Songfan Li

dblp:181/4238 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
18since 2021 · last 2026
0000-0002-4054-6513ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 7 first-author · 13 since 2021Systems, architecture and hardware · 4 · 3 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TriLoRa: Improving LoRa PHY Data Rate for High-Density LoRaWAN
abstract
As LoRaWAN evolves toward high-density deployments, the rigid, low-data-rate nature of its physical layer becomes a critical bottleneck. This paper introduces TriLoRa, a novel PHY design that significantly enhances throughput via time-domain symbol superposition. The core innovation is Triangle-Chirp Modulation (TCM), which exploits the symmetric spectral features of triangle waveforms to resolve the inherent time-frequency ambiguity of standard linear chirps. By decoupling time delays from frequency encoding, TriLoRa allows multiple symbols to be densely superimposed and reliably distinguished within a single symbol window, effectively converting excess Signal-to-Noise Ratio (SNR) into parallel transmission capacity. Centered on this, we design a hierarchical demodulation architecture and a fine-grained rate adaptation mechanism that maintain robustness even in negative SNR regimes. Experimental results demonstrate that TriLoRa improves point-to-point data rates by up to 30×. Furthermore, trace-driven evaluations based on a commercial-scale campus network reveal a 3.96 × gain in aggregate network capacity.
Songfan Li
ICDCS3
2026 μMan: Towards Device-Agnostic Power Management for Battery-free IoT
abstract
Power management, while indispensable for the working of battery-free devices on fragile ambient energy, unfortunately, also entails excessive workloads that consume the scarce harvested energy. Existing efforts aimed at addressing this typically manage to tackle only a fraction of the challenges, leaving power management as a painful Achilles’ heel for battery-free devices. In this paper, we systematically analyze the full-flow of power management and propose μ Man, a painless architecture with no extra workload on battery-free devices. That is, we shift the entire workload of power management from the resource-constrained battery-free devices to the resource-rich gateway. For this goal, we design a near-zero-power sampling-free monitoring mechanism to transparently piggyback the power status of the device directly onto the uplink signal waveform. Based on these real-time statuses, the gateway can take over the required computation and issue the resultant energy allocations back to devices. The design is fully transparent to the devices, and the devices can even remain in deep sleep during the whole process to minimize energy consumption. The experiments show that μ Man can reduce the energy consumption of power management by 97.2%, improve the power efficiency by 53%, and reduce the minimum energy requirements for the device start-up by 5.8 ×.
Chong Zhang 0017, Han Wang 0032, Qianhe Meng, Yize Zhao, Songfan Li, Zetao Gao, Li Lu 0001, Hongzi Zhu
SenSys6
2026 Remote Intermittency Control for RF-Powered Devices via Backscatter Communication
abstract
RF energy harvesting devices operate intermittently due to the dynamic nature of harvested energy. To prevent power outages and ensure reliability, intermittency control needs to track the harvested voltage signals and adjusting the system states (e.g., active or sleep) accordingly. However, tracking the harvested energy involves power-starving operations such as using analog-to-digital converter (ADC) and micro-controller (MCU) to sample to the harvested voltage. In this paper, we propose a novel approach to address this problem by shifting energy tracking from the device to the gateway side. The gateway uses ultra-low power backscatter communication to remotely sense the power harvesting state of the device, and then opportunistically controls device's system states via downlink transmission. The key challenge is that many RF-powered devices like RFID tags already utilize backscatter communication for their existing communication needs. Sensing the energy state via backscatter could lead to collisions with ongoing communications. To address this challenge, we enable the gateway to use existing backscatter communication for energy sensing. We leverage a physical channel attenuation model for backscatter communication, allowing the gateway to infer the power harvesting state of the device using signal strength information from the gateway's transmission and reception. We also leverage the backscatter reply to build the multipath profile that calibrates the power harvesting estimation in multipath-rich scenarios. We instantiate our approach in a commercial RFID system and demonstrate significant improvements of power efficiency.
Songfan Li, YanXu Bai, Li Lu 0001
IEEE Trans. Mob. Comput.1
2026 Bringing LoRa Downlink to Backscatter Devices
abstract
Recent advances in backscatter communication have exhibited great advantages on uplink, both in power consumption and communication performance. However, their downlink tends to lag far behind due to stringent on-device power constraints. This paper presentsSisyphus, a novel communication paradigm designed to empower backscatter devices with LoRa downlink. To achieve this, we propose a novel receiver design for passive coherent demodulation of LoRa. In this design, we creatively couple LoRa’s down-conversion with de-chirping (dc2), leveraging the processing gain brought by chirp spread spectrum (CSS) modulation to boost communication range without the need for additional power supply. Moreover, we exploit the cyclical time-frequency feature intrinsic to LoRa for demodulation, and a low-power analog-digital signal processing circuit with negligible power is devised to replace the existing power-intensive sampling and costly digital computation. We prototype Sisyphus for proof-of-concept, and comprehensive experimental results demonstrate that Sisyphus can achieve significant power savings compared to legacy LoRa receiver while retaining the anti-interference ability of legacy LoRa. We envision that the design of Sisyphus can unlock the potential for broader applications of LoRa-based backscatter devices.
Han Wang 0032, Yihang Song, Qianhe Meng, Chong Zhang 0017, Songfan Li, Shuwei Wu, Li Lu 0001
IEEE Trans. Netw.5
2025 Hedgehog: Pushing the Range Limits of Ultrasonic Microphone Jammers
abstract
Ultrasonic microphone jammers (UMJs) use ultrasonic waves to interfere with concealed microphone recorders, offering significant values in confidential meetings and secret talks. Existing UMJs, however, performs in a short range of typically 2 m, which remains a huge gap to practical applications. The key challenge lies in the fact that the ultrasonic signal will produce audible sounds during its transmission, caused by nonlinear distortion of power amplifiers and loudspeakers in the transmission chain of the UMJ. In this paper, we propose Hedgehog, a room-scale ultrasonic jammer design, which enhances the jamming range through two key methods. First, it corrects nonlinear distortion by modeling the transmission chain and applying digital pre-distortion. Furthermore, it redesigns the jamming signal to improve its effectiveness by not only reducing the signal-to-noise ratio (SNR) but also by suppressing the semantic information in human speech. The experimental results show that Hedgehog achieved a word error rate (WER) of over 95% at 8 meters and over 80% at 10 meters, which is a 4 times increase in jamming distance compared to existing solutions.
Mengchen Teng, Songfan Li, Xiandong Shao, Chong Zhang 0017, Li Lu 0001
MobiCom4
2025 Demo: AeroRelief: UAV-based Emergency Rescue for Time-Critical Missions
abstract
We present AeroRelief, an autonomous UAV first-responder system for rapid delivery of critical medical supplies in hard-to-reach areas. Integrating AI-assisted dispatch, real-time path planning, and a winch-based payload mechanism, AeroRelief responds swiftly to emergencies with minimal human intervention. The system uses a long-range LoRa command link for robust communication and delivers supplies mid-air without landing. Our demonstration showcases the complete workflow—from emergency identification to UAV deployment—highlighting AeroRelief's potential to accelerate rescue missions and enhance survival outcomes in remote settings.
Chun Ming Wu, Songfan Li, Zhaoteng Ye, Tsz Ho Fan, Lai Yin Garmisch Wong, Mo Li 0001
MobiCom2
2025 LoRaMirror: Illuminating Shadowed Spots in Urban LPWAN With Reflective Smart Surfaces
abstract
The deployment of low-power wide-area networks (LPWAN) in urban environments faces a critical challenge with signal blockage caused by dense obstacles like buildings, resulting inblind spotswhere end nodes have difficulty reaching the gateway. This paper proposes LoRaMirror, a reflective smart surface design, to essentially eliminate these blind spots and improve overall communication in urban LoRaWAN. LoRaMirror is different from existing smart surface designs, as it addresses unprecedented challenges posed by LPWAN's unique application scenario of extremely long communication distances, extremely low data transmission rates, and extremely wide coverage. LoRaMirror is prototyped with a 16-antenna multi-layer array and the experimental results show significant performance gains in real world practice.
Songfan Li, Jansen Christian Liando, Li Lu 0001, Mo Li 0001
IEEE Trans. Mob. Comput.1
2025 Embedding Chips Over the Air: Rethink IoT Architecture for Ubiquitous Sensing
abstract
Large-scale IoT sensor deployment calls for inexpensive, low-power sensor nodes that still perform long-range, large-scale networking at the system level. However, current sensor nodes are constructed according to the 'one-size-fits-all’ embedded design, where the processor and RF transceiver are indispensable but underutilized in low-duty cycles, resulting in overwhelmingly significant unit price and run-time power. In this paper, we propose a novel processor-sharing IoT architecture that converts the vast majority of sensor nodes from embedded computers to low-end RF peripherals. The conventional full-fledged sensor nodes are smashed into the air, and the scattered chips are scaled well with negligible overheads through a virtual I$^{2}$C bus calledRFBus. Specifically, RFBus interface is designed to be backward compatible with the I$^{2}$C bus interface, and thus, RFBus network inherits versatile link layer services transparently from the well-established I$^{2}$C link layer protocol. We design RFBus with joint consideration of system-level performance and deployment costs and evaluate the prototypes both indoors and outdoors. The result indicates that the proposed architecture achieves 6.09 × (indoor) and 6.69 × (outdoor) energy saving and reduces the unit price of sensor nodes by 23.5% (indoor) and 33.5% (outdoor).
Qianhe Meng, Han Wang 0032, Chong Zhang 0017, Yihang Song, Songfan Li, Li Lu 0001, Hongzi Zhu
IEEE Trans. Mob. Comput.5
2024 Face Recognition In Harsh Conditions: An Acoustic Based Approach
abstract
The accuracy of vision-based face recognition suffers in challenging scenarios, such as foggy or smoky weather, poor lighting, and blockage by objects like facial masks. This paper proposes an acoustic-based facial recognition system based on acoustic facial spectrum - a novel acoustic representation of human faces in 3D space. Specifically, we divide the 3D space into cubes and profile the distribution of the acoustic signal reflected by the human face inside each cube. Generating such a per-cube acoustic profile is challenging in relating each reflected signal path back to the physical location of its reflecting cube. To address the challenge, we propose a novel multipath resolving algorithm that is capable of distinguishing signal reflection happened within different cube. Based on the facial spectrum, we propose a discriminator-recognizer network that can robustly recognize human faces under varying face-microphone distances or even in presence of facial mask blockage. Extensive experimental results demonstrate that the proposed system achieves over 95% average recognition accuracy for cases with and without mask blockage. The research artifacts accompanying this paper are available via DOI: 10.5281/zenodo.11094213.
Panrong Tong, Songfan Li, Yaxiong Xie, Mo Li 0001
MobiSys3
2024 Processor-Sharing Internet of Things Architecture for Large-scale Deployment
abstract
Large-scale IoT sensor deployment calls for inexpensive, low-power sensor nodes that still perform long-range, large-scale networking at the system level. However, current sensor nodes are constructed according to the `one-size-fits-all' embedded design, where the processor and RF transceiver are indispensable but underutilized in low-duty cycles, resulting in overwhelmingly significant unit price and run-time power. In this paper, we propose a novel processor-sharing IoT architecture that converts the vast majority of sensor nodes from embedded computers to low-end RF peripherals. The conventional full-fledged sensor nodes are smashed into the air, and the scattered chips are scaled well with negligible overheads through a virtual I2C bus called RFBus. Specifically, the RFBus interface is designed to be backward compatible with the I2C bus interface, and thus, the RFBus network inherits versatile link layer services transparently from the well-established I2C link layer protocol. We design the RFBus with a joint consideration of system-level performance and deployment costs and evaluate the prototypes in indoor and outdoor scenarios. The result indicates that the proposed architecture achieves 6.09 x (indoor) and 6.69 x (outdoor) energy saving and reduces the unit price of sensor nodes by 23.5% (indoor) and 33.5% (outdoor).
Qianhe Meng, Han Wang 0032, Chong Zhang 0017, Yihang Song, Songfan Li, Li Lu 0001, Hongzi Zhu
SenSys5
2024 A Lightweight and Chip-Level Reconfigurable Architecture for Next-Generation IoT End Devices
abstract
The rapid development of IoT applications calls for re-configurable IoT devices that can easily extend new functionality on demand. However, in the current architecture, updating chip functions on the end device is highly coupled with the local microprocessor in both hardware and software aspects, leading to inadequate flexibility. In this paper, we propose LEGO, a lightweight architecture with chip-level plug-and-play capabilities for IoT end devices. To achieve this, we first decoupling the control over heterogeneous chips from end devices to the gateway, and design a novel Unified Chip Description Language (UCDL) to access various types of functional chips uniformly. To supporting chips plug-and-play, we design a novel signal converting circuit on end devices to generate all required underlying signals for chip control. We also design a layered instruction orchestrator and hierarchical scheduler to minimize transmission overhead. The results show that our LEGO system can respond to chips plug-and-play within 0.13 seconds, and the lightweight architecture could reduce 49%$\sim$61% of power consumption in practical scenarios compared with traditional IoT end devices that are controlled by a microprocessor. The lightweight and easy-to-deploy features of LEGO makes it helpful to reduce deployment cost, thus conducive to accelerating large-scale applications.
Chong Zhang 0017, Songfan Li, Yihang Song, Qianhe Meng, Li Lu 0001, Hongzi Zhu, Xin Wang 0064
IEEE Trans. Computers2
2024 Watch Out Your Thumb Drive: Covert Data Theft From Portable Data Storage via Backscatter
abstract
USB flash drives are widely employed for data storage including sensitive personal or business data. Current defense strategies to protect those data mainly focus on preventing data theft when a USB drive plugs into a host computer that is infected with malware. This paper reveals a threat - attackers can produce spy USB flash drives that are able to leak the stored data via covert wireless communication without triggering security defenses on host computers. In this paper, we presentSpyUSB, a USB flash drive implanted with a backscatter-based data theft hardware to demonstrate the threat of covert data theft.SpyUSBcollects data from the physical layer of the communication between the host computer andSpyUSBdevice, which is transparent to the security mechanisms on the host computer.SpyUSBleverages backscatter communication to create a covert wireless channel. Furthermore, we explore the opportunity of covert data theft when theSpyUSBdevice is disconnected from the host computer using a tiny energy reservoir. Our experiment shows thatSpyUSBcan achieve a transmission bandwidth of up to 1,600 kbps. After unplugged from a computer, it can maintain standby for over 6 hours or continuously transmit data for 1.9 hours.
Songfan Li, Yihang Song, Chong Zhang 0017, Li Lu 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Frequency Scaling Meets Intermittency: Optimizing Task Rate for RFID-Scale Computing Devices
abstract
RFID (Radio Frequency Identification) computing devices in practical applications often suffer from their poor computing performance in terms of low task throughput (also known as task rate) due to scarce harvested power. For optimizing the task throughput, the basic idea is to choose an optimal processor clock frequency when executing a specific task ($e.g.$, operate sensor) in order to maximize task execution rate. Existing methods are based on the common sense where the frequency and task throughput are directly proportional to each other, meaning that a higher frequency causes a higher task rate. In RFID-scale devices, however, we observe that the relationship between the frequency and task throughput overturns the common sense, in which if the device rises the frequency, the task throughput will increase first and then decrease due to intermittent task execution pattern on such devices. In this paper, we present a systematic task throughput model to explain and formulate the non-monotonic relationship between the frequency and task throughput. Based on the throughput model, we further introduce dynamic optimal frequency scaling (DOFS) to calculate the optimal frequency for task execution and thus optimize the task throughput in the RFID-scale devices. The experimental results show that the task throughput can be improved by 45.8% on average compared to the existing best effort.
Songfan Li, Chao Song 0002, Li Lu 0001
IEEE Trans. Mob. Comput.1
2023 LEGO: Empowering Chip-Level Functionality Plug-and-Play for Next-Generation IoT Devices
abstract
Versatile Internet of Things (IoT) applications call for re-configurable IoT devices that can easily extend new functionality on demand. However, the heterogeneity of functional chips brings difficulties in device customization, leading to inadequate flexibility. In this paper, we propose LEGO, a novel architecture for chip-level re-configurable IoT devices that supports plug-and-play with Commercial Off-The-Shelf (COTS) chips. To combat the heterogeneity of functional chips, we first design a novel Unified Chip Description Language (UCDL) with meta-operation and chip specifications to access various types of functional chips uniformly. Then, to achieve chips plug-and-play, we build up a novel platform and shift all chip control logic to the gateway, which makes IoT devices entirely decoupled from specific applications and does not need to make any changes when plugging in new functional chips. Finally, to handle communications overheads, we built up a novel orchestration architecture for gateway instructions, which minimizes instruction transmission frequency in remote chip control. We implement the prototype and conduct extensive evaluations with 100+ types of COTS functional chips. The results show that new functional chips can be automatically accessed by the system within 0.13 seconds after being plugged in, and only bringing 0.53 kb of communication load on average, demonstrating the efficacy of LEGO design.
Chong Zhang 0017, Songfan Li, Yihang Song, Qianhe Meng, Yanxu Bai, Li Lu 0001, Hongzi Zhu
ASPLOS (3)2
2023 Go Beyond RFID: Rethinking the Design of RFID Sensor Tags for Versatile Applications
abstract
Designing ultra-low power RFID sensor tags is a major challenge, especially when incorporating a micro-controller (MCU) to operate sensors. While simplifying MCU functionality can reduce power consumption, it has limited effect as the fundamental information transformation is necessary for communication between the RFID reader and the sensor. Unfortunately, information transformation requires baseband sampling and processing, which consumes significant power on passive RFID tags. This paper proposes a novel approach that enables the reader to communicate directly with the sensor, eliminating the need for information transformation of MCU. We address the unique challenges posed by the physical and link layers of the EPC Gen2 protocol and introduce GoodID, a cross-layer design for next-generation RFID sensor tags featuring ultra-low power consumption. We prototype the GoodID tag for proof-of-concept and demonstrate significant power benefits through experimental results.
Songfan Li, Qianhe Meng, Yanxu Bai, Chong Zhang 0017, Yihang Song, Li Lu 0001
MobiCom1
2022 Passive DSSS: Empowering the Downlink Communication for Backscatter Systems
Songfan Li, Chong Zhang 0017, Yihang Song, Li Lu 0001, Mo Li 0001
NSDI1
2022 Chipnet: Enabling Large-scale Backscatter Network with Processor-free Devices
abstract
Differing from tremendous existing works that mainly focus on optimizing backscatter communication, Radio-to-Bus (R2B) communication utilizes backscatter to offload processors from IoT devices to the gateway, achieving processor-free devices of significantly reduced power and hardware cost. However, R2B communication is not suitable for large-scale backscatter networks, since R2B cannot support parallel and long-range communication between the gateway and hundreds of R2B devices. In this article, we present Chipnet, a network that supports hundreds of long-range and concurrent connections between the gateway and multiple processor-free devices. The high-level design of Chipnet includes a parallel frequency-division uplink mechanism that can work on processor-free devices and a processor-free MAC layer protocol that supports gateway to broadcast downlink data and individually manage each processor-free device. This design addresses practical issues facing the processor-free device architecture, such as synchronizing hundreds of processor-free devices, assigning unique channel frequencies to every device, and realizing power-efficient processor-free signal conversion. The results demonstrate that a Chipnet network can achieve a task throughput of 2,400 tasks/s with a latency of 72.23 ms. Compared with the R2B network, Chipnet achieves 3×–5× improvements in network coverage range and two orders of magnitude improvement in both network throughput and network latency.
Yihang Song, Chao Song 0002, Li Lu 0001, Songfan Li, Chong Zhang 0017, Qianhe Meng, Xiandong Shao
ACM Trans. Sens. Networks5
2021 A Spectrum-Efficient Cross-Layer RF Distance Bounding Scheme
abstract
Distance bounding protocols guarantee a credible distance upper bound between the devices which require the spatial distance as a security parameter to defend Mafia Fraud attacks. However, in RF systems, the realization of distance bounding protocol faces obstacles due to low spectrum efficiency, since the distance bound estimation consumes a significant amount of frequency band in existing schemes. This hinders RF distance bounding from being practically deployed, especially in commonly used ISM bands. In this work, we propose an alternative, spectrum-efficient scheme for RF distance bounding. We build the physical layer as well as a protocol design based on SFCW signal and SFCW ranging. Thus, comparing existing schemes that consume many frequency bands, our scheme frees many spectrum resources. We propose solutions to the unique challenges facing such an SFCW-based scheme design, namely, data communication over unintelligent SFCW signals, and secure synchronization in the SFCW-based challenge-response exchange. We evaluate our scheme via the security analysis and physical layer simulations. The results show (i) its resistance to attacks commonly concerned in distance bounding, (ii) the feasibility of the physical layer design such as accurate ranging and data communication function, and (iii) the communication noise tolerance and the ability of multipath signal discrimination.
Yihang Song, Songfan Li, Chong Zhang 0017, Li Lu 0001
Secur. Commun. Networks2
2020 Internet-of-microchips: direct radio-to-bus communication with SPI backscatter
abstract
Energy consumption of Internet-of-Things end devices is a major constraint that limits their long-term and large-scale deployment. Conventionally, the radios and processors used in these end devices are major power consumption that drains at the level of milliwatts (mWs). However, in recent decades, backscatter communication has dramatically reduced the power consumed by the radios in end devices to microwatts (μWs), and thus the processor remains the major bottleneck for energy optimization.
Songfan Li, Chong Zhang 0017, Yihang Song, Li Lu 0001, Mo Li 0001
MobiCom1
2019 Sentinel: Breaking the Bottleneck of Energy Utilization Efficiency in RF-Powered Devices
abstract
As a result of the limited available energy, radio frequency (RF)-powered devices must be capable of efficiently utilizing scarce energy by planning task execution according to the current harvested energy. However, the energy utilization efficiency is challenging to be improved in RF-powered devices, since sensing the harvested energy consumes a significant amount of energy that should be used for task execution. In this paper, we propose Sentinel, a novel low power method to sense the harvested energy. Sentinel is fully delegated to detect the energy for the device, while the device does not participate in the energy sensing. By this means, the computing overhead of the device is reduced. Sentinel works with low energy consumption, and functions as a trigger to activate the device when, and only when, the energy reaches an expected energy threshold. We also present a lightweight scheme to set the desired thresholds so that Sentinel achieves detecting any expected thresholds. We implement Sentinel by off-the-shelf components and conduct experiments to show that Sentinel consumes only 5.2% of energy overhead of the general energy sensing technique. With Sentinel, we show that the energy utilization efficiency can be improved up to 94.9%, outperforming the best existing works at 64.7% in the WISP platform.
Songfan Li, Li Lu 0001, Muhammad Jawad Hussain, Yalan Ye, Hongzi Zhu
IEEE Internet Things J.1
2018 R3: Reliable Over-the-Air Reprogramming on Computational RFIDs
abstract
Computational Radio Frequency Identification (CRFID) tags operate solely on harvested energy and have emerged as viable platforms for a variety of ubiquitous sensing and computation applications. Due to their battery-less nature, these tags can be permanently deployed in hard-to-reach places where the possibility of tag access is eliminated. In such scenarios, maintaining and upgrading the tag’s firmware becomes infeasible because programming tools, including wired interface and PC-based software, are required to erase, modify, or reprogram the microcontroller unit’s memory. Such limitations necessitate the demand for an over-the-air (OTA) scheme, which can wirelessly reprogram or upgrade the firmware in CRFID tags. In this article, we present R 3 —a reliable OTA reprogramming scheme that is compliant with EPC protocol and requires no hardware upgrade to RFID reader or CRFID tag. We demonstrate our scheme on three platforms, which include both software-defined as well as chip-based CRFID tags, that is, WISP5.1 and Optimized WISP (Opt-WISP), and Spider tag, respectively. The selection also includes both the FLASH- and FRAM-based microcontrollers. We extensively evaluate our scheme in terms of several metrics, including overall system delay, time and energy overhead, and success rate in line with interrogation range. We foresee our endeavor to offer the viability of OTA reprogramming and firmware upgrade for CRFID tokens under practical situations.
Dié Wu, Li Lu 0001, Muhammad Jawad Hussain, Songfan Li, Mo Li 0001, Fengli Zhang
ACM Trans. Embed. Comput. Syst.4