Yiwen Hu 0002

dblp:195/8063-2 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0002-8790-5579ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks, and Countermeasures
abstract
Lost and stolen phone reporting services are widely deployed to prevent unauthorized device use by blacklisting International Mobile Equipment Identities (IMEIs). However, through an extensive experimental study across three major U.S. carriers and diverse mobile devices, we discover that these services unexpectedly introduce severe and previously unexplored security risks. Specifically, we identify six new vulnerabilities spanning the device, carrier, and cross-carrier domains, which together enable attackers to arbitrarily block cellular devices from accessing carrier networks. Building on these findings, we design and validate two practical denial-of-service (DoS) attacks: Home Security System Freezing, which disables cellular-based home security gateways and blocks alarm delivery, and Zero-Day Flagship Phone Ambush, which preemptively blocks brand-new flagship phones from accessing mobile services at launch. Both attacks are experimentally validated on operational 5G/4G networks. Finally, we propose practical, backward-compatible countermeasures and implement a prototype to evaluate their effectiveness.
Min-Yue Chen, Yiwen Hu 0002, Yu-An Chen, Chi-Yu Li 0001, Tian Xie 0001, Guan-Hua Tu
MobiSys2
2026 When Mobile Equipment Security Lags Behind Infrastructure: Vulnerabilities, Attacks, and Countermeasures in IMS Services
Jingwen Shi, Min-Yue Chen, Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Yiwen Hu 0002, Man-Hsin Chen, Haitian Yan, Chi-Yu Li 0001, Chunyi Peng 0001
IEEE Trans. Netw.6
2024 Uncovering Problematic Designs Hindering Ubiquitous Cellular Emergency Services Access
abstract
Cellular networks provide the most accessible emergency services with ubiquitous coverage, yet their emergency-specific designs remain largely unexplored. To systematically explore potential design defects that lead to failures or delays in emergency services, we introduce M911-Verifier, an emergency-specific model checking tool. It reveals many counterintuitive findings regarding the ubiquitous access support for cellular emergency services. Our study shows that, despite sufficient wireless signal coverage, users may still experience prolonged emergency call setup times, call initiation failures, or call drops due to flaws in the design of cellular emergency services. These design defects arise from three major causes: problematic network selection for initiating emergency calls, emergency-unaware call operation, and network escalation forbidden during emergency calls. The impacts of these defects have been experimentally validated across three U.S. carriers and two Taiwan carriers using commodity smartphones. Finally, we propose solutions and evaluate their effectiveness.
Yiwen Hu 0002, Min-Yue Chen, Haitian Yan, Chuan-Yi Cheng, Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Chunyi Peng 0001, Li Xiao 0001, Jiliang Tang
MobiCom1
2024 IMS is Not That Secure on Your 5G/4G Phones
abstract
IMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities.
Jingwen Shi, Sihan Wang 0002, Min-Yue Chen, Guan-Hua Tu, Tian Xie 0001, Man-Hsin Chen, Yiwen Hu 0002, Chi-Yu Li 0001, Chunyi Peng 0001
MobiCom7
2024 Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure Designs
abstract
Cellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities.
Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
IEEE/ACM Trans. Netw.2
2024 Dissecting Operational Cellular IoT Service Security: Attacks and Defenses
abstract
More than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to${\$}226$with less than 120 MB spam traffic, increase an IoT text bill at a rate of${\$}5$per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions.
Sihan Wang 0002, Tian Xie 0001, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001
IEEE/ACM Trans. Netw.9
2024 On the Inference of Original Graph Information from Graph Embeddings
abstract
Graph embedding converts a graph data into a low dimensional space to preserve the original graph information. However, graph data can be reconstructed by malicious adversaries to train machine learning models from graph embeddings. This paper studies to what extent an adversary (without the original graph data) can recover the original graph data from graph embeddings. To quantify the original graph information leakage from graph embeddings, we develop a deep neural network model InferNet that can be used by adversaries to infer the original graph information from an adversary-accessible graph embedding database. More specifically, we propose the data-free reversed knowledge distillation technique to support the InferNet training even if the original graph dataset is absent. To ensure the performance of InferNet, we design two cycle-consistency loss functions to have an interactive training of InferNet over three series of datasets. To further enhance the performance of InferNet, we provide a joint training algorithm that simultaneously trains the pseudo-sample generator and InferNet, which significantly reduces the storage space. We evaluate the performance of InferNet on three datasets, and the intensive experiments demonstrate that InferNet can infer the original graph information from the graph embedding dataset with high accuracy.
Yantao Li 0001, Huafeng Qin, Yiwen Hu 0002, Gang Zhou 0002
ACM Trans. Sens. Networks5
2023 Towards Inference of Original Graph Data Information from Graph Embeddings
abstract
This paper studies to what extent an adversary (without the original graph data) can recover the original raw graph data from graph embeddings. To quantify the original graph data information leakage from graph embeddings, we develop a deep neural network model InferNet that can be used by adversaries to infer the original graph data information from an adversary-accessible graph embedding database. Specifically, we propose the data-free reversed knowledge distillation (KD) technique to support InferNet training even if the original graph dataset is absent. To improve the performance of InferNet, we design two cycle-consistency loss functions to have an interactive training of InferNet over three series of datasets. Our intensive experiments demonstrate that InferNet can infer the original graph data information from the graph embedding dataset with high accuracy.
Yantao Li 0001, Huafeng Qin, Yiwen Hu 0002
IJCNN5
2022 Uncovering insecure designs of cellular emergency services (911)
abstract
Cellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities.
Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
MobiCom1
2021 Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and Countermeasures
abstract
Nowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards.
Yiwen Hu 0002, Sihan Wang 0002, Guan-Hua Tu, Li Xiao 0001, Tian Xie 0001, Chi-Yu Li 0001
CODASPY1
2021 Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasures
abstract
More than 150 cellular networks worldwide have rolled out massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover five vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices and launch data/text spamming attacks against them. We experimentally validate these vulnerabilities and attacks with three major U.S. IoT carriers. The attack evaluation result shows that the adversary can raise an IoT data bill by up to $226 with less than 120 MB spam traffic and increase an IoT text bill at a rate of $5 per second; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions.
Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001
MobiCom8