Yunqi Guo

dblp:178/3594 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
15since 2021 · last 2025
0000-0002-1852-3825ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 4 first-author · 13 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2025 AquaScan: A Sonar-based Underwater Sensing System for Human Activity Monitoring
abstract
Human activity monitoring in the water is essential for pool management and drowning prevention. Existing camera-based solutions pose significant concerns about privacy and extra installation costs. Although sonars have been widely used for underwater sensing in open aquatic environments such as oceans and lakes, monitoring human activities with sonars in a pool setup is challenging. In this work, we propose AquaScan, the first scanning sonar-based underwater sensing system for human activity monitoring. To overcome the low frame rate, we propose a novel scanning strategy and apply an image reconstruction method to accelerate the scanning speed without compromising the performance of motion detection. We develop a novel signal processing pipeline based on a physical model to remove noises and localize human subjects. We extract features like motion, time, and spatial information from sonar images and develop a state-transfer-based activity recognition system to recognize five common water activities. We deployed AquaScan on three public swimming pools for a total period of 94 hours. The evaluation results show that AquaScan can successfully recognize the five activities in the water at about 91.5%.
Haozheng Hou, Sitong Cheng, Xiaoguang Zhao, Peiheng Wu, Lixing He, Yunqi Guo, Guoliang Xing, Zhenyu Yan 0002
MobiCom7
2025 Assistive AR System for Enhancing Human-Human and Human-Environment Interactions
Yunqi Guo
MobiSys1
2025 SensorMCP: A Model Context Protocol Server for Custom Sensor Tool Creation
Yunqi Guo, Guanyu Zhu, Kaiwei Liu 0001, Guoliang Xing
MobiSys1
2025 Poster: Mobile Menstrual Health Advising with Multimodal Feature Engineering
Liekang Zeng, Zhenyu Yan 0002, Yunqi Guo, Hongkai Chen 0001, Guoliang Xing
MobiSys4
2025 TaskSense: A Translation-like Approach for Tasking Heterogeneous Sensor Systems with LLMs
abstract
An increasing number of environments, such as smart homes and factories, are being equipped with multiple sensor systems to enable diverse intelligent applications. However, most existing sensor coordination systems require manually predefined rules, limiting their ability to handle flexible and complex tasks. While recent approaches leverage large language models (LLMs) to interact with external APIs, they struggle to fully understand the capabilities and data dependencies of practical sensor systems. This paper introduces TaskSense, a novel system that coordinates multiple sensor systems in response to users' complex queries. TaskSense introduces a sensor language that automatically translates the capabilities and data dependencies of sensor systems into vocabularies and grammar rules that can be understood by LLMs. It then interprets user intentions into executable task plans for sensor systems using this sensor language in combination with LLMs. Meanwhile, TaskSense checks the solvability of user queries and verifies the correctness of task plan dependencies. To further enhance robustness, TaskSense incorporates a dynamic plan execution mechanism that adjusts plans based on real-time feedback from sensor data availability, data quality and execution results. TaskSense is deployed on real-world smart home systems, utilizing six popular LLMs. The system is evaluated across 4 scenarios involving 9 types of sensor systems, over 60 APIs, 170 tasks and 5 types of data modalities. Results show that TaskSense achieves up to 2× higher planning accuracy and a 75% increase in answer accuracy using the similar amount of tokens compared with baseline approaches.
Kaiwei Liu 0001, Bufang Yang, Lilin Xu, Yunqi Guo, Guoliang Xing, Xian Shuai, Xiaozhe Ren, Xin Jiang 0002, Zhenyu Yan 0002
SenSys4
2025 Semantic information-based attention mapping network for few-shot knowledge graph completion
Xiangmao Chang, Yunqi Guo, Guoliang Xing, Yunlong Zhao 0001
Neural Networks3
2024 Improving On-Device LLMs' Sensory Understanding with Embedding Interpolations
abstract
Large Language Models (LLMs) have shown significant potential in performing inferences on various tasks using heterogeneous sensors with minimal human intervention. Despite their promise, challenges such as high inference overhead and limitations on resource-constrained edge devices remain. Additionally, model hallucinations, particularly those arising from cognitive biases when interpreting numerical data, hinder performance. This work introduces a novel technique, embedding interpolation, to enhance LLMs' understanding of sensor measurements and mitigate inference overhead on edge devices. By computing embeddings through pre-computed boundary embeddings instead of directly from the input, we improve efficiency and accuracy. The effective-ness of this approach is demonstrated through visualizations with image generation models.
Kaiyuan Hou, Yunqi Guo, Heming Fu, Hongkai Chen 0001, Zhenyu Yan 0002, Guoliang Xing, Xiaofan Jiang 0001
MobiCom2
2024 Poster Abstract: Tasking Heterogeneous Sensor Systems with LLMs
abstract
Despite the extensive use of sensors enabling intelligent applications, the complementary potential of co-existing sensor systems is often not fully utilized, limiting more advanced applications. This paper introduces a novel solution using Large Language Models (LLMs) to coordinate sensor systems for handling complex user queries. It defines a sensor language for sensor systems, including vocabulary set and grammar rules, analogous to natural language components, enabling LLMs to translate user intentions into sensor coordination plans. Preliminary results show that our approach significantly outperforms the existing solution at plan generation, execution and response generation stages.
Kaiwei Liu 0001, Bufang Yang, Lilin Xu, Yunqi Guo, Neiwen Ling, Guoliang Xing, Xian Shuai, Xiaozhe Ren, Xin Jiang 0002, Zhenyu Yan 0002
SenSys4
2024 LDRP: Device-Centric Latency Diagnostic and Reduction for Cellular Networks Without Root
abstract
We design and implementLDRP, a device-based, standard-compliant solution to latency diagnosis and reduction in mobile networks without root privilege.LDRPtakes a data-driven approach and works with a variety of latency-sensitive applications. After identifying elements in LTE uplink latency, we designLDRPthat can infer the critical parameter used in data transmission and infer them for diagnosis. In addition,LDRPdesignates small dummy messages, which precede uplink data transmissions, thus eliminating latency elements due to power-saving, scheduling, etc. It imposes proper timing control among dummy messages and data packets to handle various conflicts. We achieve the latency diagnosis and reduction without requiring root privilege and ensure the latency is no worse than the legacy LTE design. The design ofLDRPis also applicable for 5G. The evaluation shows that,LDRPinfers the latency with at most 4% error and reduces the median LTE uplink latency by a factor up to 7.4× (from 42 to 5 ms) for four apps over 4 mobile carriers.
Zhaowei Tan, Yuanjie Li, Yunqi Guo, Songwu Lu
IEEE Trans. Mob. Comput.5
2023 Sign-to-911: Emergency Call Service for Sign Language Users with Assistive AR Glasses
abstract
Sign-to-911 offers a compact mobile system solution to fast and runtime American Sign Language (ASL) and English translations. It is designated as 911 call services for ASL users with hearing disabilities upon emergencies. It enables bidirectional translations of ASL-to-English and English-to-ASL. The signer wears the AR glasses, runs Sign-to-911 on his/her smartphone and glasses, and interacts with a 911 operator. The design of Sign-to-911 departs from the popular deep learning based solution paradigm, and adopts simpler traditional AI/machine learning (ML) models. The key is to exploit ASL linguistic features to simplify the model structures and improve accuracy and speed. It further leverages recent component solutions from graphics, vision, natural language processing, and AI/ML. Our evaluation with six ASL signers and 911 call records has confirmed its viability.
Yunqi Guo, Boyan Ding, Congkai Tan, Weichong Ling, Zhaowei Tan, Jennifer Miyaki, Hongzhe Du, Songwu Lu
MobiCom1
2022 Breaking Cellular IoT with Forged Data-plane Signaling: Attacks and Countermeasure
abstract
We devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (a.k.a. both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. The attacker can forge both uplink and downlink data-plane signaling messages that pass the current security checks used by the receiver. With the capability of forging messages, the attacker can launch attacks that exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, connection reset, and multicast disabling. Our testbed evaluation and operational network validation have confirmed the attack viability. To combat the threat, we further propose a new defense solution within the 3GPP C-IoT standard framework. It leverages the synchronized timer clock information to protect the data-plane signaling messages with low overhead.
Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu
ACM Trans. Sens. Networks4
2021 On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative Impact
abstract
This paper studies the feasibility of key reinstallation attacks in the 4G LTE network.It is well known that LTE uses session keys for confidentiality and integrity protection of its control-plane signaling packets.However, if the keys are not updated and counters are reset, key reinstallation attacks may arise.In this paper, we show that several design choices in the current LTE security setup are vulnerable to key reinstallation attacks.Specifically, on the control plane, the LTE security association setup procedures, which establish security between the device and the network, are disconnected.The keys are installed through one procedure, whereas their associated parameters (such as uplink and downlink counters) are reset through another different procedure.The adversary can thus exploit the disjoint security setup procedures, and launch the key stream reuse attacks.He consequently breaks message encryption, when he tricks the victim to use the same pair of keys and counter value to encrypt multiple messages.This control-plane attack hijacks the location update procedure, thus rendering the device to be unreachable from the Internet.Moreover, it may also deregister the victim from the LTE network.We have confirmed our findings with two major US operators, and found that such attacks can be launched with software-defined radio devices that cost about $299.We further propose remedies to defend against such threats.
Muhammad Taqi Raza, Yunqi Guo, Songwu Lu, Fatima M. Anwar 0001
ACSAC2
2021 Experience: a five-year retrospective of MobileInsight
abstract
This paper reports our five-year lessons of developing and using MobileInsight, an open-source community tool to enable software-defined full-stack, runtime mobile network analytics inside our phones. We present how MobileInsight evolves from a simple monitor to a community toolset with cross-layer analytics, energy-efficient real-time user-plane analytics, and extensible user-friendly analytics at the control and user planes. These features are enabled by various novel techniques, including cross-layer state machine tracking, missing data inference, and domain-specific cross-layer sampling. Their powerfulness is exemplified with a 5-year longitudinal study of operational mobile network latency using a 6.4TB dataset with 6.1 billion over-the-air messages. We further share lessons and insights of using MobileInsight by the community, as well as our visions of MobileInsight's past, present, and future.
Yuanjie Li, Chunyi Peng 0001, Zhehui Zhang, Zhaowei Tan, Haotian Deng 0001, Qianru Li 0002, Yunqi Guo, Kai Ling, Boyan Ding, Hewu Li, Songwu Lu
MobiCom8
2021 Data-plane signaling in cellular IoT: attacks and defense
abstract
In this paper, we devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (aka both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. Such attacks exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, and connection reset. Our testbed evaluation and operational network validation have confirmed the viability. We further propose a new defense solution within the 3GPP C-IoT standard framework.
Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu
MobiCom4
2021 SecureSIM: rethinking authentication and access control for SIM/eSIM
abstract
The SIM/eSIM card stores critical information for a mobile user to access the 4G/5G network. In this work, we uncover three vulnerabilities of the current SIM practice. We show that the PIN-based access control may expose the in-SIM data to an adversary through both hardware and software. Once exposed, such in-SIM information can be used to reconstruct various keys used for device authentication, data encryption, etc. They thus enable a number of attacks, including traffic eavesdropping, man-in-the-middle attack, impersonation, etc. The fundamental problem is that, the current SIM design does not offer proper authentication and fine-grained access control to hundreds of in-SIM files for various in-card applets and off-card units. We next propose a new solution that offers both authentication and fine-grained access control. Our implementation and evaluation have confirmed the viability of our proposal.
Boyan Ding, Yunqi Guo, Zhaowei Tan, Songwu Lu
MobiCom3
2020 Towards Model-Centric Security for IoT Systems
abstract
In this paper, we make a case for a novel model-centric security approach to the IoT application systems. We thus depart from the popular device-centric and data-centric schemes. Our proposal is based on the premise that the trained model, rather than the fine-grained input and output data streams, plays the pivotal role in many IoT application systems. We thus seek to obfuscate the model directly, but not the individual data items or sensory data streams. We present our initial design of sampling-based model obfuscation. Both evaluations and analysis have partially confirmed our design to date.
Yunqi Guo, Zhaowei Tan, Songwu Lu
ICCCN1