VLDB 2026 Research / reviewers in the wild / expert
Yicong Du
dblp:189/9854
· DBLP profile ↗
16ranked-venue papers
5as first author
16since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 5 first-author · 10 since 2021Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Physical Layer Secret Key Generation Leveraging Variable-Length Segment Matching in Wireless NetworksabstractPhysical layer secret key generation has emerged as a promising approach for secret key establishment in wireless networks. Unlike traditional quantization-based methods, recent studies have explored matching the patterns of segmented channel samples of equal length for key agreement. However, equal-length segmentation either suffers from inconsistencies between users for short segments or a reduced key generation rate for long ones. To address these issues, we propose a Variable-length Segment Matching-based Secret Key Generation method, VSM-SKG, which adaptively partitions channel samples into variable-length segments to enhance overall matching accuracy, key generation rate, and encryption strength. Specifically, we introduce a dissimilarity-enhanced segmentation and calibration strategy that partitions channel samples into variable-length segments to enlarge segment-wise dissimilarity. To achieve consistent key recovery between users, we develop a dynamic path-aware key generation method that identifies potential segmentation patterns and generates agreed-upon secret keys using a recursive approach combined with a fast retrieval mechanism. Theoretical analyses and real-world experiments validate the attributes of VSM-SKG in terms of accuracy, efficiency, and security in key generation. Yicong Du, Yuchen Su 0001, Haitao Jia, Shuai Li 0002, Yanzhi Ren, Hongbo Liu 0002 |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | DECK: Experiences on Delta Checkpointing for Industrial Recommendation SystemsabstractIn large-scale industrial recommendation systems, model checkpoints are instrumental in maintaining training goodput and numerical correctness during system failures and job preemptions. The increasing prevalence of multi-terabyte models has rendered frequent regular model checkpoints impractical, resulting in substantial lost progress when recovering from failures. As model sizes continue to grow, researchers and practitioners are compelled to investigate more efficient and scalable solutions. This paper presents DECK, a novel approach to delta model checkpointing designed for real-world industrial systems. Specifically, DECK focuses on extracting delta states with near-zero overhead, staging and streaming delta checkpoints without interrupting the training process, and merging delta checkpoints in an optimal and decoupled manner. Experimental results demonstrate that DECK achieves a 12-fold increase in checkpoint frequency while maintaining negligible impact on training throughput, thereby attaining state-of-the-art (SOTA) production performance. Sibasish Acharya, Sihui Han, Yongxiong Ren, Yanli Zhao, Chucheng Wang, Pradeep Fernando, Siqi Yan, Yicong Du, Elzbieta Krepska, Intaik Park, Min Ni, Qunshu Zhang |
Proc. VLDB Endow. | 11 |
| 2025 | ArmSpy++: Enhanced PIN Inference through Video-based Fine-grained Arm Posture AnalysisabstractAs one of the most common ways for user authentication, Personal Identification Number (PIN), due to its simplicity and convenience, has suffered from plenty of side-channel attacks, which pose a severe threat to people’s privacy and property. The success of existing attacks is usually built upon the premise of no occlusion between the attacker and the victim’s hand gesture, but it increases the difficulty of launching the attack and the possibility of exposure. To overcome such limitation, we propose ArmSpy++, an improved video-assisted PIN inference attack built upon our previous research, ArmSpy. Specifically, ArmSpy++ employs new modules to leverage more features like the keystroke-induced elbow bending, wrist speed variation, and the spatial relationship between different arm joints, to correctly detect Keystrokes. ArmSpy++ delves into the perspective relationship and natural typing habits to ensure a high success rate of PIN inference. We also re-designed the inferred PIN pattern coordination mechanism to accurately deduce the PINs. By using a pre-trained HigherHRNet model for posture estimation ArmSpy++ eliminates the necessity of additional training. The extensive experiments demonstrate that ArmSpy++ can achieve over 83.1% average accuracy with 3 attempts and even 92.5% for some victims, indicating the severity of the threat posed by ArmSpy++. Yuefeng Chen, Yicong Du, Luping Wang 0001, Ziyu Shao, Hongbo Liu 0002, Yanzhi Ren, Jiadi Yu, Bo Liu 0006 |
ACM Trans. Priv. Secur. | 3 |
| 2025 | Efficient and Error-Free Secret Key Generation Leveraging Sorted Indices MatchingabstractSecret key generation exploiting inherent channel randomness stands as an important paradigm for physical-layer security in wireless networks. However, existing work relying on quantization has some difficulties in eliminating inconsistent key bits due to the impact of ambient noise. Recent studies propose to match the segmented channel samples (i.e., channel episodes) of similar variation patterns between legitimate peers to achieve error-free key generation, but they also suffer from high computational overhead and reduced accuracy for large key lengths. This work proposes a secret key generation method based on sorted indices matching (SIM-SKG), aiming at efficient and error-free key generation. Specifically, we sort the channel samples to ensure each channel episode with a unique variation pattern for accurate matching. To avoid the impact of half-duplex communication mode and ambient noise, we propose to match the indices instead of the channel samples as in existing studies. We also develop a noise perturbation scheme that further mitigates the ambiguity during indices matching. Extensive experimental studies demonstrate the high efficiency and accuracy of SIM-SKG under various scenarios for both RSS and CSI channel measurements. Specifically, SIM-SKG achieves error-free key generation with a length of 2048 bits within as little as 1.7$msec$. Moreover, theoretical analyses and experiments also confirm the security of the SIM-SKG method against various attacks. Yicong Du, Hongbo Liu 0002, Guyue Li, Yanzhi Ren, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Secret Key Generation with Adaptive Pilot Manipulation for Matching-Based MethodabstractSecret key generation plays an important role in device-to-device communication security in wireless networks. For consistent key generation between two communicating parties, existing matching-based key generation methods match segmented channel measurements (channel episodes) of similar patterns between two parties. However, these methods suffer diminished accuracy for large key lengths or in the presence of ambient noise. This work takes a different perspective to produce the desired channel measurements through adaptive manipulation of pilot signals for robust and accurate physical layer secret key generation. Specifically, an adaptive pilot manipulation scheme is designed not only to ensure that each channel episode has a unique pattern but also to improve pattern similarity between a pair of matched channel episodes, thus enabling high matching consistency. To validate the effectiveness of our method, we implement it by re-configuring software modules in GNU radio running on the USRP platform. Extensive experiments demonstrate that our method outperforms existing representative quantization-based and matching-based methods with improved key generation performance. Yicong Du, Hongbo Liu 0002, Yanzhi Ren, Bo Liu 0058 |
ICC | 1 |
| 2024 | Physical Layer Secret Key Generation Leveraging Proactive Pilot ContaminationabstractPhysical layer-based secret key generation has garnered significant attention due to its inherent advantages of lightweight implementation, information-theoretic security, and broad applicability for mobile devices. The reciprocal randomness of the wireless channel ensures the consistent generation of secret bits between two communicating parties. However, it also suffers from the degradation of the efficiency of key generation attributed to the adverse impact of ambient noise, despite sustained efforts to mitigate the inconsistency during quantization. We find that a slight perturbation of the pilot signal, without affecting the correct reception of data frames, induces a corresponding change in the channel response, making it possibly adaptable to the target quantization strategies, thereby reducing the probability of key mismatch. Therefore, we take a different viewpoint on proactive contamination of the pilot signals to obtain the desired channel measurements for accurate physical layer secret key generation. Specifically, we design an adaptive pilot manipulation to avoid the expected channel measurements being too close to the quantization thresholds, enabling high quantization consistency. Furthermore, we also develop a random cross-threshold mechanism to prevent attackers from inferring the quantization results by monitoring the trend of pilot signal variations. A reliable long training sequence (LTS) modification mechanism is incorporated into our method to ensure communication performance by adaptively adjusting the scale of the pilot signal. To validate the effectiveness of our proposed method, we implement a prototype by re-configuring software modules in GNU radio running on the USRP platform. Extensive experiments demonstrate that our scheme outperforms existing representative quantization schemes with better key generation performance. Hongbo Liu 0002, Yicong Du, Ziyu Shao, Haomiao Yang, Yanzhi Ren |
ICDCS | 3 |
| 2024 | Practical Adversarial Attack on WiFi Sensing Through Unnoticeable Communication Packet PerturbationabstractThe pervasive use of WiFi has driven the recent research in WiFi sensing, converting communication tech into sensing for applications such as activity recognition, user authentication, and vital sign monitoring. Despite the integration of deep learning into WiFi sensing systems, potential security vulnerabilities to adversarial attacks remain unexplored. This paper introduces the first physical attack focusing on deep learning-based WiFi sensing systems, demonstrating how adversaries can subtly manipulate WiFi packet preambles to affect channel state information (CSI), a critical feature in such systems, and thereby influence underlying deep learning models without disrupting regular communication. To realize the proposed attack in practical scenarios, we rigorously analyze and derive the intricate relationship between the pilot symbol and CSI. A novel mechanism is proposed to facilitate quantitive control of receiver-side CSI through minimal modifications to the pilot symbols of WiFi packets at the transmitter. We further develop a perturbation optimization method based on the Carlini & Wagner (CW) attack and a penalty-based training process to ensure the attack's universal efficacy across various CSI responses and noise. The physical attack is implemented and evaluated in two representative WiFi sensing systems (i.e., activity recognition and user authentication) with 35 participants over 3 months. Extensive experiments demonstrate the remarkable attack success rates of 90.47% and 83.83% for activity recognition and user authentication, respectively. Mingjing Xu, Yicong Du, Cong Shi 0004, Yan Wang 0003, Hongbo Liu 0002, Yingying Chen 0001 |
MobiCom | 3 |
| 2024 | OISMic: Acoustic Eavesdropping Exploiting Sound-induced OIS Vibrations in SmartphonesabstractOptical image stabilization (OIS), powered by a special micro-electromechanical structure in the camera lenses to compensate for the optical distortion caused by camera shakes, has become an indispensable feature in many smartphones. However, we discover that this seemingly benign component can be exploited to eavesdrop on nearby audio signals, posing a significant threat to people's privacy during conversations or phone calls. Specifically, the OIS component can be influenced by external acoustic stimuli leading to slight vibrations, and at the same time, the coil and magnetized components inside the OIS induce electromagnetic leakage as they vibrate, according to Faraday's Law of Electromagnetic Induction. This electro-magnetic leakage contains voice information that can be used to recover the audio signals if intercepted by individuals with malicious intent. Inspired by the above discovery, we propose OISMic, a new acoustic eavesdropping attack that takes advantage of sound-induced OIS vibrations on smartphones. Unlike other existing acoustic eavesdropping attacks, eavesdropping exploiting OIS vibrations not only overcomes the constraints imposed by system permissions for many sensor-based approaches but is also immune to ultrasonic jammer that hinders the methods relying on microwave or light reflections to sense sound-induced vibrations. To execute this non-trivial attack in practical scenarios, we developed a prototype circuit that has a compact design capable of capturing the electromagnetic leakage caused by OIS vibrations. After converting the collected leaked electromagnetic signals into audio signals, a software-based phase-locked loop (PLL) method is developed to enhance the representation of voice components. Meanwhile, to reconstruct the weak audio signals, we also designed a diffusion-based neural network to learn the distribution of electromagnetic noise within the audio spectrum. Extensive experiments indicate that OISMic can accurately reconstruct voice under various scenarios, achieving an average word correct rate of 90.57 % across different devices. Ziyu Shao, Yuchen Su 0001, Yicong Du, Shiyue Huang, Tingyuan Yang, Hongbo Liu 0002, Yanzhi Ren, Bo Liu 0058, Shuai Li 0002 |
SECON | 3 |
| 2024 | Secret Key Generation Based on Manipulated Channel Measurement MatchingabstractThe physical layer secret key generation exploiting wireless channel reciprocity has demonstrated its viability and effectiveness in various wireless scenarios, such as the Internet of Things (IoT) network, mobile communication network, and industrial control system. Most of the existing studies rely on the quantization technique to convert channel measurements into secret bits for confidential communications. However, non-simultaneous packet exchanges in time-division duplex systems and noise effects usually induce inconsistent quantization results and mismatched secret bits. Although recent research has spent significant effort mitigating such non-reciprocity, it is still far from practical error-free key generation. Unlike previous quantization-based approaches, we take a different viewpoint to match the randomly manipulated (i.e., permuted or edited) channel measurements between a pair of users by minimizing their discrepancy holistically. Specifically, two novel secret key generation algorithms based on bipartite graph matching (BMSKG) and edited sequence alignment (SA-SKG) are developed. BM-SKG allows two users to generate the same secret key based on the permutation order of channel measurements, while SASKG aims to align the edited channel measurements between a pair of users for secret key agreement. In both algorithms, one user can preset the secret key and embed encrypted messages in the exchanged data packets, which reduces communication overheads in key generation. Extensive experimental results show that both BM-SKG and SA-SKG algorithms achieve error-free key agreement on channel measurements at a low cost under various scenarios. Yicong Du, Hongbo Liu 0002, Yan Wang 0003, Guyue Li, Yanzhi Ren, Yingying Chen 0001, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Secure and Controllable Secret Key Generation Through CSI Obfuscation Matrix EncapsulationabstractPhysical-layer key generation has emerged as a promising avenue for establishing secret keys using reciprocal channel measurements between wireless devices. However, channel reciprocity may suffer degradation from ambient noise and cause mismatched secret bits, while existing methods mitigating this issue may yet face limitations in key efficiency. The root cause behind such limitations is the heavy reliance on channel measurements, which can be naturally susceptible to channel non-reciprocity attributed to environmental factors. Instead of direct key extraction from channel measurements, we seek to share a pre-defined key and utilize channel measurements as a bearer to facilitate key transmission. We propose an accurate and efficient key generation method (KeyCome) to ensure secure key sharing by encapsulating it with channel state information (CSI) obfuscation matrices through circulant convolution. To this end, we develop a reliable key derivation through a quadratic programming method with matrix equilibration, ensuring stable and rapid solutions. Notably, the transmitter can control the key beforehand for enhanced communication efficiency and combine it with an error correction mechanism for accurate key derivation. Furthermore, a lightweight reconciliation scheme is designed to minimize mismatched bits caused by occasional non-reciprocity. Comprehensive experiments demonstrate KeyCome's high accuracy and efficiency in key generation. Yicong Du, Hongbo Liu 0002, Ziyu Shao, Yanzhi Ren, Shuai Li 0002, Jiadi Yu |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | P2Auth: Two-Factor Authentication Leveraging PIN and Keystroke-Induced PPG MeasurementsabstractPersonal Identification Number (PIN), as one of the primary means of protecting digital properties and privacy on mobile devices, has been suffering from shoulder surfing attacks and weak password guessing for the long term. Recent years witness the growing interest in two-factor authentication that takes advantage of two different ways for mutual verification, thereby strengthening user authentication's accuracy and reliability. Especially with the popularity of smartwatches, more physiological signals are readily available to facilitate two-factor authentication. This paper presents a lightweight and unobtrusive two-factor authentication scheme, P2Auth, integrating the PIN and unique keystroke-related Photoplethysmography (PPG) measurement on wearables. Specifically, we propose the transformation of the multivariate PPG signal induced by the keystrokes to extract reliable biometric features. We develop short-time energy-based methods to identify the input cases, thus enabling support the authentication for both one-handed and two-handed input cases. Furthermore, we also consider the situation where there is no fixed PIN and design a new enhanced privacy scheme by combining the PPG measurements of different keystrokes to improve authentication security. The experiments involving 15 volunteers demonstrate that our prototype system can achieve an average authentication accuracy of over 95% for one-handed cases and over 90% for two-handed cases. Yuchen Su 0001, Guoqing Jiang, Yicong Du, Yuefeng Chen, Hongbo Liu 0002, Yanzhi Ren, Yan Wang 0003, Shuai Li 0002, Yingying Chen 0001 |
ICDCS | 3 |
| 2023 | Backdoor-Resistant Public Data Integrity Verification Scheme Based on Smart ContractsabstractThis article analyzes existing smart contract-based public data integrity verification schemes and identifies certain weaknesses. First, the fair arbitration mechanism deployed in these schemes fails to meet the users’ requirements as it may not promptly notify users of data corruption or loss. Second, to ensure outsourced data confidentiality, existing data integrity schemes use a conventional encrypted method, where each user randomly selects a key to encrypt the outsourced data. Such a method results in varying ciphertexts for the same data by different users, leading to additional storage costs for the cloud server. Third, users’ devices, if poorly designed or even intentionally backdoored, can potentially exfiltrate secrets and compromise the security of schemes. To address these issues, we propose the first backdoor-resistant public data integrity verification scheme based on smart contracts (ASSIST). The key idea is to introduce a new entity (a whistleblower) to periodically monitor the state of verification results recorded in the blockchain. This allows for timely notification of data corruption to users. ASSIST requires users to encrypt their data with a cryptographic primitive called message-locked encryption (MLE), which motivates different users to produce the same ciphertext for the same data and reduces storage costs for cloud servers. We also deploy a cryptographic reverse firewall between users’ devices and the external to rerandomize interactive messages, making the exfiltration impossible. We provide rigorous security proofs to demonstrate the security of ASSIST. The performance evaluation shows that ASSIST is efficient regarding computation and communication costs. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Anjia Yang, Xinsheng Wen, Kefei Chen |
IEEE Internet Things J. | 4 |
| 2023 | HealthFort: A Cloud-Based eHealth System With Conditional Forward Transparency and Secure Provenance via BlockchainabstractIn this paper, we propose a servers-aided password-based subsequent-key-locked encryption mechanism to ensure the confidentiality of outsourced electronic health records (EHRs). The encryption mechanism achieves conditional forward transparency: a doctor can only access a patient's EHRs related to the current diagnosis with the patient's delegation. It also achieves portability: to delegate a doctor for accessing a specific part of EHRs, the patient only needs to send one key (at most 256 bits) in addition to the delegation information to the doctor; the patient does not need to maintain any secret in a local device. Then, we propose a blockchain-based secure EHR provenance mechanism, where a data structure of EHR provenance record is designed to precisely reflect the EHRs’ provenance information; a smart contract on a public blockchain is deployed to secure both EHRs and the corresponding provenance records. Finally, we develop a cloud-based eHealth system, dubbed HealthFort, based on the two mechanisms. Security analysis and comprehensive performance evaluation are conducted to demonstrate that HealthFort is secure and efficient. Shiyu Li 0002, Yuan Zhang 0006, Chunxiang Xu, Nan Cheng 0001, Zhi Liu 0002, Yicong Du, Xuemin Shen |
IEEE Trans. Mob. Comput. | 6 |
| 2023 | Blockchain-Based Transparent Integrity Auditing and Encrypted Deduplication for Cloud StorageabstractIn this paper, we introduce a concept of transparent integrity auditing and propose a concrete scheme based on the blockchain, which goes one step beyond existing public auditing schemes, since the auditing does not rely on third-party auditors while freeing users from heavy communication costs on auditing the data integrity. Then we construct a secure transparent deduplication scheme based on the blockchain that supports deduplication over encrypted data and enables users to attest the deduplication pattern on the cloud server. Such a scheme allows users to directly benefit from data deduplication and protects data content against anyone who does not own the data. Finally, we integrate the proposed transparent integrity auditing scheme and transparent deduplication scheme into one system, dubbed BLIND. We evaluate BLIND from security and efficiency, which demonstrates that BLIND achieves a strong security guarantee with high efficiency. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Kefei Chen |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | An Improved Least-square based Jammer Localization AlgorithmabstractDue to the shared nature of wireless mediums, jamming attacks have long been a great hazard to the security of wireless networks. A plethora of efforts have been spent to mitigate the impact of jamming attacks, and especially the localization technique of malicious jammer emerges in the last decade and enables us to remove the interfering devices from the physical layer. Since it is impossible to directly measure the interfering signal in a jamming scenario, many existing methods rely on inaccurate ranging estimation to locate the jammers. In this paper, we propose an improved least-square jammer localization method leveraging the network distribution properties. Specifically, we exploit the stochastic geometry theory to analyze the coverage changes of wireless devices around the jammer, which are then used to improve the accuracy of ranging estimation. Extensive numerical results demonstrate the effectiveness and robustness of the proposed jammer localization methods under various scenarios. Notably, the improved leastsquares method has a decreasing of 35 % on the mean localization error comparing to the traditional least-square method. Ruiqiong Tong, Yicong Du, Hongbo Liu 0002, Yingying Chen 0001 |
ICPADS | 2 |
| 2022 | ArmSpy: Video-assisted PIN Inference Leveraging Keystroke-induced Arm Posture ChangesabstractPIN inference attack leveraging keystroke-induced side-channel information poses a substantial threat to the security of people’s privacy and properties. Among various PIN inference attacks, video-assisted method provide more intuitive and robust side-channel information to infer PINs. But it usually requires there is no visual occlusion between the attacker and the victims or their hand gestures, making the attackers either easy to expose themselves or inapplicable to the scenarios such as ATM or POS terminals. In this paper, we present a novel and practical video-assisted PIN inference system, ArmSpy, which infers victim’s PIN by observing from behind the victims in a stealthy way. Specifically, ArmSpy explores the subtle keystroke-induced arm posture changes, including elbow bending angle changes and the spatial relationship between different arm joints, to infer the PIN entries. We develop the keystroke inference mechanism to detect the keystroke events and pinpoint the keystroke positions, and then accurately infer the PINs with the proposed inferred PIN coordination mechanism. Extensive experimental results demonstrate that ArmSpy can achieve over 67% average accuracy on inferring the PIN with 3 attempts and even over 80% for some victims, indicating the severity of the threat posed by ArmSpy. Yuefeng Chen, Yicong Du, Chunlong Xu, Yanghai Yu, Hongbo Liu 0002, Yanzhi Ren, Jiadi Yu |
INFOCOM | 2 |