attacks. Traditional malware-based attacks can quickly spread across these devices, but they are well-understood threats with effective defense techniques such as malware fingerprinting and community-based fingerprint sharing. Recently, fileless attacks---attacks that do not rely on malware files---have been increasing on Linux-based IoT devices, and posing significant threats to the security and privacy of IoT systems. Little has been known in terms of their characteristics and attack vectors, which hinders research and development efforts to defend against them. In this paper, we present our endeavor in understanding fileless attacks on Linux-based IoT devices in the wild. Over a span of twelve months, we deploy 4 hardware IoT honeypots and 108 specially designed software IoT honeypots, and successfully attract a wide variety of real-world IoT attacks. We present our measurement study on these attacks, with a focus on fileless attacks, including the prevalence, exploits, environments, and impacts. Our study further leads to multi-fold insights towards actionable defense strategies that can be adopted by IoT vendors and end users. Fan Dang 0001, Zhenhua Li 0001, Yunhao Liu 0001, Ennan Zhai, Qi Alfred Chen, Tianyin Xu, Yan Chen 0004 |
MobiSys | 1 |
| 2019 | Pricing Data Tampering in Automated Fare Collection with NFC-Equipped SmartphonesabstractAutomated Fare Collection (AFC) systems have been globally deployed for decades, particularly in the public transportation network where the transit fee is calculated based on the length of the trip (a.k.a., distance-based pricing AFC systems). Although most messages of AFC systems are insecurely transferred in plaintext, system operators did not pay much attention to this vulnerability, since the AFC network is basically isolated from the public network (e.g., the Internet)-there is no way of exploiting such a vulnerability from the outside of the AFC network. Nevertheless, in recent years, the advent of Near Field Communication (NFC)-equipped smartphones has opened up a channel to invade into the AFC network from the mobile Internet, i.e., by Host-based Card Emulation (HCE) over NFC-equipped smartphones. In this paper, we identify a novel paradigm of attacks, called LessPay, against modern distance-based pricing AFC systems, enabling users to pay much less than what they are supposed to be charged. The identified attack has two important properties: 1) it is invisible to AFC system operators because the attack never causes any inconsistency in the back-end database of the operators; and 2) it can be scalable to affect a large number of users (e.g., 10,000) by only requiring a moderate-sized AFC card pool (e.g., containing 150 cards). To evaluate the efficacy of the attack, we developed an HCE app to launch the LessPay attack; and the real-world experiments demonstrate not only the feasibility of the LessPay attack (with 97.6 percent success rate) but also its low cost in terms of bandwidth and computation. Finally, we propose, implement and evaluate four types of countermeasures, and present security analysis and comparison of these countermeasures on defending against the LessPay attack. Fan Dang 0001, Ennan Zhai, Zhenhua Li 0001, David Mohaisen, Kaigui Bian, Qingfu Wen, Mo Li 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | Large-scale invisible attack on AFC systems with NFC-equipped smartphonesabstractAutomated Fare Collection (AFC) systems have been globally deployed for decades, particularly in public transportation. Although the transaction messages of AFC systems are mostly transferred in plaintext, which is obviously insecure, system operators do not need to pay much attention to this issue, since the AFC network is well isolated from public network (e.g., the Internet). Nevertheless, in recent years, the advent of Near Field Communication (NFC)-equipped smartphones has bridged the gap between the AFC network and the Internet through Host-based Card Emulation (HCE). Motivated by this fact, we design and practice a novel paradigm of attack on modern distance-based pricing AFC systems, enabling users to pay much less than actually required. Our constructed attack has two important properties: 1) it is invisible to AFC system operators because the attack never causes any inconsistency in the backend database of the operators; and 2) it can be scalable to large number of users (e.g., 10,000) by maintaining a moderate-sized AFC card pool (e.g., containing 150 cards). Based upon this constructed attack, we developed an HCE app, named LessPay. Our real-world experiments on LessPay demonstrate not only the feasibility of our attack (with 97.6% success rate), but also its low-overhead in terms of bandwidth and computation. Fan Dang 0001, Zhenhua Li 0001, Ennan Zhai, David Mohaisen, Qingfu Wen, Mo Li 0001 |
INFOCOM | 1 |
| 2016 | A real independent centimeter-grade 3D indoor localization system on smartphoneabstractFine grained indoor localization is attractive for its wide usage in indoor navigation system, infrastructure management, and blooming augmented reality applications. In this paper, we propose a smartphone based indoor localization system called Plotter, providing a centimeter-grade localization service without any prior knowledge or additional devices. Leveraging the simultaneous localization and mapping (SLAM) technology, Plotter not only learns its relative position among surroundings, but also simultaneously constructs and updates the map of unknown area. We take advantage of a modified Kalman Filter algorithm in the system in order to eliminate unacceptable errors produced by motion sensors on smartphones. Evaluation result shows that Plotter achieves centimeter-grade accuracy, which is competitive comparing with prior works assisted by additional devices. Fan Dang 0001 |
IWCMC | 1 |
| 2015 | Anti-counterfeiting via federated RFID tags' fingerprints and geometric relationshipsabstractRFID has been widely adopted as an effective method for anti-counterfeiting. Legacy systems based on security protocol are either too heavy to be affordable by passive tags or suffering from various protocol-layer attacks, e.g. reverse engineering, cloning, side-channel. In this work, we present a novel anti-counterfeiting system, TagPrint, using COTS RFID tags and readers. Achieving a low-cost and offline genuineness validation utilizing passive tags has been a daunting task. Our system achieves these three goals by leveraging a few of federated tags' fingerprints and geometric relationships. In TagPrint, we exploit a new kind of fingerprint, called phase fingerprint, extracted from the phase value of the backscattered signal, provided by the COTS RFID readers. To further solve the separation challenge, we devise a geometric solution to validate the genuineness. We have implemented a prototype of TagPrint using COTS RFID devices. The system has been tested extensively over 6,000 tags. The results show that our new fingerprint exhibits a good fitness of uniform distribution and the system achieves a surprising Equal Error Rate of 0.1% for anti-counterfeiting. Lei Yang 0025, Fan Dang 0001, Cheng Wang 0001, Xiang-Yang Li 0001, Yunhao Liu 0001 |
INFOCOM | 3 |