Zhaowei Tan

dblp:177/7011 · DBLP profile ↗
← Back
26ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0002-0118-7917ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 21 · 5 first-author · 17 since 2021Systems, architecture and hardware · 2 · 1 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
Xin'an Zhou, Juefei Pu, Zhutian Liu 0002, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy, Mathy Vanhoef
NDSS5
2025 Automated Model-Based Fuzzing for 5G O-RAN
abstract
The evolution of 5G and future-G technologies has led to the development of an open, distributed, and multi-vendor architecture known as Open Radio Access Network (O-RAN). While O-RAN offers greater flexibility and stimulates innovation, it also introduces potential issues such as bugs, inconsistencies, and vulnerabilities. In this paper, we present a novel model-based fuzzing system, ARCANE, to address these challenges. Unlike existing fuzzing techniques that struggle with the complexity and dynamism of O-RAN, ARCANE distinguishes itself by employing a smart, model-based approach. It first analyzes O-RAN specifications using a Large Language Model (LLM) and incorporates a unique method that integrates passive model learning to refine the model. With this refined model, ARCANE designs an O-RAN-aware, model-based fuzzing scheme that maintains high efficiency by adhering to O-RAN's specific semantics and syntax. We implement ARCANE and evaluate it on the OAI5G. It finds 9 root bugs from three categories, all having serious security implications. ARCANE has shown superior efficiency and coverage compared to state-of-the-arts.
Sixu Tan, Zhutian Liu 0002, Zhaowei Tan
MobiCom5
2025 Poster Abstract: SEE-V2X: Empirical Evaluation of C-V2X Direct Communication in Real-World Scenarios
abstract
Cellular-vehicle-to-everything (C-V2X) technology has been increasingly adopted by the research community, automotive industry, and government agencies as the next key technology to enhance transportation safety and efficiency. Recent years have also witnessed emerging C-V2X-based applications, connecting sensors on vehicle (V2V), from infrastructure (V2I), and carried by pedestrians (V2P), to enable novel capabilities such as cooperative perception, sustainable transportation, and remote operations. While researchers have made successful strides in simulating these promising applications, the disconnect with real-world C-V2X performance often renders ungrounded assumptions, resulting in huge barriers towards deployment. In this poster, we conduct an application driven C-V2X network measurement using commercial off-the-shelf standard compliant C-V2X radios. Emulating the traffic patterns of popular C-V2X applications, we investigate the gap between the demand and reality.
Ruoshen Mo, Zhaowei Tan, Hang Qiu 0001
SenSys3
2025 SEE-V2X: C-V2X Direct Communication Dataset: An Application-Centric Approach
abstract
Cellular-vehicle-to-everything (C-V2X) technology has been increasingly adopted by the research community, automotive industry, and government agencies as the next key technology to enhance transportation safety and efficiency. Recent years have also witnessed emerging C-V2X-based applications, connecting sensors on vehicles (V2V), from the infrastructure (V2I), and carried by pedestrians (V2P), to enable novel capabilities such as cooperative perception, sustainable transportation, and remote operations. While researchers have made successful strides in simulating these promising applications, the disconnect with real-world C-V2X performance often renders ungrounded assumptions, resulting in huge barriers towards deployment. In this paper, we aim to build and release a real-world C-V2X dataset, SEE-V2X, using commercial off-the-shelf standard compliant C-V2X radios. Emulating the traffic patterns of popular C-V2X applications, we investigate the gap between the demand and reality. Beyond throughput and latency, SEE-V2X contains cross-layer details, offers insight into the resource scheduling and allocation mechanism in various situations, and reveals the impact of nuanced configuration. Our preliminary analysis shows that severe packet collision and jitter can easily happen, indicating opportunities to avoid performance degradation with careful and subtle configuration. SEE-V2X dataset and the analysis tools are available at https://cisl.ucr.edu/SEE-V2X/.
Ruoshen Mo, Zhaowei Tan, Hang Qiu 0001
SenSys3
2025 Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured Firewalls
abstract
Public IP addresses can expose devices and services to risks such as port scanning and subsequent cyberattacks. Therefore, firewalls are extensively deployed and play a critical role in enforcing security policies and preventing unauthorized access. However, vulnerabilities can allow firewalls to be by-passed, effectively nullifying the protection. In this paper, we present the first comprehensive study of a previously understudied attack surface: firewall misconfigurations that inadvertently expose protected services to the public Internet. Specifically, we demonstrate flawed firewall rules that allow inbound connections from special source ports to bypass the firewall, and explore the prevalence and security implications thereof. To this end, we scan the IPv4 space for 15 commonly high-risk TCP and UDP services from two special source ports. Our measurement reveals the widespread existence of such misconfigurations and identified over 2,000,000 otherwise unreachable services spread over 15,837 autonomous systems, expanding the “observable Internet” for various protocols by up to 12.60%. More importantly, the affected services generally exhibit higher security risks than the publicly accessible ones, like outdated software versions and weak configurations. Despite the severity of this vulnerability, our honeypot experiment provides little evidence of active exploitation in the wild. Our findings offer insights for better security posture and network administration, helping researchers and organizations anticipate and mitigate potential cyber threats emanating from the Internet.
Qing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian, Srikanth V. Krishnamurthy
SP3
2024 M2HO: Mitigating the Adverse Effects of 5G Handovers on TCP
abstract
The advent of 5G promises high bandwidth with the introduction of mmWave technology recently, paving the way for throughput-sensitive applications. However, our measurements in commercial 5G networks show that frequent handovers in 5G, due to physical limitations of mmWave cells, introduce significant under-utilization of the available bandwidth. By analyzing 5G link-layer and TCP traces, we uncover that improper interactions between these two layers causes multiple inefficiencies during handovers. To mitigate these, we propose M2HO, a novel device-centric solution that can predict and recognize different stages of a handover and perform state-dependent mitigation to markedly improve throughput. M2HO is transparent to the firmware, base stations, servers, and applications. We implement M2HO and our extensive evaluations validate that it yields significant improvements in TCP throughput with frequent handovers.
Zhutian Liu 0002, Qing Deng, Zhaowei Tan, Zhiyun Qian, Xinyu Zhang 0003, Ananthram Swami, Srikanth V. Krishnamurthy
MobiCom3
2024 LDRP: Device-Centric Latency Diagnostic and Reduction for Cellular Networks Without Root
abstract
We design and implementLDRP, a device-based, standard-compliant solution to latency diagnosis and reduction in mobile networks without root privilege.LDRPtakes a data-driven approach and works with a variety of latency-sensitive applications. After identifying elements in LTE uplink latency, we designLDRPthat can infer the critical parameter used in data transmission and infer them for diagnosis. In addition,LDRPdesignates small dummy messages, which precede uplink data transmissions, thus eliminating latency elements due to power-saving, scheduling, etc. It imposes proper timing control among dummy messages and data packets to handle various conflicts. We achieve the latency diagnosis and reduction without requiring root privilege and ensure the latency is no worse than the legacy LTE design. The design ofLDRPis also applicable for 5G. The evaluation shows that,LDRPinfers the latency with at most 4% error and reduces the median LTE uplink latency by a factor up to 7.4× (from 42 to 5 ms) for four apps over 4 mobile carriers.
Zhaowei Tan, Yuanjie Li, Yunqi Guo, Songwu Lu
IEEE Trans. Mob. Comput.1
2024 Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure Designs
abstract
Cellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities.
Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
IEEE/ACM Trans. Netw.11
2023 Sign-to-911: Emergency Call Service for Sign Language Users with Assistive AR Glasses
abstract
Sign-to-911 offers a compact mobile system solution to fast and runtime American Sign Language (ASL) and English translations. It is designated as 911 call services for ASL users with hearing disabilities upon emergencies. It enables bidirectional translations of ASL-to-English and English-to-ASL. The signer wears the AR glasses, runs Sign-to-911 on his/her smartphone and glasses, and interacts with a 911 operator. The design of Sign-to-911 departs from the popular deep learning based solution paradigm, and adopts simpler traditional AI/machine learning (ML) models. The key is to exploit ASL linguistic features to simplify the model structures and improve accuracy and speed. It further leverages recent component solutions from graphics, vision, natural language processing, and AI/ML. Our evaluation with six ASL signers and 911 call records has confirmed its viability.
Yunqi Guo, Boyan Ding, Congkai Tan, Weichong Ling, Zhaowei Tan, Jennifer Miyaki, Hongzhe Du, Songwu Lu
MobiCom6
2023 CA++: Enhancing Carrier Aggregation Beyond 5G
abstract
Carrier aggregation (CA) is an important component technology in 5G and beyond. It aggregates multiple spectrum fragments to serve a mobile device. However, the current CA suffers under both high mobility and increased spectrum space. The limitations are rooted in its sequential, cell-by-cell operations. In this work, we propose CA++, which departs from the current paradigm and explores a group-based design scheme. We thus propose new algorithms that enable concurrent channel inference by measuring one or few cells but inferring all, while minimizing measurement cost via set cover approximations. Our evaluations have confirmed the effectiveness of CA++. Our solution can also be adapted to fit in the current 5G OFDM PHY and the 3GPP framework.
Qianru Li 0002, Zhehui Zhang, Yanbing Liu 0002, Zhaowei Tan, Chunyi Peng 0001, Songwu Lu
MobiCom4
2023 CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data Plane
Zhaowei Tan, Boyan Ding, Songwu Lu
NSDI1
2022 Uncovering insecure designs of cellular emergency services (911)
abstract
Cellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities.
Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
MobiCom10
2022 SEED: a SIM-based solution to 5G failures
abstract
Failures in 5G mobile networks are becoming the norm with the ongoing global rollout. If left unattended, they affect mobile user experiences and the proper functioning of applications. In this work, we describe SEED, which offers a novel SIM-based solution to 5G failure diagnosis and handling. SEED infers failure causes by exploiting current standardized 5G error codes and decision-tree/online learning algorithms. It further takes corresponding multi-tier reset/redo actions (reset protocol operations, refresh outdated configurations, reload profiles, etc.) once the failure cause is inferred. SEED takes the operator's perspective in its design for fast deployment. SEED design works within the 5G standard framework and does not require changes on the device firmware or infrastructure hardware. Our evaluation has confirmed the viability of SEED.
Zhaowei Tan, Zhehui Zhang, Songwu Lu
SIGCOMM2
2022 Breaking Cellular IoT with Forged Data-plane Signaling: Attacks and Countermeasure
abstract
We devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (a.k.a. both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. The attacker can forge both uplink and downlink data-plane signaling messages that pass the current security checks used by the receiver. With the capability of forging messages, the attacker can launch attacks that exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, connection reset, and multicast disabling. Our testbed evaluation and operational network validation have confirmed the attack viability. To combat the threat, we further propose a new defense solution within the 3GPP C-IoT standard framework. It leverages the synchronized timer clock information to protect the data-plane signaling messages with low overhead.
Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu
ACM Trans. Sens. Networks1
2021 Zeus: locality-aware distributed transactions
abstract
State-of-the-art distributed in-memory datastores (FaRM, FaSST, DrTM) provide strongly-consistent distributed transactions with high performance and availability. Transactions in those systems are fully general; they can atomically manipulate any set of objects in the store, regardless of their location. To achieve this, these systems use complex distributed transactional protocols. Meanwhile, many workloads have a high degree of locality. For such workloads, distributed transactions are an overkill as most operations only access objects located on the same server - if sharded appropriately.
Antonios Katsarakis, Yijun Ma, Zhaowei Tan, Andrew Bainbridge, Matthew Balkwill, Aleksandar Dragojevic, Boris Grot, Bozidar Radunovic, Yongguang Zhang
EuroSys3
2021 Sonica: an open-source NB-IoT prototyping platform
abstract
In this demo, we describe Sonica, an open-source NB-IoT prototype platform. Both radio access and core network components are designed and implemented with the features and characteristics of NB-IoT into account. With its eNB and core network (EPC) components, Sonica can function as an NB-IoT testbed which interacts with commercial off-the-shelf NB-IoT devices. Moreover, Sonica provides a flexible framework that supports quick prototyping for MAC/PHY layers.
Boyan Ding, Zhaowei Tan, Songwu Lu
MobiCom3
2021 Experience: a five-year retrospective of MobileInsight
abstract
This paper reports our five-year lessons of developing and using MobileInsight, an open-source community tool to enable software-defined full-stack, runtime mobile network analytics inside our phones. We present how MobileInsight evolves from a simple monitor to a community toolset with cross-layer analytics, energy-efficient real-time user-plane analytics, and extensible user-friendly analytics at the control and user planes. These features are enabled by various novel techniques, including cross-layer state machine tracking, missing data inference, and domain-specific cross-layer sampling. Their powerfulness is exemplified with a 5-year longitudinal study of operational mobile network latency using a 6.4TB dataset with 6.1 billion over-the-air messages. We further share lessons and insights of using MobileInsight by the community, as well as our visions of MobileInsight's past, present, and future.
Yuanjie Li, Chunyi Peng 0001, Zhehui Zhang, Zhaowei Tan, Haotian Deng 0001, Qianru Li 0002, Yunqi Guo, Kai Ling, Boyan Ding, Hewu Li, Songwu Lu
MobiCom4
2021 Data-plane signaling in cellular IoT: attacks and defense
abstract
In this paper, we devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (aka both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. Such attacks exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, and connection reset. Our testbed evaluation and operational network validation have confirmed the viability. We further propose a new defense solution within the 3GPP C-IoT standard framework.
Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu
MobiCom1
2021 SecureSIM: rethinking authentication and access control for SIM/eSIM
abstract
The SIM/eSIM card stores critical information for a mobile user to access the 4G/5G network. In this work, we uncover three vulnerabilities of the current SIM practice. We show that the PIN-based access control may expose the in-SIM data to an adversary through both hardware and software. Once exposed, such in-SIM information can be used to reconstruct various keys used for device authentication, data encryption, etc. They thus enable a number of attacks, including traffic eavesdropping, man-in-the-middle attack, impersonation, etc. The fundamental problem is that, the current SIM design does not offer proper authentication and fine-grained access control to hundreds of in-SIM files for various in-card applets and off-card units. We next propose a new solution that offers both authentication and fine-grained access control. Our implementation and evaluation have confirmed the viability of our proposal.
Boyan Ding, Yunqi Guo, Zhaowei Tan, Songwu Lu
MobiCom4
2021 Device-Based LTE Latency Reduction at the Application Layer
Zhaowei Tan, Yuanjie Li, Songwu Lu
NSDI1
2020 Towards Model-Centric Security for IoT Systems
abstract
In this paper, we make a case for a novel model-centric security approach to the IoT application systems. We thus depart from the popular device-centric and data-centric schemes. Our proposal is based on the premise that the trained model, rather than the fine-grained input and output data streams, plays the pivotal role in many IoT application systems. We thus seek to obfuscate the model directly, but not the individual data items or sensory data streams. We present our initial design of sampling-based model obfuscation. Both evaluations and analysis have partially confirmed our design to date.
Yunqi Guo, Zhaowei Tan, Songwu Lu
ICCCN2
2018 A Machine Learning Based Approach to Mobile Network Analysis
abstract
In this paper, we present our recent work in progress on 4G mobile network analysis. In order to provide an in-depth study on the closed network operations, we advocate a novel approach via two-level, device-centric machine learning that can open up the system behaviors and facilitate fine-grained analysis . We describe our proposed approach, and use the latency analysis on two popular mobile apps (Web browsing and Instant Messaging) to illustrate how our scheme works. We further preliminary results and discuss the open issues.
Zengwen Yuan, Yuanjie Li, Chunyi Peng 0001, Songwu Lu, Haotian Deng 0001, Zhaowei Tan, Muhammad Taqi Raza
ICCCN6
2018 D2-Tree: A Distributed Double-Layer Namespace Tree Partition Scheme for Metadata Management in Large-Scale Storage Systems
abstract
The behavior of metadata server (MDS) cluster is critically important to the overall performance of today's petabyte-scale or even exabyte-scale distributed file system. How to maintain a high level of both system locality and load balancing is a significant challenge to MDS clusters. However, traditional metadata management schemes, including hash-based mapping and subtree partitioning, have severe bias on either system locality or load balancing. In this paper, we propose D2-Tree, a distributed double-layer namespace tree partition scheme, for metadata management in large-scale storage systems. The innovative idea is to design a greedy strategy to split the namespace tree into global layer and local layer subtrees, of which global layer is replicated to maintain load balancing and the lower-half subtrees are allocated separately to MDS's by a mirror division method to preserve locality. Both theoretical analysis based on empirical cumulative distribution and extensive experiments are provided to validate the efficiency of D2-Tree. Experiments using actual trace data on Amazon EC2 also exhibit the superior performance of D2-Tree compared with much previous literature.
Xinjian Luo, Xiaofeng Gao 0001, Zhaowei Tan, Xiaochun Yang 0001, Guihai Chen
ICDCS3
2017 Towards Automated Intelligence in 5G Systems
abstract
In this paper, we call for a paradigm shift away from the wireless-access focused research efforts on 5G networked systems. We believe that the architectural limitations should share equal blame on issues of performance, reliability, and security. We thus identify architectural weakness on both sides of the mobile clients and the 4G network infrastructure. Our recent findings show that, contrary to commonly held perceptions, many design and operational issues arise not due to poor wireless link qualities. Instead, they are rooted in such architectural downsides. To address these issues, we further propose a new approach of enabling automated intelligence inside the 4G/5G network systems. We next describe our ongoing efforts along two dimensions: empowering date-driven smart clients and constructing verifiable network infrastructure. We report some early results and discuss possible next steps.
Haotian Deng 0001, Qianru Li 0002, Yuanjie Li, Songwu Lu, Chunyi Peng 0001, Muhammad Taqi Raza, Zhaowei Tan, Zengwen Yuan, Zhehui Zhang
ICCCN7
2017 The Tick Programmable Low-Latency SDR System
abstract
Tick is a new SDR system that provides programmability and ensures low latency at both PHY and MAC. It supports modular design and element-based programming, similar to the Click router framework [23]. It uses an accelerator-rich architecture, where an embedded processor executes control flows and handles various MAC events. User-defined accelerators offload those tasks, which are either computation-intensive or communication-heavy, or require fine-grained timing control, from the processor, and accelerate them in hardware. Tick applies a number of hardware and software co-design techniques to ensure low latency, including multi-clock-domain pipelining, field-based processing pipeline, separation of data and control flows, etc. We have implemented Tick and validated its effectiveness through extensive evaluations as well as two prototypes of 802.11ac SISO/MIMO and 802.11a/g full-duplex.
Tao Wang 0004, Zengwen Yuan, Chunyi Peng 0001, Zhaowei Tan, Boyan Ding, Yuanjie Li, Jun Liu 0063, Songwu Lu
MobiCom6
2016 STH-Bass: A Spatial-Temporal Heterogeneous Bass Model to Predict Single-Tweet Popularity
Zhaowei Tan, Xiaofeng Gao 0001, Shaojie Tang 0001, Guihai Chen
DASFAA (2)2