VLDB 2026 Research / reviewers in the wild / expert
Chao Wang 0097
dblp:188/7759-97
· DBLP profile ↗
17ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0003-0906-445XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 2 first-author · 5 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The arts and crafts of android adware across a decade
Chao Wang 0097, Tianming Liu 0001, Yanjie Zhao 0001, Lin Zhang 0062, Xiaoning Du 0001, Li Li 0029, Haoyu Wang 0001 |
Autom. Softw. Eng. | 1 |
| 2025 | Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMsabstractThe customization and fragmentation of the Android ecosystem have fostered its prosperity and highlighted the growing importance of conducting security audits on these customized systems. This significance is driven by the distinct strategies that Original Equipment Manufacturers (OEMs) deploy to enhance device performance and user experience, which are important to their competitive differentiation. A key aspect of these strategies includes system-level optimizations for super apps and other widely used apps, marking a competitive trend among OEMs. Granting privileges to such apps often stems from trust in these apps. However, without proper validation of apps' identities, this can lead to severe implicit trust vulnerabilities, providing a convenient pathway for malicious apps to impersonate privileged ones and gain their access rights. For malicious developers, exploiting these vulnerabilities is both cost-effective and potentially highly rewarding. In this study, we undertook a comprehensive analysis of 686 custom Android ROMs from 46 OEMs, aimed at uncovering potential security risks associated with implicit trust vulnerabilities in apps. Our investigation identified 3,085 instances where thirdparty app package names were embedded within the ROMs. Alarmingly, only seven of these instances had implemented adequate authentication mechanisms to mitigate the associated risks, exposing 3,078 potential vulnerabilities that exhibited an increasing trend over time. We have reported 22 manually confirmed cases to seven relevant OEMs. As of the time of writing this paper, four vulnerabilities have been explicitly acknowledged by the OEMs, and one has been assigned a CVE ID. Chao Wang 0097, Yanjie Zhao 0001, Jiapeng Deng, Haoyu Wang 0001 |
SP | 1 |
| 2024 | Same App, Different Behaviors: Uncovering Device-specific Behaviors in Android AppsabstractThe Android ecosystem is significantly challenged by fragmentation, arising from diverse system versions, device specifications, and manufacturer customizations. The growing divergence among devices leads to marked variations in how a given app behaves across diverse devices. This is referred to as device-specific behaviors. Fragmentation not only complicates development processes but also impacts the overall industry by increasing maintenance costs and potentially harming user experience due to inconsistent app performance. In this work, we present the first large-scale empirical study of device-specific behaviors in real-world Android apps. We have designed a three-phase static analysis framework to accurately detect and understand the device-specific behaviors. Upon employing our tool on a dataset comprising more than 20,000 apps, we detected device-specific behaviors in 2,357 of them. By examining the distribution of device-specific behaviors, our analysis revealed that apps within the Chinese third-party app market exhibit more such behaviors compared to their counterparts in Google Play. Additionally, these behaviors are more likely to feature dominant brands that hold larger market shares. Reflecting this, we have classified these device-specific behaviors into 29 categories based on the functionalities implemented, providing a structured insight that is crucial for developers and stakeholders in the industry. Beyond the common behaviors, such as issue fixes and feature adaptations, we have observed 33 aggressive apps, including popular ones with millions of downloads. These apps abuse system properties of customized ROMs to obtain user-unresettable identifiers without requiring any permissions, posing significant privacy risks. Finally, we investigated the origins of device-specific behaviors, highlighting the significant challenges developers encounter in implementing them comprehensively. Our research aims to inform and equip industry practitioners with knowledge to enhance user experience and user privacy, marking a critical step toward addressing the less touched yet vital aspect of device-specific behaviors in the Android ecosystem. Zikan Dong, Yanjie Zhao 0001, Tianming Liu 0002, Chao Wang 0097, Guosheng Xu 0001, Guoai Xu, Lin Zhang 0062, Haoyu Wang 0001 |
ASE | 4 |
| 2024 | VibSpeech: Exploring Practical Wideband Eavesdropping via Bandlimited Signal of Vibration-based Side Channel
Chao Wang 0097, Feng Lin 0004, Wenyao Xu, Kui Ren 0001 |
USENIX Security Symposium | 1 |
| 2024 | High-Quality Speech Recovery Through Soundproof Protections via mmWave SensingabstractOnline voice communications are widely used nowadays. To protect speech from leakage, people tend to initiate the talk in sound-isolated environments. In this paper, we reveal a novel attack that recovers high-quality speech from outside soundproof zones. The rationale of the attack is to leverage sound-sensitive characteristics of piezoelectric materials, i.e., a piezo film that can change the phase of reflected mmWaves when placed in a sound field. If the attacker transmits mmWaves and analyzes reflected signals from the piezo film, the speech information can be compromised. More importantly, the piezo film is paper-like and works without a power supply. We propose a new speech recovery methodology to transform sound waves into wireless signals and build an end-to-end eavesdropping system working as a through-wall “microphone” to recover high-quality speech stealthily. To combat signal attenuation and improve speech quality, we develop a speech-enhancement scheme based on generative adversarial networks and propose to use multi-antenna information for intelligible speech reconstruction. We conduct extensive experiments to evaluate the system. The results indicate that the system achieves over 98% accuracy for digit recognition and works well over 5m away through the wall. We also test the system under complex scenarios and give countermeasures. Feng Lin 0004, Chao Wang 0097, Tiantian Liu 0002, Ziwei Liu 0007, Yijie Shen, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | MotoPrint: Reconfigurable Vibration Motor Fingerprint via Homologous Signals LearningabstractDevice fingerprints can satisfy the high-security requirement of modern mobile applications (e.g., mobile payments) by guaranteeing the operation is performed on a trusted device. However, existing works on device fingerprints are weak to leakage, which leads to an irreversible failure of the device fingerprint authentication system after suffering from fingerprint theft attacks. The vulnerability drives us to propose a reconfigurable device fingerprint, i.e.,MotoPrint, that can recover the system after suffering from such attacks.MotoPrintstems from the motor vibration that can represent in both signals of the accelerometer and the gyroscope (i.e., they are homologous motion signals). Therefore, we designed a two-path feature extracting network and a sensor-independent training strategy to eliminate sensor noise that can decline authentication performance. In addition,MotoPrinthas a complete reconfiguration mechanism to cope with fingerprint leakage, which brings the damaged authentication system back to health. The evaluation of 80 stand-alone vibration motors and 20 in-built ones shows thatMotoPrintcan achieve high authentication accuracy of 98.5%. Meanwhile, we also demonstrate the reconfiguredMotoPrint, which can also effectively indicate the device's uniqueness with over 98% accuracy, is independent ofMotoPrints under other stimulating codes. Yijie Shen, Feng Lin 0004, Chao Wang 0097, Tiantian Liu 0002, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Wavoice: An mmWave-Assisted Noise-Resistant Speech Recognition SystemabstractAs automatic speech recognition evolves, deployment of the voice user interface (VUI) has boomingly expanded. Especially since the COVID-19 pandemic, the VUI has gained more attention in online communication owing to its non-contact property. However, the VUI struggles to be applied in public scenes due to the degradation of received audio signals caused by various ambient noises. In this article, we propose Wavoice , the first noise-resistant multi-modal speech recognition system that fuses two distinct voices sensing modalities (i.e., millimeter-wave signals and audio signals from a microphone) together. One key contribution is to model the inherent correlation between millimeter-wave and audio signals. Based on it, Wavoice facilitates the real-time noise-resistant voice activity detection and user targeting from multiple speakers. Additionally, we elaborate on two novel modules for multi-modal fusion embedded into the neural network, leading to accurate speech recognition. Extensive experiments prove the effectiveness of Wavoice under adverse conditions—that is, the character recognition error rate below 1% in a range of 7 m. In terms of robustness and accuracy, Wavoice considerably outperforms existing audio-only speech recognition methods with lower character error and word error rates. Tiantian Liu 0002, Chao Wang 0097, Zhengxiong Li, Ming-Chun Huang, Wenyao Xu, Feng Lin 0004 |
ACM Trans. Sens. Networks | 2 |
| 2023 | MagBackdoor: Beware of Your Loudspeaker as A Backdoor For Magnetic Injection AttacksabstractAn audio system containing loudspeakers and microphones is the fundamental hardware for voice-enabled devices, enabling voice interaction with mobile applications and smart homes. This paper presents MagBackdoor, the first magnetic field attack that injects malicious commands via a loudspeaker-based backdoor of the audio system, compromising the linked voice interaction system. MagBackdoor focuses on the magnetic threat on loudspeakers and manipulates their sound production stealthily. Consequently, the microphone will inevitably pick up malicious sound generated by the attacked speaker, due to the closely packed arrangement of internal audio systems. To prove the feasibility of MagBackdoor, we conduct comprehensive simulations and experiments. This study further models the mechanism by which an external magnetic field excites the sound production of loudspeakers, giving theoretical guidance to MagBackdoor. Aiming at stealthy magnetic attacks in real-world scenarios, we self-design a prototype that can emit magnetic fields modulated by voice commands. We implement MagBackdoor and evaluate it across a wide range of smart devices involving 16 smartphones, four laptops, two tablets, and three smart speakers, achieving an average 95% injection success rate with high-quality injected acoustic signals. Tiantian Liu 0002, Feng Lin 0004, Zhangsen Wang, Chao Wang 0097, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
SP | 4 |
| 2023 | WavoID: Robust and Secure Multi-modal User Identification via mmWave-voice MechanismabstractWith the increasing deployment of voice-controlled devices in homes and enterprises, there is an urgent demand for voice identification to prevent unauthorized access to sensitive information and property loss. However, due to the broadcast nature of sound wave, a voice-only system is vulnerable to adverse conditions and malicious attacks. We observe that the cooperation of millimeter waves (mmWave) and voice signals can significantly improve the effectiveness and security of user identification. Based on the properties, we propose a multi-modal user identification system (named WavoID) by fusing the uniqueness of mmWave-sensed vocal vibration and mic-recorded voice of users. To estimate fine-grained waveforms, WavoID splits signals and adaptively combines useful decomposed signals according to correlative contents in both mmWave and voice. An elaborated anti-spoofing module in WavoID comprising biometric bimodal information defend against attacks. WavoID produces and fuses the response maps of mmWave and voice to improve the representation power of fused features, benefiting accurate identification, even facing adverse circumstances. We evaluate WavoID using commercial sensors on extensive experiments. WavoID has significant performance on user identification with over 98% accuracy on 100 user datasets. Tiantian Liu 0002, Feng Lin 0004, Chao Wang 0097, Chenhan Xu, Zhengxiong Li, Wenyao Xu, Ming-Chun Huang, Kui Ren 0001 |
UIST | 3 |
| 2022 | mmPhone: Acoustic Eavesdropping on Loudspeakers via mmWave-characterized Piezoelectric EffectabstractMore and more people turn to online voice communication with loudspeaker-equipped devices due to its convenience. To prevent speech leakage, soundproof rooms are often adopted. This paper presents mmPhone, a novel acoustic eavesdropping system that recovers loudspeaker speech protected by soundproof environments. The key idea is that properties of piezoelectric films in mmWave band can change with sound pressure due to the piezoelectric effect. If the property changes are acquired by an adversary (i.e., characterizing the piezoelectric effect with mmWaves), speech leakage can happen. More importantly, the piezoelectric film can work without a power supply. Base on this, we proposed a methodology using mmWaves to sense the film and decoding the speech from mmWaves, which turns the film into a passive "microphone". To recover intelligible speech, we further develop an enhancement scheme based on a denoising neural network, multi-channel augmentation, and speech synthesis, to compensate for the propagation and penetration loss of mmWaves. We perform extensive experiments to evaluate mmPhone and conduct digit recognition with over 93% accuracy. The results indicate mmPhone can recover high-quality and intelligible speech from a distance over 5m and is resilient to incident angles of sound waves (within 55 degrees) and different types of loudspeakers. Chao Wang 0097, Feng Lin 0004, Tiantian Liu 0002, Ziwei Liu 0007, Yijie Shen, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
INFOCOM | 1 |
| 2022 | mmEve: eavesdropping on smartphone's earpiece via COTS mmWave deviceabstractEarpiece mode of smartphones is often used for confidential communication. In this paper, we proposed a remote(>2m) and motion-resilient attack on smartphone earpiece. We developed an end-to-end eavesdropping system mmEve based on a commercial mmWave sensor to recover speech emitted from smartphone earpiece. The rationale of the attack is based on our observation that, soundwaves emitted from the smartphone's earpiece have a strong correlation with reflected mmWaves from the smartphone's rear. However, we find the recovered speech suffers from the sensor's self-noise and smartphone user's motion which limit attack distance to less than 2m, causing limited threats in real world. We modeled the motion interference under mmWave sensing and proposed a motion-resilient solution by optimizing the fitting function on I/Q plane. To achieve a practical attack with reasonable attack distance, we developed a GAN-based denoising scheme to eliminate the noise pattern of the sensor, which boosted the attack range to 6--8m. We evaluated mmEve with extensive experiments and find 23 different models of smartphones manufactured by Samsung, Huawei, etc. can be compromised by the proposed attack. Chao Wang 0097, Feng Lin 0004, Tiantian Liu 0002, Kaidi Zheng, Zhibo Wang 0001, Zhengxiong Li, Ming-Chun Huang, Wenyao Xu, Kui Ren 0001 |
MobiCom | 1 |
| 2021 | Wavoice: A Noise-resistant Multi-modal Speech Recognition System Fusing mmWave and Audio SignalsabstractWith the advance in automatic speech recognition, voice user interface has gained popularity recently. Since the COVID-19 pandemic, VUI is increasingly preferred in online communication due to its non-contact. Additionally, various ambient noise impedes the public applications of voice user interfaces due to the requirement of audio-only speech recognition methods for a high signal-to-noise ratio. In this paper, we present Wavoice, the first noise-resistant multi-modal speech recognition system that fuses two distinct voice sensing modalities, i.e., millimeter-wave (mmWave) signals and audio signals from a microphone, together. One key contribution is that we model the inherent correlation between mmWave and audio signals. Based on it, Wavoice facilitates the real-time noise-resistant voice activity detection and user targeting from multiple speakers. Furthermore, we elaborate on two novel modules into the neural attention mechanism for multi-modal signals fusion, and result in accurate speech recognition. Extensive experiments verify Wavoice's effectiveness under various conditions with the character recognition error rate below 1% in a range of 7 meters. Wavoice outperforms existing audio-only speech recognition methods with lower character error rate and word error rate. The evaluation in complex scenes validates the robustness of Wavoice. Tiantian Liu 0002, Ming Gao 0023, Feng Lin 0004, Chao Wang 0097, Zhongjie Ba, Jinsong Han, Wenyao Xu, Kui Ren 0001 |
SenSys | 4 |
| 2021 | G2F: A Secure User Authentication for Rapid Smart Home IoT ManagementabstractInternet-of-Things (IoT) devices are widely deployed nowadays. A large number of smart home IoT devices are hosted on a cloud server for easy management. Users can use their accounts to initiate operations and management on IoT devices through a cloud server, such as updating firmware and configuring devices. However, the cloud account may be hacked resulting in adversarial attacks to the hosted IoT devices. As a consequence, an adversary may perform malicious operations through the cloud remotely to the hosted IoT devices without user awareness. Motivated by this, in this article we propose gateway-based 2 factor authentication (G2F), a secure user authentication framework dedicated for a gateway based on the universal 2nd factor (U2F) protocol to enhance the security of IoT devices management. In G2F, the user authentication on the gateway is completed utilizing a hardware token that interacts with the local gateway node to guarantee the token owner’s presence. Furthermore, G2F can grant multiple simultaneous operations on IoT devices through just one user authentication. We implement a prototype to further evaluate the performance of G2F. Based on our realization on the commercial IoT server, i.e., Alibaba Cloud, G2F demonstrates the ability to protect against malicious attacks with high authentication efficiency. Chao Wang 0097, Hao Luo 0001, Fan Zhang 0010, Feng Lin 0004, Guoai Xu |
IEEE Internet Things J. | 2 |
| 2016 | Cache-Partitioned Preemption Threshold Scheduling
Zonghua Gu 0001, Chao Wang 0097, Haibo Zeng 0001 |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2016 | Minimizing Stack Memory for Hard Real-Time Applications on Multicore Platforms with Partitioned Fixed-Priority or EDF SchedulingabstractMulticore processors are increasingly adopted in resource-constrained real-time embedded applications. In the development of such applications, efficient use of RAM memory is as important as the effective scheduling of software tasks. Preemption Threshold Scheduling (PTS) is a well-known technique for controlling the degree of preemption, possibly improving system schedulability, and to reduce system stack usage. In this paper, we consider partitioned multi-processor scheduling on a multicore processor with either Fixed-Priority or Earliest Deadline First scheduling algorithms with PTS and address the design optimization problem of mapping tasks to processor cores and assignment of task priorities and preemption thresholds with the optimization objective of minimizing system stack usage. We present both optimal solution techniques based on Mixed Integer Linear Programming and efficient heuristic algorithms that can achieve high-quality results. We perform extensive performance evaluations using both synthetic tasksets and industrial case studies. Chao Wang 0097, Chuansheng Dong, Haibo Zeng 0001, Zonghua Gu 0001 |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2016 | Global Fixed Priority Scheduling with Preemption Threshold: Schedulability Analysis and Stack Size MinimizationabstractMemory is a limited resource in cost-sensitive, resource-constrained embedded applications. Preemption Threshold Scheduling (PTS) is a well-known technique for reducing the system stack size requirement. We consider Global Fixed Priority Scheduling with Preemption Threshold (gFPPT), as integration of PTS with global Fixed-Priority scheduling on a homogeneous multiprocessor platform, and formulate the optimization problem of minimizing the system stack size requirement while guaranteeing schedulability. We present schedulability analysis, optimization algorithms for priority and preemption threshold assignment, and an ILP formulation for computing system stack size requirement. Performance evaluation shows that the system stack size requirement can be reduced significantly with gFPPT compared to preemptive scheduling. Chao Wang 0097, Zonghua Gu 0001, Haibo Zeng 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2015 | Integration of Cache Partitioning and Preemption Threshold Scheduling to Improve Schedulability of Hard Real-Time SystemsabstractFor preemptive scheduling with shared cache, different tasks may cause interference in the shared cache, leading to Cache-Related Preemption Overhead (CRPD). Cache partitioning is a well-known technique for mitigating unpredictable cache interference in preemptive scheduling, but it reduces cache space available to each task, causing an increase in task execution time. Non-preemptive scheduling algorithms do not incur CRPD, but they generally have poor schedulability. Preemption Threshold Scheduling (PTS) is an effective approach to strike a balance between preemptive and non-preemptive scheduling. We propose integration of cache partitioning and PTS to optimize schedulability on a uniprocessor. We force each subset of tasks assigned the same cache partition to be a non-preemptive group, by assigning the same PT to all tasks in the subset that is equal to or higher than the highest priority of the tasks in that subset. This eliminates CRPD within each cache partition, and helps to improve schedulability. We present an ILP formulation as well as an efficient heuristic algorithm. Chao Wang 0097, Zonghua Gu 0001, Haibo Zeng 0001 |
ECRTS | 1 |