VLDB 2026 Research / reviewers in the wild / expert
Yanjun Pan 0001
dblp:192/9996-1
· DBLP profile ↗
15ranked-venue papers
8as first author
11since 2021 · last 2026
0000-0001-6425-7102ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 7 first-author · 9 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CP-Free ODDM: Modeling and Design
Yanjun Pan 0001, Jeremiah Wimer, Jingxian Wu 0001, Hai Lin 0001, Jinhong Yuan |
ICC | 1 |
| 2026 | CP-Free ODDM Over General Doubly-Selective Fading ChannelsabstractThis paper proposes a new orthogonal delay-Doppler division multiplexing (ODDM) system, which is designed to operate without the need of using a cyclic prefix (CP) in the transmitted signals. The CP-free ODDM is enabled by exploiting the unique structures of the ODDM prototype pulses, which are constructed through repetitions of finite-duration elementary pulses. The system eliminates the need of CP by designing a new receiving filter through temporally extending the transmission prototype pulse. The elementary pulse repetition at the transmitter along with the temporal filter extension at the receiver introduce a wrap-around effect in the equivalent channel spreading function in the dealy-Doppler (DD) domain. The wrap-around effect leads to a block-circulant-like structure of the DD-domain channel matrix that is the same as conventional ODDM systems with CP. Thus CP-free ODDM can employ the same receiver as conventional ODDM systems, yet it yields a higher energy efficiency as no energy needs to be allocated for CP symbols. The wrap-around effects are theoretically demonstrated by deriving the exact analytical expressions of the cross-ambiguity functions of practical transmission and receiving prototype pulses. In addition, theoretical analysis of the cross-ambiguity function verifies that the CP-free ODDM waveforms satisfy local bi-orthogonality in the delay and Doppler domains. This bi-orthogonality property along with the wrap-around effects of the channel spreading function enables the design of a low complexity iterative receiver, which performs interference cancellation and coherent matrix combining (CMC) in the delay domain and minimum mean squared error (MMSE) detection in the Doppler domain. The proposed receiver can collect the diversity in both the delay and Doppler domains while simultaneously suppressing the negative impacts of DD-domain intersymbol interference (ISI) introduced by the doubly-selective fading channels. Yanjun Pan 0001, Jeremiah Wimer, Jingxian Wu 0001, Hai Lin 0001, Jinhong Yuan |
IEEE Trans. Wirel. Commun. | 1 |
| 2025 | Harvesting Physical-Layer Randomness in Millimeter Wave BandsabstractThe unpredictability of the wireless channel has been used as a natural source of randomness to build physical-layer security primitives for shared key generation, authentication, access control, proximity verification, and other security properties. Compared to pseudo-random generators, it has the potential to achieve information-theoretic security. In sub-6 GHz frequencies, the randomness is harvested from the small-scale fading effects of RF signal propagation in rich scattering environments. However, the RF propagation characteristics follow sparse models with clustered paths when devices operate in millimeter-wave (mmWave) bands (5G and Next-Generation networks, Wi-Fi in 60GHz). Millimeter-wave transmissions are typically directional to increase the gain and combat high signal attenuation, leading to stable and more predictable channels. In this paper, we first demonstrate that state-of-the-art methods relying on channel state information or received signal strength measurements fail to produce high randomness. Accounting for the unique features of mmWave propagation, we propose a novel randomness extraction mechanism that exploits the random timing of channel blockage to harvest random bits. Compared with the prior art in CSI-based and context-based randomness extraction, our protocol remains secure againstpassive and active Man-in-the-Middle adversaries co-located with the legitimate devices. We demonstrate the security properties of our method in a 28 GHz mmWave testbed in an indoor setting. Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Ming Li 0003, Loukas Lazos |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Low Complexity OTFS Detection with a Delay-Doppler Domain CMC-MMSE ReceiverabstractA low complexity receiver is developed for orthogonal time frequency space (OTFS) systems by exploring the special structure of the delay-Doppler (DD) domain channel matrix. Based on the system architecture of OTFS, we propose to shuffle the received samples in the DD domain such that samples experiencing the same delay but different Doppler spreads are grouped together. It is shown through theoretical analysis that the proposed shuffling operation yields a special block-circulantlike structure of the DD domain channel matrix. Enabled by the special structure, we propose to develop an iterative receiver that performs coherent matrix combining (CMC) with minimum mean squared error (MMSE) detection in the DD domain. The proposed receiver can collect the diversity in both the delay and Doppler domains while simultaneously suppress the negative impacts of DD domain intersymbol interference (ICI). Simulation results show that the proposed DD-CMC-MMSE receiver achieves significant performance gain over the commonly used message passing (MP) receiver for OTFS systems. Yanjun Pan 0001, Jingxian Wu 0001, Jinhong Yuan |
ICC | 1 |
| 2024 | Detection of Overshadowing Attack in 4G and 5G NetworksabstractDespite the promises of current and future cellular networks to increase security, privacy, and robustness, 5G networks are designed to streamline discovery and initiate connections with limited computation and communication costs, leading to the predictability of control channels. This predictability enables signal-level attacks, particularly on unprotected initial access signals. To assess vulnerability in access control and enhance robustness in cellular networks, we present a strategic approach leveraging O-RAN architecture in this paper that detects and classifies signal-level attacks for actionable countermeasure defense. We evaluate attack scenarios of various power levels on both 4G/LTE-Advanced and 5G communication systems. We categorize the types of attack models based on the attack cost: Overshadowing and Jamming. Overshadowing represents low attack power categories with time and frequency synchronization, while Jamming represents un-targeted attacks that cause similar quality-of-service degradation as overshadowing attacks but require high power levels. Our detection strategy relies on supervised machine-learning models, specifically a Reservoir Computing (RC) based supervised learning approach that leverages physical and MAC-layer information for attack detection and classification. We demonstrate the efficacy of our detection strategy through extensive experimental evaluations using the O-RAN platform with software-defined radios (SDRs) and commercial off-the-shelf (COTS) user equipment (UEs). Empirical results show that our method can classify the change in statistics caused by most overshadowing and jamming attacks with more than 95% classification accuracy. Jiongyu Dai, Usama Saeed, Ying Wang 0113, Yanjun Pan 0001, Haining Wang 0001, Kevin T. Kornegay, Lingjia Liu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | 5G RRC Protocol and Stack Vulnerabilities Detection via Listen-and-LearnabstractThe paper proposes a protocol-independent Listen-and -Learn (LAL) based fuzzing system, which provides a systematic solution for vulnerabilities and unintended emergent behavior detection with sufficient automation and scalability, for 5G and nextG protocols and large-scale open programmable stacks. We use the relay model as our base and capture and interpret packets without prior knowledge of protocols imple-mentation. Radio Resource Control (RRC) is selected proof of concept of the proposed system. Our fuzzing architecture incorporates two abstractions of different dimension fuzzing-command-level and bit-level, and the proposed LAL fuzzing framework focuses on command-level fuzzing covering potential attacks by autonomously generating a comprehensive fuzzing case set. Our analysis of 39 RRC states successfully illustrates 129 vulnerabilities resulting in RRC connection establishment failure from 205 command-level fuzzing cases and reveals insights into exploitable vulnerabilities in each channel of RRC procedure. Furthermore, to assess risks and prevent potential vulnerability, we use the Long Short-Term Memory (LSTM) based model to perform a deep analysis of transaction states in sequenced commands. With the LSTM based model, we efficiently predict more than 95% connection failure at an average duration of 0.059 seconds after the fuzzing attack and provide sufficient time for proactive defense before RRC connection completion or failure, with an average of 3.49 seconds. The rapid vulnerability prediction capability also enables proactive defenses to potential attacks. The proposed fuzzing system offers sufficient automation, scalability, and usability to improve 5G security assurance, and could be used for existing and newly released protocols and stacks validation and real-time system vulnerability detection and prediction. Jingda Yang, Ying Wang 0113, Tuyen X. Tran, Yanjun Pan 0001 |
CCNC | 4 |
| 2023 | Cross-Modality Continuous User Authentication and Device Pairing With Respiratory PatternsabstractAt-home screening systems for obstructive sleep apnea (OSA) can bring convenience to remote chronic disease management. However, the unsupervised home environment is subject to spoofing and unintentional interference from the household member. To improve robustness, this work presents SIENNA, an insider-resistant breathing-based authentication/pairing protocol. SIENNA leverages the uniqueness of breathing patterns to automatically and continuously authenticate a user and pairs a mobile OSA app and a physiological monitoring radar system (PRMS). SIENNA does not require biometric enrollment and instead transforms the respiratory measurements taken during the users routine physical checkup into breathing biometrics comparable with the PRMS readings. Furthermore, it can operate within a noisy multi-target home environment and is secure against a co-located attacker through the usage of JADE-ICA, fuzzy commitment, and friendly jamming. We fully implemented SIENNA and evaluated its performance with medium-scale trials. Results show that SIENNA can achieve reliable (> 90% success rate) user authentication and secure device pairing in a noisy environment against an attacker with full knowledge of the authorized users breathing biometrics. Shekh M. M. Islam, Yao Zheng 0004, Yanjun Pan 0001, Marionne Millan, Willy Chang, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun |
IEEE Internet Things J. | 3 |
| 2022 | PoF: Proof-of-Following for Vehicle Platoons
Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Loukas Lazos, Ming Li 0003, Nirnimesh Ghose |
NDSS | 3 |
| 2021 | Insider-Resistant Context-Based Pairing for Multimodality Sleep Apnea TestabstractThe increasingly sophisticated at-home screening systems for obstructive sleep apnea (OSA), integrated with both contactless and contact-based sensing modalities, bring convenience and reliability to remote chronic disease management. However, the device pairing processes between system components are vulnerable to wireless exploitation from a non-compliant user wishing to manipulate the test results. This work presents SIENNA, an insider-resistant context-based pairing protocol. SIENNA leverages JADE-ICA to uniquely identify a user's respiration pattern within a multi-person environment and fuzzy commitment for automatic device pairing, while using friendly jamming technique to prevent an insider with knowledge of respiration patterns from acquiring the pairing key. Our analysis and test results show that SIENNA can achieve reliable (> 90% success rate) device pairing under a noisy environment and is robust against the attacker with full knowledge of the context information. Yao Zheng 0004, Shekh M. M. Islam, Yanjun Pan 0001, Marionne Millan, Samson Aggelopoulos, Brian Lu, Alvin Yang, Thomas Yang 0003, Stephanie Aelmore, Willy Chang, Alana Power, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun |
GLOBECOM | 3 |
| 2021 | Man-in-the-Middle Attack Resistant Secret Key Generation via Channel RandomizationabstractPhysical-layer based key generation schemes exploit the channel reciprocity for secret key extraction, which can achieve information-theoretic secrecy against eavesdroppers. Such methods, although practical, have been shown to be vulnerable against man-in-the-middle (MitM) attacks, where an active adversary, Mallory, can influence and infer part of the secret key generated between Alice and Bob by injecting her own packet upon observing highly correlated channel/RSS measurements from Alice and Bob. As all the channels remain stable within the channel coherence time, Mallory's injected packets cause Alice and Bob to measure similar RSS, which allows Mallory to successfully predict the derived key bits. To defend against such a MitM attack, we propose to utilize a reconfigurable antenna at one of the legitimate transceivers to proactively randomize the channel state across different channel probing rounds. The randomization of the antenna mode at every probing round breaks the temporal correlation of the channels from the adversary to the legitimate devices, while preserving the reciprocity of the channel between the latter. This prevents key injection from the adversary without affecting Alice and Bob's ability to measure common randomness. We theoretically analyze the security of the protocol and conduct extensive simulations and real-world experiments to evaluate its performance. Our results show that our approach eliminates the advantage of an active MitM attack by driving down the probability of successfully guessing bits of the secret key to a random guess. Yanjun Pan 0001, Ziqi Xu 0006, Ming Li 0003, Loukas Lazos |
MobiHoc | 1 |
| 2021 | Online Learning-Based Reconfigurable Antenna Mode Selection Exploiting Channel CorrelationabstractReconfigurable antennas (RAs) emerged as a promising technology that can deal with channel variations and enhance the capacity and reliability of the wireless channel. To fully exploit the advantage of RAs, optimal antenna modes need to be selected in an online manner. However, the channel statistics are unknown a priori. Multi-armed bandit-based online learning algorithms were proposed to address this challenge, but the main drawback of existing approaches are that their regret scales linearly with the number of antenna modes, which converges slowly when the latter is large. To improve the scalability, we first apply an existing algorithm: Thompson sampling via Gaussian process (TS-GP), and propose two new algorithms for antenna mode selection: upper confidence bound with channel prediction (UCB-CP) and Thompson Sampling with channel prediction (TS-CP). TS-GP uses Gaussian prior to model the reward distribution of each antenna mode, as well as the correlation among them. UCB-CP and TS-CP exploit channel modeling to predict the channel conditions of unexplored antenna modes at each time step, by relating the correlation between different channel states to the underlying antenna modes. We prove the finite-time regret bound of UCB-CP and show that it is independent from the number of arms, when the expected channel estimation errors are small enough. We also extend the algorithms to the mobile setting. Both simulation results and real-world experiments show that all of our proposed learning algorithms can significantly improve the convergence rate and yield much lower regret (thus higher throughput) than existing schemes. Tianchi Zhao 0001, Ming Li 0003, Yanjun Pan 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2020 | ROBin: Known-Plaintext Attack Resistant Orthogonal Blinding via Channel RandomizationabstractOrthogonal blinding based schemes for wireless physical layer security aim to achieve secure communication by injecting noise into channels orthogonal to the main channel and corrupting the eavesdropper’s signal reception. These methods, albeit practical, have been proven vulnerable against multiantenna eavesdroppers who can filter the message from the noise. The vulnerability is rooted in the fact that the main channel state remains static in spite of the noise injection, which allows an eavesdropper to estimate it promptly via known symbols and filter out the noise. Our proposed scheme leverages a reconfigurable antenna for Alice to rapidly change the channel state during transmission and a compressive sensing based algorithm for her to predict and cancel the changing effects for Bob. As a result, the communication between Alice and Bob remains clear, whereas randomized channel state prevents Eve from launching the knownplaintext attack. We formally analyze the security of the scheme against both single and multi-antenna eavesdroppers and identify its unique anti-eavesdropping properties due to the artificially created fast-changing channel. We conduct extensive simulations and real-world experiments to evaluate its performance. Empirical results show that our scheme can suppress Eve’s attack success rate to the level of random guessing, even if she knows all the symbols transmitted through other antenna modes. Yanjun Pan 0001, Yao Zheng 0004, Ming Li 0003 |
INFOCOM | 1 |
| 2020 | Data inference from encrypted databases: a multi-dimensional order-preserving matching approachabstractDue to increasing concerns of data privacy, databases are being encrypted before they are stored on an untrusted server. To enable search operations on the encrypted data, searchable encryption techniques have been proposed. Representative schemes use order-preserving encryption (OPE) for supporting efficient Boolean queries on encrypted databases. Yet, recent works showed the possibility of inferring plaintext data from OPE-encrypted databases, merely using the order-preserving constraints, or combined with an auxiliary plaintext dataset with similar frequency distribution. So far, the effectiveness of such attacks is limited to single-dimensional dense data (most values from the domain are encrypted), but it remains challenging to achieve it on high-dimensional datasets (e.g., spatial data), which are often sparse in nature. In this paper, for the first time, we study data inference attacks on multi-dimensional encrypted databases (with 2-D as a special case). We formulate it as a 2-D order-preserving matching problem and explore both unweighted and weighted cases, where the former maximizes the number of points matched using only order information and the latter further considers points with similar frequencies. We prove that the problem is NP-hard, and then propose a greedy algorithm, along with a polynomial-time algorithm with approximation guarantees. Experimental results on synthetic and real-world datasets show that the data recovery rate is significantly enhanced compared with the previous 1-D matching algorithm. Yanjun Pan 0001, Alon Efrat, Ming Li 0003, Boyang Wang 0001, Hanyu Quan, Joseph S. B. Mitchell, Jie Gao 0001, Esther M. Arkin |
MobiHoc | 1 |
| 2020 | Message Integrity Protection Over Wireless Channel: Countering Signal Cancellation via Channel RandomizationabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel signal cancellation attack framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments as well as the online nature of the attack. Based on theoretical results, we propose a practical channel randomization approach to defend against signal cancellation attack, which exploits state diversity and swift reconfigurability of reconfigurable antenna to increase randomness and meanwhile reduce correlation of channel state information. We show that by proactively mimicking the attacker and placing restrictions on the attacker's location, we can bound the attacker's knowledge of channel state information, thereby achieve a guaranteed level of message integrity protection in practice. Besides, we conduct extensive experiments and simulations to show the security and performance of the proposed approach. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yanjun Pan 0001, Yantian Hou, Ming Li 0003, Ryan M. Gerdes, Kai Zeng 0001, Md. Asaduzzaman Towfiq, Bedri A. Cetiner |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | On the Throughput Limit of Multi-Hop Wireless Networks with Reconfigurable AntennasabstractReconfigurable antenna (RA) has emerged as a disruptive antenna technology with the potential of significantly improving the capacity of wireless links, by agilely reconfiguring its antenna states. Through jointly optimizing antenna state selection, routing and scheduling, it offers another dimension of opportunity to enhance end- to-end (E2E) throughput in multi-hop wireless networks (MWNs). However, the throughput limit of MWNs with RAs has not been well understood, due to challenges in theoretical modeling and computational intractability caused by a large number of states. In this work, we endeavor to systematically study this problem. We first propose a general antenna state-link conflict graph model to capture the intricate state-link association and corresponding interference relationship in the network. Based on this model, we formulate a max-flow based optimization framework to derive the throughput bound of a given MWN. As this problem is NP-hard, we explore column generation to solve it more efficiently, and propose a heuristic algorithm which can also accelerate the optimal solution. Simulation results show that our proposed algorithms can efficiently approach or compute the optimal throughput, and validate the advantage of antenna reconfigurability in MWNs. Yanjun Pan 0001, Ming Li 0003, Neng Fan, Yantian Hou |
SECON | 1 |