Zhenlin An

dblp:203/8833 · DBLP profile ↗
← Back
57ranked-venue papers
14as first author
45since 2021 · last 2026
0000-0003-4120-773XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 53 · 14 first-author · 41 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MetaRFence: Protecting Human Motion Privacy Against RFID Sensing via Metasurface
abstract
Radio Frequency Identification (RFID) technology has emerged as a pervasive modality for human motion sensing in applications such as smart environments and healthcare monitoring. However, the inherent through-wall sensing capability of RFID technology raises critical privacy concerns regarding the unintended leakage of human motion information, a challenge that has not been adequately addressed. To fill this gap, we present a metasurface-based RFID sensing defence (MetaRFence), the first system designed to protect human motion privacy against adversarial through-wall RFID sensing. To this end, we first devise a programmable metasurface comprising 1-bit phase shifters to systematically obfuscate motion-induced signal patterns. Then, we characterize the metasurface's impact on RFID signals across temporal and spectral domains through comprehensive theoretical modeling and empirical investigations. However, our analysis reveals that it is non-trivial to achieve effective signal obfuscation in both domains, primarily due to a fundamental trade-off between increasing temporal signal variation and masking human motion in its spectrum. To overcome this, we judiciously devise a metasurface controlling strategy that jointly optimizes the signal entropy, variance, and spectrum distribution to reach a balance between temporal and spectral motion obfuscation. Our comprehensive experiments demonstrate thatMetaRFencereduces adversarial through-wall motion detection rates to$\leq$6%, decreases the F1-score of human gesture recognition to$\leq$0.11 on average, and amplifies respiration rate estimation errors by 3×, establishing a robust defense mechanism for RFID-based motion privacy protection.
Zheng Shi 0006, Zhikai Ding, Yanni Yang 0003, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001
IEEE Trans. Mob. Comput.4
2026 Toward Scalable Reconfigurable Intelligent Surfaces Using Commercial RFIDs
abstract
Reconfigurable Intelligent Surfaces (RISs) have emerged as cost-effective technologies for improving wireless signal transmission. Conventional RIS designs, however, face challenges such as bulkiness, high production costs, limited scalability, and complex installation due to their reliance on wired connections. In this work, we introduce MetaMosaic, a novel RIS platform that repurposes 920 MHz RFID tags into battery-free unit cells, enabling an affordable, scalable, and flexible one-bit phase-modulated RIS. The system is engineered for compatibility with 2.4 GHz Wi-Fi communications while being controlled at 920 MHz. Our design incorporates two central innovations: the transformation of commercial RFID tags into functional unit cells and the development of a tailored neural radiance field to guide efficient reconfiguration. To further enhance global search capability and support multi-hotspot alignment, we extend the system with a genetic algorithm (GA)-based optimization strategy. Compared with the vanilla MetaMosaic, the GA-based MetaMosaic achieves an additional 3.1 dB signal strength improvement and enables simultaneous enhancement for up to five target points. Extensive testing across ten diverse environments demonstrates that MetaMosaic consistently boosts signal strength, with a mean gain of 19 dB over non-RIS setups. This outperforms current leading RIS systems by a 3-fold improvement.
Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025
IEEE Trans. Mob. Comput.6
2025 GA-Clip: Semantic-Aware Graph Augmentation for Contrastive Learning
abstract
Recent advancements in Text-Attributed Graphs (TAGs) have attracted significant attention for their wide-ranging applications in domains such as social networks, academics, and e-commerce. The powerful text-processing capabilities of pre-trained language models offer a promising avenue for effectively integrating textual attributes with graph structures. However, existing methods exhibit two key limitations: (1) reliance on rigid graph construction processes that fail to capture a comprehensive view of the text-attributed graph data; (2) insufficient fusion of textual semantics and graph topology, leading to information loss, unstable training, and limited generalization across diverse downstream tasks. In this work, we propose GA-Clip, a novel semantic-aware graph augmentation contrastive learning model. We leverage the pre-trained language model to generate semantic edges that extract the fine-grained topology within the text feature space to augment the graph structure. We then separately employ the graph and text encoders to sufficiently fuse the different modalities through a modified self-supervised contrastive learning approach. This augmentation mitigates the dependency on cumbersome graph construction processes and integrates information from different modalities, which jointly enables scalable graph learning on coarse-grained, large-scale source data. Experimental results demonstrated that our approach achieved a 2-4% improvement over the SOTA methods in accuracy across multiple datasets, validating the effectiveness of the proposed method.
Shuaiqi Lu, Yi Guo 0008, Zhenlin An, Ning Huang 0006
ICME3
2025 Commercial RFIDs as Reconfigurable Intelligent Surfaces
Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025
INFOCOM5
2025 RFNOID: Protecting RFID Motion Privacy via Metasurface
Yanni Yang 0003, Zheng Shi 0006, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001
INFOCOM3
2025 Physics-Informed AI for Wireless Communication and Sensing
abstract
Deep learning models encounter fundamental challenges when directly applied to wireless systems, including limited interpretability, low data efficiency, and poor adaptability in dynamic environments. To overcome these challenges, this extended abstract presents my research on embedding electromagnetic physics into AI frameworks to create physics-informed models for wireless communication and sensing. These hybrid models leverage the structure of physical laws alongside data-driven learning, leading to substantial improvements in accuracy, generalization, interpretability, and robustness across complex scenarios. My work demonstrates how this methodology reforms wireless systems across multiple key applications: channel prediction, indoor localization, antenna design, and hardware fingerprinting. Together, these efforts establish a new paradigm for next-generation wireless system design.
Zhenlin An
MobiSys1
2025 LeakyFeeder: In-Air Gesture Control Through Leaky Acoustic Waves
abstract
We present LeakyFeeder, a mobile application that explores the acoustic signals leaked from headphones to reconstruct gesture motions around the ear for fine-grained gesture control. To achieve this goal, LeakyFeeder repurposes the speaker and a single feedforward microphone on active noise cancellation (ANC) headphones as a SONAR system, using inaudible frequency-modulated continuous-wave (FMCW) signals to track gesture reflections for accurate sensing. Since this single-receiver SONAR system is unable to differentiate reflection angles and further disentangle signal reflections from different gesture parts, we draw on principles of multi-modal learning to frame gesture motion reconstruction as a multi-modal translation task and propose a deep learning-based approach to fill the information gap between low-dimensional FMCW ranging readings and high-dimensional 3D hand movements. We implement LeakyFeeder on a pair of Google Pixel Buds and conduct experiments to examine the efficacy and robustness of LeakyFeeder in various conditions. Experiments based on six gesture types inspired by Apple Vision Pro demonstrate that LeakyFeeder achieves a PCK performance of 89% at 3cm across ten users, with an average MPJPE and MPJRPE error of 2.71cm and 1.88cm, respectively.
Yongjie Yang 0008, Tao Chen 0033, Zhenlin An, Shirui Cao, Xiaoran Fan, Longfei Shangguan
SenSys3
2025 Wireless Eavesdropping on Wired Audio With Radio-Frequency Retroreflector Attack
abstract
Recent studies have demonstrated the feasibility of eavesdropping on audio via radio frequency signals or videos, which capture physical surface vibrations from surrounding objects. However, these methods are inadequate for intercepting internally transmitted audio through wired media. In this work, we introduce radio-frequency retroreflector attack (RFRA) and bridge this gap by proposing an RFRA-based eavesdropping system,RF-Parrot${}^{\mathbf {2}}$, capable of wirelessly capturing audio signals transmitted through earphone wires. Our system entails embedding a tiny field-effect transistor within the wire to establish a battery-free retroreflector, whose reflective efficiency is correlated with the amplitude of the audio signal. To preserve the details of audio signals, we designed a unique retroreflector using a depletion-mode MOSFET (D-MOSFET). This MOSFET can be triggered by any voltage level present in the audio signals, thus guaranteeing no information loss during activation. However, the D-MOSFET introduces a nonlinear convolution operation on the original audio, resulting in distorted audio eavesdropping. Thus, we devised an engineering solution which utilized a novel convolutional neural network in conjunction with an efficient Parallel WaveGAN vocoder to reconstruct the original audio. Our comprehensive experiments demonstrate a strong similarity between the reconstructed audio and the original, achieving an impressive 95% accuracy in speech command recognition.
Genglin Wang, Zheng Shi 0006, Yanni Yang 0003, Zhenlin An, Pengfei Hu 0001, Xiuzhen Cheng, Jiannong Cao 0001
IEEE Trans. Mob. Comput.4
2025 Romeo: Fault Detection of Rotating Machinery via Fine-Grained mmWave Velocity Signature
abstract
Real-time velocity monitoring is pivotal for fault detection of rotating machinery. However, existing methods rely on either troublesome deployments of optical encoders and IMU sensors or various tachometers delivering coarse-grained velocity measurements insufficient for fault detection. To overcome these limitations, we proposeRomeoas the first work to exploit the mmWave radar forrotatingmachinery fault detection by extracting a fine-grained velocity signature. Though mmWave radars should capture instant rotation information with their claimed high sensitivity and sampling rate, direct adoption entails significant efforts for high-precision velocity measurement per radar to handle; particularly, exhausted system calibration and noise interference. To this end, we first develop a phase-velocity model to characterize the relationship between the mmWave signal phase and the fine-grained angular velocity. We then explore the geometric properties of specific positions in the rotation trajectory to precisely calibrate the rotation sensing model, leading to an iterative algorithm for accurate angular velocity measurement. Finally, we propose a simple yet effective fault detection algorithm by extracting a unique velocity signature. Our extensive experiments showRomeoachieves a median error of 0.4$^\circ$/s for fine-grained angular speed measurement, outperforming SOTA solutions with over ×16 angular speed granularity and ×7 measurement precision.
Yanni Yang 0003, Pengfei Hu 0001, Jun Luo 0001, Zhenlin An, Jiannong Cao 0001, Dongxiao Yu, Xiuzhen Cheng
IEEE Trans. Mob. Comput.4
2025 Frequency-Aware Neural Radio-Frequency Radiance Fields
abstract
Although Maxwell discovered the physical laws of electromagnetic waves about 160 years ago, accurately modeling the propagation of RF signals in large and complex electrical environments remains a persistent challenge. This complexity arises from the interactions between the RF signal and various obstacles, including reflection and diffraction. Inspired by the success of neural networks in mapping the optical field in computer vision, we introduce the neural radio-frequency radiance field, or$\mathbf{NeRF}^{2}$. This represents a continuous volumetric scene function that effectively models RF signal propagation. Remarkably, after only a sparse amount of training with signal measurements,$\mathbf{NeRF}^{2}$can accurately predict the nature and origin of signals received at any location, assuming the transmitter's position is known. Additionally, we propose the frequency-aware$\mathbf{NeRF}^{2}$to enhance channel prediction performance for wideband signals using an RF prism module. Compared to the vanilla$\mathbf{NeRF}^{2}$, the frequency-aware$\mathbf{NeRF}^{2}$achieves a 4 dB improvement in SNR for FDD OFDM channel estimation and is nearly 3.5 × faster. Functioning as a physical-layer neural network,$\mathbf{NeRF}^{2}$also supports application-layer artificial neural networks (ANNs) by generating synthetic training datasets. Our empirical results demonstrate that augmented sensing enhances the accuracy of AoA estimation, achieving an approximate 50% improvement.
Zhenlin An, Qingrui Pan, Lei Yang 0025
IEEE Trans. Mob. Comput.2
2024 RF-Parrot: Wireless Eavesdropping on Wired Audio
abstract
Recent works demonstrated that we can eavesdrop on audio by using radio frequency signals or videos to capture the physical surface vibrations of surrounding objects. They fall short when it comes to intercepting internally transmitted audio through wires. In this work, we first address this gap by proposing a new eavesdropping system, RF-Parrot, that can wirelessly capture the audio signal transmitted in earphone wires. Our system involves embedding a tiny field-effect transistor in the wire to create a battery-free retroreflector, with its reflective efficiency tied to the audio signal’s amplitude. To capture full details of the analog audio signals, we engineered a novel retroreflector using a depletion-mode MOSFET, which can be activated by any voltage of the audio signals, ensuring no information loss. We also developed a theoretical model to demystify the nonlinear transmission of the retroreflector, identifying it as a convolution operation on the audio spectrum. Subsequently, we have designed a novel convolutional neural network-based model to accurately reconstruct the original audio. Our extensive experimental results demonstrate that the reconstructed audio bears a strong resemblance to the original audio, achieving an impressive 95% accuracy in speech command recognition.
Yanni Yang 0003, Genglin Wang, Zhenlin An, Xiuzhen Cheng, Pengfei Hu 0001
INFOCOM3
2024 Enabling Cross-Medium Wireless Networks with Miniature Mechanical Antennas
abstract
Within the burgeoning 6G wireless network landscape, there is an intensified push toward achieving all-encompassing accessibility through integrated solutions spanning a multitude of domains. Notwithstanding recent advancements, the conventional relay-centric communication paradigms grapple with scalability and optimal performance issues. In this paper, we introduce MeAnt ---a versatile IoT platform uniquely architected to foster seamless cross-medium communication by leveraging the compact design of piezoelectric-based mechanical antennas (Piezo-MAs). By capitalizing on the propagation attributes of medium-frequency radios emitted from Piezo-MAs, MeAnt promises communication across diverse environments such as air, water, soil, concrete, and even biological tissue, all while maintaining a compact antenna footprint. Moreover, in light of challenges such as potential interference from AM broadcasts and the intrinsic unidirectional nature of Piezo-MAs, we have developed a finely crafted full-stack communication protocol. Comprehensive tests underscore the system's proficiency, demonstrating a penetration depth of up to 10 m in cross-medium environments and realizing a throughput of 8.7 kbps.
Zhenlin An, Donghui Dai, Jingyu Tong, Shuijie Long, Lei Yang 0025
MobiCom2
2024 Binary Optical Machine Learning: Million-Scale Physical Neural Networks with Nano Neurons
abstract
Deep learning excels in advanced inference tasks using electronic neural networks (ENN), but faces energy consumption and limited computation speed challenges. To mitigate this, optical neural networks (ONNs) were developed, utilizing light for computations. However, their high manufacturing costs limited accessibility. In this work, we first introduce the binary optical neural network (BONN) - a streamlined ONN variant with binarized weights, which significantly reduces fabrication complexities and costs. Specifically, we address (i) the development of a binarization weight function aligned with backward-error propagation, and (ii) a simulation-based training for extra-large neural networks housing millions of neurons. We prototype six BONNs, each comprising four 0.8 × 0.8mm2 layers with one million 800 nm diameter neurons. Costs are cut to 0.13 USD per layer, marking a substantial decrease of 769× from previous ONNs. Experimental results reveal BONNs consume 2, 405× less power than leading ENNs while maintaining an average recognition accuracy of 74% across six datasets.
Xueyuan Yang, Zhenlin An, Qingrui Pan, Lei Yang 0025, Dangyuan Lei, Yulong Fan
MobiCom2
2024 In-Sensor Machine Learning: Radio Frequency Neural Networks for Wireless Sensing
abstract
Growing interest in wireless sensing, a cornerstone of the Artificial Intelligence of Things (AIoT), stems from its ability to gauge target states through nearby wireless signals. However, the escalating count of AIoT nodes escalates redundant data flow and exacerbates energy usage in AI cloud infrastructures. This amplifies the urgency for machine learning techniques that function in proximity to, or directly within, sensors. In light of this, we present the Radio-Frequency Neural Network (RFNN), a novel architecture that uses cost-effective transmissive intelligent surfaces to mimic the functions of a traditional neural network near (or in) sensors, transforming sensory nodes into intelligent terminals primed for machine learning. We first devised a unique training algorithm to mitigate the issues arising from unmodelable error-backward propagation; secondly, we incorporated contrastive learning to address the issue of blind labels stemming from environmental uncertainties. Our RFNN prototype, resonating at a 5 GHz WiFi bandwidth, has been honed across nine varied sensing tasks. The rigorous evaluation shows that it achieves a mean accuracy of 91.5% while consuming only 67.2 μJ of energy. This positions RFNN as a match in inferencing prowess to its electronic neural network counterparts but with significantly diminished energy demands.
Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025
MobiHoc2
2024 Understanding Localization by a Tailored GPT
abstract
Conventional deep learning approaches for indoor localization often suffer from their reliance on high-quality training samples and display limited adaptability across varied scenarios. To address these challenges, we repurpose the Transformer model, celebrated for its profound contextual insights, to explore the underlying principles of indoor localization. Our microbenchmark results compellingly demonstrate the superiority of our approach, showing improvements of 30% to 70% across a diverse set of 50 scenarios compared to other state-of-the-art methods. In conclusion, we propose a specialized Generative Pre-training Transformer (GPT) variant, termed LocGPT, configured with 36 million parameters that are tailored to facilitate transfer learning. By fine-tuning this pre-trained model, we achieve near-par accuracy using merely half the conventional dataset, thereby heralding a pioneering stride in transfer learning within the indoor localization domain.
Zhenlin An, Qingrui Pan, Lei Yang 0025
MobiSys3
2024 RFID+: Spatially Controllable Identification of UHF RFIDs via Controlled Magnetic Fields
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025
NSDI2
2024 Privacy-preserving human activity sensing: A survey
abstract
With the prevalence of various sensors and smart devices in people’s daily lives, numerous types of information are being sensed. While using such information provides critical and convenient services, we are gradually exposing every piece of our behavior and activities. Researchers are aware of the privacy risks and have been working on preserving privacy while sensing human activities. This survey reviews existing studies on privacy-preserving human activity sensing. We first introduce the sensors and captured private information related to human activities. We then propose a taxonomy to structure the methods for preserving private information from two aspects: individual and collaborative activity sensing. For each of the two aspects, the methods are classified into three levels: signal, algorithm, and system. Finally, we discuss the open challenges and provide future directions.
Yanni Yang 0003, Pengfei Hu 0001, Jiaxing Shen, Haiming Cheng, Zhenlin An, Xiulong Liu 0001
High Confid. Comput.5
2024 Pushing the Boundaries of High-Precision AoA Estimation With Enhanced Phase Estimation Protocol
abstract
The emergence of high-precision indoor backscatter tag tracking in GPS-deprived environments has advanced applications from virtual reality to factory automation. Despite this, the high-precision tracking range remains limited to just a few meters, restricting the use of backscatters to the vicinity of checkpoints in warehouses, even though they possess a communication range of 50 m. We have identified that this limited localization range primarily originates from the butterfly effect in localization systems, where a slight phase measurement error gradually escalates into a substantial localization error. This article introduces two innovative phase estimation protocols to address the intrinsic challenges in achieving high-accuracy phase estimation over long-distance communication. The first, consistent phase estimator (CPE), resolves the$\boldsymbol {\pi }$-ambiguity commonly encountered with commercial radio-frequency identification readers. Building on this, CPE+ is designed to cancel flicker noise, neutral white noise, and restore spatial and temporal imbalances. Our experimental results demonstrate that CPE+ extends the range of accurate Angle of Arrival (AoA) estimation and centimeter-level localization from 8 to 15 m in stationary scenarios. It maintains decimeter-level accuracy across the entire 50-m communication range for CPE+ with two or more gateways. In dynamic scenarios, the error of CPE+ increases with tag speed, reaching a median localization error of 11.7 cm at 5 m for tag speeds of 50 cm/s.
Zhenlin An, Qingrui Pan, Qiongzheng Lin, Lei Yang 0025
IEEE Internet Things J.3
2024 Harnessing NFC to Generate Standard Optical Barcodes for NFC-Missing Smartphones
abstract
Mobile payments have grown significantly recently, driven by their contactless feature that minimizes COVID-19 transmission risks. While NFC offers more security and convenience than barcodes and benefits those with amblyopia, many smartphones lack NFC due to module shortages or security decisions. In this work, we present${\sf MagCode}$, an innovative method connecting NFC readers with cameras, allowing users to enjoy NFC payment security using prevalent camera technology. At the heart of${\sf MagCode}$is the harmless magnetic interference on the CMOS image sensor of a smartphone placed nearby the NFC reader, resulting in a group of barcode-like stripes appearing on the captured images. We take advantage of these stripes to encode the data and achieve simplex communication from an NFC reader to an NFC-denied or NFC-disabled smartphone. In particular, we developed a comprehensive suite of protocols spanning from the physical layer to the transport layer, and we rigorously tested our proof-of-concept prototype on 11 different smart devices. Our extensive evaluations showcase a maximum throughput of 2.58 kbps–surpassing magnetometer-based alternatives by a factor of 58–and demonstrate an average data exchange time of 1.3 seconds for mobile payment transactions between an NFC reader and a smartphone.
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025
IEEE Trans. Mob. Comput.2
2024 The Power of Precision: High-Resolution Backscatter Frequency Drift in RFID Identification
abstract
Physical-layer identification uses manufacturing variations to create unique identifiers for each device. A decade ago, this concept was applied to RFID tags using backscatter frequency drift (BFD), a specific kind of ‘fingerprint’ determined by the difference between the actual backscatter signal received and the expected backscatter link frequency (BLF). However, BFD has been undervalued due to its low performance in tag identification, achieving less than 30% accuracy. In this study, we reevaluate BFD, focusing on the issue of frequency resolution as the cause of its poor performance. The problem doesn't lie in the BFD's uniqueness, but in the inferior way we measure the frequency of a backscatter signal, which is limited by the current air interface protocol. This situation is akin to trying to identify human fingerprints using low-quality imaging. We propose a practical solution to improve the frequency resolution from kilohertz to sub-hertz, without requiring hardware or protocol changes. Our findings show that this high-resolution BFD approach significantly enhances the distinguishability to 99.4% and the identification accuracy to 94% when tested on a dataset of 7,135 RFID tags across nine models.
Qingrui Pan, Zhenlin An, Lei Yang 0025
IEEE Trans. Mob. Comput.2
2024 Jump Out of Resonance: A Practical NFC Tag Fingerprinting Scheme
abstract
NFC tag authentication is crucial for preventing tag misuse. Existing NFC fingerprinting methods use physical-layer signals, which incorporate tag hardware imperfections, for authentication purposes. However, these methods suffer from limitations such as low scalability for a large number of tags or incompatibility with various NFC protocols, hindering practical application. To address these issues, we propose a new NFC fingerprinting scheme called NFChain$^+$. Instead of sticking to the NFC resonant frequency, NFChain$^+$excavates the tag hardware uniqueness from the protocol-agnostic tag response signal using an agile and compatible frequency band of NFC to extract the tag fingerprint from a chain of tag responses over multiple frequencies. This significantly improves fingerprint scalability. However, extracting the desired fingerprint presents two challenges: fingerprint inconsistency under different configurations, and fingerprint variations due to the signal noise in generic readers. To overcome these challenges, we design an effective signal elimination method to remove the effect of device configurations and employ contrastive learning to reduce fingerprint variations for accurate tag authentication. We further cultivate a data augmentation strategy to save the cost of manually collecting fingerprint measurements for training the authentication model. Extensive experiments show that we can achieve as low as 3.4% FRR and 4.1% FAR for over 600 NFC tags.
Yanni Yang 0003, Zhenlin An, Jiannong Cao 0001, Yanwen Wang 0001, Pengfei Hu 0001, Xiuzhen Cheng
IEEE Trans. Mob. Comput.2
2024 Transfer Beamforming via Beamforming for Transfer
abstract
Although billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in the two major performance limitations (i.e., short reading range and high miss reading rate) resulting from the current harvesting inefficiency. The classic beamforming technique is regarded as the most promising solution to address the issue. However, applying it to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new paradigm calledtransfer beamforming(${\sf TBF}$), namely, the beamforming strategies can be transferred from reference tags with known positions to power up other unknown neighbor tags of interest. In short, transfer beamforming (is accomplished) via (launching) beamforming (to reference tags first) for (the purpose of) transfer. To do so, we adopt the semi-active tags as the reference tags, which can be powered up with a normal reader in a wide range. Then the beamforming is initiated and transferred to power up the low-sensitive but cost-effective passive tags surrounded by reference tags. A prototype evaluation of${\sf TBF}$with 8 transmitting antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our comprehensive evaluation reveals that${\sf TBF}$can improve the power transmission by 6.9 dB and boost the inventory speed by 2× compared with state-of-art methods.
Xueyuan Yang, Zhenlin An, Lei Yang 0025
IEEE Trans. Mob. Comput.2
2023 Transfer Beamforming via Beamforming for Transfer
abstract
Although billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in performance limitations (i.e., short reading range and high miss-reading rate) resulting from power harvesting inefficiency. However, applying classic beamforming technique to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new beamforming paradigm called transfer beamforming (TBF), namely, beamforming strategies can be transferred from reference tags with known positions to power up unknown neighbor tags of interest. Transfer beamforming (is accomplished) via (launching) beamforming (to reference tags firstly) for (the purpose of) transfer. To do so, we adopt semi-active tags as reference tags, which can be easily powered up with a normal reader. Then beamforming is initiated and transferred to power up passive tags surrounded by reference tags. A prototype evaluation of TBF with 8 antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our evaluation reveals that TBF improves the power transmission by 6.9 dB and boosts the inventory speed by 2 × compared with state-of-art methods.
Xueyuan Yang, Zhenlin An, Lei Yang 0025
INFOCOM2
2023 NFChain: A Practical Fingerprinting Scheme for NFC Tag Authentication
abstract
IEEE INFOCOM 2023 - IEEE Conference on Computer Communications, New York City, NY, USA, 17-20 May 2023
Yanni Yang 0003, Jiannong Cao 0001, Zhenlin An, Yanwen Wang 0001, Pengfei Hu 0001
INFOCOM3
2023 MagCode: NFC-Enabled Barcodes for NFC-Disabled Smartphones
abstract
Mobile payment has achieved explosive growth in recent years due to its contactless feature, which lowers the infection risk of COVID-19. In the market, near-field communication (NFC) and barcodes have become the de facto standard technologies for mobile payment. The NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopia group. Unfortunately, NFC functionality is unavailable in nearly half of smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons.
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025
MobiCom2
2023 MagCode: Bringing NFC Feature to All Smartphones
abstract
Mobile payments have experienced a significant surge in recent years, primarily due to their contactless feature that mitigates the risk of COVID-19 transmission. In this landscape, NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopic community. Unfortunately, NFC functionality is unavailable in nearly half of the smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons.
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025
MobiCom2
2023 Radio Frequency Neural Networks for Wireless Sensing
abstract
Wireless sensing has attracted considerable attention because it can sense the state of the targets by analyzing the surrounding wireless signals, which has become the key role of the artificial intelligence of things (AIoT). As the number of sensory nodes increases, large amounts of redundant data are exchanged between sensory terminals and the AI cloud. To process such large amounts of data efficiently and decrease power consumption, a machine-learning approach that operates close to or inside sensors must be developed. To this end, we present the radio-frequency neural network (RFNN), a physical neural network taking advantage of a group of transmissive intelligent surfaces (i.e., metasurfaces) to mimic the computations of a fully-connected neural network. The design is spurred by the capability of RFNNs to perform expensive multiplication and additions at the speed of light, with ultra-low power consumption. We prototype RFNN at 5 GHz for WiFi sensing regarding nine wireless sensing tasks. Extensive evaluations demonstrate the comparably equivalent inference ability as the conventional electronic neural networks while consuming less energy.
Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025
MobiCom2
2023 NeRF2: Neural Radio-Frequency Radiance Fields
abstract
Although Maxwell discovered the physical laws of electromagnetic waves 160 years ago, how to precisely model the propagation of an RF signal in an electrically large and complex environment remains a long-standing problem. The difficulty is in the complex interactions between the RF signal and the obstacles (e.g., reflection, diffraction, etc.). Inspired by the great success of using a neural network to describe the optical field in computer vision, we propose a neural radio-frequency radiance field, NeRF2, which represents a continuous volumetric scene function that makes sense of an RF signal's propagation. Particularly, after training with a few signal measurements, NeRF2 can tell how/what signal is received at any position when it knows the position of a transmitter. As a physical-layer neural network, NeRF2 can take advantage of the learned statistic model plus the physical model of ray tracing to generate a synthetic dataset that meets the training demands of application-layer artificial neural networks (ANNs). Thus, we can boost the performance of ANNs by the proposed turbo-learning, which mixes the true and synthetic datasets to intensify the training. Our experiment results show that turbo-learning can enhance performance with an approximate 50% increase. We also demonstrate the power of NeRF2 in the field of indoor localization and 5G MIMO.
Zhenlin An, Qingrui Pan, Lei Yang 0025
MobiCom2
2023 Revisiting Backscatter Frequency Drifts for Fingerprinting RFIDs: A Perspective of Frequency Resolution
abstract
Physical-layer identification is to exploit inherent randomness introduced during manufacturing to endow a unique fingerprint to a physical entity. A classic fingerprint, called backscatter frequency drift (BFD), was explored a decade ago for the physical-layer identification of RFID tags. The BFD is defined as the offset between the frequency of the backscatter signal actually received from a tag and the requested backscatter link frequency (BLF). As a context-free fingerprint, the BFD is being seriously underestimated due to its terrible performance in tag classification or identification (e.g., accuracy < 30%). In this work, we revisit BFD from the perspective of frequency resolution to pinpoint the reason behind its underperformance. Namely, the low accuracy is not because BFD is insufficiently unique in nature but rather due to the low-resolution measurement of the frequency of a backscatter signal, which is mainly constrained by the current air interface protocol. This challenge is analogous to the recognition of human fingerprints via low-resolution and blurry imaging devices. To address this issue, we propose a practical solution to improve the frequency resolution from kHz to sub-Hz, without any modification of hardware or protocols. The results demonstrate the distinguishability of high-resolution BFD is significantly increased to 99.4% and the identification accuracy is raised to 94% when in the face of 7,135 RFID tags of nine models.
Qingrui Pan, Zhenlin An, Lei Yang 0025
SECON2
2023 XiTuXi: Sealing the Gaps in Cross-Technology Communication by Neural Machine Translation
abstract
Cross-Technology Communication (CTC) is an emerging technology that enables physical-layer direct communication from a WiFi sender to other Internet of Things (IoT) receivers via waveform emulation. The previous works use the reverse engineering to find the appropriate WiFi payload that can emulate the waveform similar to the desired IoT packet in the format of the IoT protocol (e.g., ZigBee). Unfortunately, the reverse engineering approach suffers from many limitations, such as being non-reversible and unscalable, misaligning symbols, and over-relying on empiricism. In this work, we present XiTuXi, a one-size-fits-all solution to automatically achieve the CTC by taking advantage of the neural machine translation (NMT), inspired by the task comparability between CTC and homophony-based cross-linguistic communication. We employ a well-known NMT model called Transformer to learn the bit-sequence to bit-sequence translation rationale behind the CTC without human intervention. Particularly, we introduce the forward engineering to address the dilemma of acquiring training datasets. By using XiTuXi, we achieved the CTC with 30 protocol combinations (ie., 802.11b, g, n, ax, ah Å ZigBee, Bluetooth, LoRa, and Sigfox) effortlessly, which ultimately liberates the experts from previous tedious tasks.
Sicong Liao, Zhenlin An, Qingrui Pan, Jingyu Tong, Lei Yang 0025
SenSys2
2023 Inducing Wireless Chargers to Voice Out for Inaudible Command Attacks
abstract
Recent works demonstrated that speech recognition systems or voice assistants can be manipulated by malicious voice commands, which are injected through various inaudible media, such as ultrasound, laser, and electromagnetic interference (EMI). In this work, we explore a new kind of inaudible voice attack through the magnetic interference induced by a wireless charger. Essentially, we show that the microphone components of smart devices suffer from severe magnetic interference when they are enjoying wireless charging, due to the absence of effective protection against the EMI at low frequencies (100 kHz or below). By taking advantage of this vulnerability, we design two inaudible voice attacks, HeartwormAttack and ParasiteAttack, both of which aim to inject malicious voice commands into smart devices being wirelessly charged. They make use of a compromised wireless charger or accessory equipment (called parasite) to inject the voice, respectively. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and 6 types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of two proposed attacks with commercial charging settings.
Donghui Dai, Zhenlin An, Lei Yang 0025
SP2
2023 Localizing RFIDs in Pixel Dimensions
abstract
Radio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things (IoT). Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7∘ and 2.9∘ at azimuth and elevation angle estimation, respectively. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈1.3 cm at 96 dpi) in a 640× 480 image.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008, Ping Li 0020
ACM Trans. Sens. Networks1
2022 LSAB: Enhancing Spatio-Temporal Efficiency of AoA Tracking Systems
Qingrui Pan, Zhenlin An, Qiongzheng Lin, Lei Yang 0025
INFOCOM2
2022 Inducing wireless chargers to voice out
abstract
Recent advances have demonstrated that voice assistants or speech recognition systems can be manipulated by malicious and inaudible voice commands. However, the previously proposed attacks require an acoustical generator (e.g., a speaker or a capacitor) to trigger mechanical vibrations at a microphone diaphragm. In this work, we investigate a new type of inaudible command attack using wireless chargers. Specifically, the magnetic interference generated by a wireless charger can induce an inaudible sound at a nearby microphone, without triggering any mechanical vibrations, even if the microphone is equipped with a Faraday cage and an internal electromagnetic interference filter already. By taking advantage of this new insight, we will present a novel inaudible command attack demo that can inject inaudible voice commands into smart devices that are being charged or near to a charger. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and six types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of the proposed attack with commercial charging settings.
Donghui Dai, Zhenlin An, Lei Yang 0025
MobiCom2
2022 Constructing smart buildings with in-concrete backscatter networks
abstract
Given the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule-a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively.
Zhenlin An, Jingyu Tong, Donghui Dai, Lei Yang 0025
MobiCom2
2022 RF-DNA: large-scale physical-layer identifications of RFIDs via dual natural attributes
abstract
Physical-layer identification aims to identify wireless devices during RF communication by exploiting the imperfections of their radio circuitry, i.e., hardware fingerprint. Previous work proposed several hardware fingerprints for RFIDs (e.g., TIE, ABD, PSD, etc). However, these proposed fingerprints suffer from either unscalability or acquisition inefficiency. This work presents RF-DNA, a new hardware fingerprint composed of millions of Dual Natural Attributes (DNA) organized in a helical structure, where a pair of DNA represents a tag's intrinsic response at some frequency. We take advantage of the frequency agnostic phenomenon that a commercial RFID tag can respond within a wider band than the regulated, to acquire 10X more features than previous fingerprints. At the heart of this work are the context-free acquisition approach to extracting DNA from backscatter signals; and the accurate DNA matching algorithm for verifying a tag's identity. A total of 160,000 RF-DNA instances were collected from 16,000 tags using a customized automatic acquisition system. We subsequently carried out large-scale experiments to test the identification accuracy of RF-DNA and previously proposed fingerprints. Our comprehensive evaluation reveals that RF-DNA can achieve a mean accuracy of 95.98%. In contrast, those of previous fingerprints fall to 60% below when in face of thousands of tags.
Qingrui Pan, Zhenlin An, Xueyuan Yang, Lei Yang 0025
MobiCom2
2022 Empowering smart buildings with self-sensing concrete for structural health monitoring
abstract
Given the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. Traditional wireless sensor networks fail to serve in-concrete communication for SHM because of the complexity of battery replacement and the concrete Faraday cage. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule- a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively. Our results demonstrate single link throughputs of up to 13 kbps and power-up ranges of up to 6 m. Finally, we demonstrate a long-term pilot study on the structural health monitoring of a real-life footbridge.
Lubing Han, Zhenlin An, Lei Yang 0025, Siqi Ding
SIGCOMM3
2022 Tagcaster: Activating Wireless Voice of Electronic Toll Collection Systems With Zero Start-Up Cost
abstract
This work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged-fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in the existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented, and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations, and two-thirds of volunteer drivers rate it with a score of 4+ out of 5.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004
IEEE/ACM Trans. Netw.1
2022 LSAB: Enhancing Spatio-temporal Efficiency of AoA Tracking Systems
abstract
Estimating the angle-of-arrival (AoA) of an RF source by using a large-sized antenna array is a classical topic in wireless systems. However, AoA tracking systems are not yet used for Internet of Things (IoT) in the real world due to their unaffordable cost. Many efforts, such as a time-sharing array, emulated array, and sparse array, were recently made to cut the cost. This work introduces a log-spiral antenna belt ( LSAB ), a new novel sparse “planar array” that could estimate the AoA of an IoT device in 3D space by using a few antennas connected to a single timeshare channel. Unlike the conventional arrays, LSAB deploys antennas on a log-spiral-shaped belt in a non-linear manner, following the theory of minimum resolution redundancy newly discovered in this work. One physical 8 × 8 uniform planar array (UPA) and four logical sparse arrays, including LSAB , were prototyped to validate the theory and evaluate the performance of sparse arrays. The extensive benchmark demonstrates that the performance of LSAB was comparable to that of a UPA, with similar degree of resolution; and LSAB could provide over 40% performance improvement than existing sparse arrays. We also prototyped a second LSAB adapted to an RFID system for localizing RFID tags at centimeter-level accuracy.
Qingrui Pan, Zhenlin An, Lei Yang 0025, Qiongzheng Lin
ACM Trans. Sens. Networks2
2021 Turbocharging Deep Backscatter Through Constructive Power Surges with a Single RF Source
abstract
Backscatter networks are becoming a promising solution for embedded sensing. In these networks, backscatter sensors are deeply implanted inside objects or living beings and form a deep backscatter network (DBN). The fundamental challenges in DBNs are the significant attenuation of the wireless signal caused by environmental materials (e.g., water and bodily tissues) and the miniature antennas of the implantable backscatter sensors, which prevent existing backscatter networks from powering sensors beyond superficial depths. This study presents RiCharge, a turbocharging solution that enables powering up and communicating with DBNs through a single augmented RF source, which allows existing backscatter sensors to serve DBNs at zero startup cost. The key contribution of RiCharge is the turbocharging algorithm that utilizes RF surges to induce constructive power surges at deep backscatter sensors in accordance with the FCC regulations, for overcoming the turn-on voltage barrier. RiCharge is implemented in commodity devices, and the evaluation result reveals that RiCharge can use only a single RF source to power up backscatter sensors at 60 m distance in the air (i.e., 10x longer than a commercial off-the-shelf reader) and 50 cm-depth under water (i.e., 2x deeper than the previous record).
Zhenlin An, Qiongzheng Lin, Qingrui Pan, Lei Yang 0025
INFOCOM1
2021 One tag, two codes: identifying optical barcodes with NFC
abstract
Barcodes and NFC have become the de facto standards in the field of automatic identification and data capture. These standards have been widely adopted for many applications, such as mobile payments, advertisements, social sharing, admission control, and so on. Recently, considerable demands require the integration of these two codes (barcode and NFC code) into a single tag for the functional complementation. To achieve the goal of "one tag, two codes" (OTTC), this work proposes CoilCode, which takes advantage of the printed electronics to fuse an NFC coil antenna into a QR code on a single layer. The proposed code could be identified by cameras and NFC readers. With the use of the conductive inks, QR code and NFC code have become an essential part of each other: the modules of the QR code facilitate the NFC chip in harvesting energy from the magnetic field, while the NFC antenna itself represents bits of the QR code. Compared to the prior dual-layer OTTC, CoilCode is more compact, cost-effective, flimsy, flexible, and environment-friendly, and also reduces the fabrication complexity considerably. We prototyped hundreds of CoilCodes and conducted comprehensive evaluations (across 4 models of NFC chips and 8 kinds of NFC readers under 13 different system configurations). CoilCode demonstrates high-quality identification results for QR code and NFC functions on a wide range of inputs and under different distortion effects.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Dongliang Zheng, Guiqing Wu, Shan Chang
MobiCom1
2021 RegNet: a neural network model for predicting regional desirability with VGI data
abstract
Volunteered geographic information can be used to predict regional desirability. A common challenge regarding previous works is that intuitive empirical models, which are inaccurate and bring in perceptual bias, are traditionally used to predict regional desirability. This results from the fact that the hidden interactions between user online check-ins and regional desirability have not been revealed and clearly modelled yet. To solve the problem, a novel neural network model ‘RegNet’ is proposed. The user check-in history is input into a neural network encoder structure firstly for redundancy reduction and feature learning. The encoded representation is then fed into a hidden-layer structure and the regional desirability is predicted. The proposed RegNet is data-driven and can adaptively model the unknown mappings from input to output, without presumed bias and prior knowledge. We conduct experiments with real-world datasets and demonstrate RegNet outperforms state-of-the-art methods in terms of ranking quality and prediction accuracy of rating. Additionally, we also examine how the structure of encoder affects RegNet performance and suggest on choosing proper sizes of encoded representation. This work demonstrates the effectiveness of data-driven methods in modelling the hidden unknown relationships and achieving a better performance over traditional empirical methods.
Wenzhong Shi, Zhewei Liu, Zhenlin An
Int. J. Geogr. Inf. Sci.3
2021 Revitalizing Ultrasonic Positioning Systems for Ultrasound-Incapable Smart Devices
abstract
An ultrasonic positioning system (UPS) has demonstrated its high accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today’s smart devices, which lack ultrasonic sensors and were considered as being “deaf” to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone’s nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are downconverted to a low-frequency by exploiting the nonlinearity effect at the receiver’s microphone. This underlying property functions as an implicit ultrasonic downconverter without inflicting harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008
IEEE Trans. Mob. Comput.1
2021 RFID Harmonic for Vibration Sensing
abstract
Conventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome to deploy. Recently research community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by low reading rate and long wavelength, current RFID based solutions can only sense low-frequency (e.g., below 100 Hz) mechanical vibrations with larger amplitude (e.g., >5 mm). To address the issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensingand a newrecovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows (i) TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100 Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500 Hz. (ii) TagSound can achieve a Hz-level frequency estimation even when the vibration amplitude is only 2 mm.
Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang, Qiongzheng Lin
IEEE Trans. Mob. Comput.2
2021 Identifying UHF RFIDs in Range of Readers With WiFi
abstract
Recent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operate at the spectrum between 840~920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers.
Zhenlin An, Lei Yang 0025, Qiongzheng Lin
IEEE/ACM Trans. Netw.1
2020 Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up Cost
abstract
This work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged- fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ> 2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations and two- thirds volunteer drivers rate it with a score of 4+ out of 5.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004
INFOCOM1
2020 General-purpose deep tracking platform across protocols for the internet of things
abstract
In recent years, considerable effort has been recently exerted to explore the high-precision RF-tracking systems indoors to satisfy various real-world demands. However, such systems are tailored for a particular type of device (e.g., RFID, WSN or Wi-Fi). With the rapid development of the Internet of Things (IoT), various new wireless protocols (e.g., LoRa, Sigfox, and NB-IoT) have been proposed to accommodate different demands. The coexistence of multiple types of IoT devices forces users to deploy multiple tracking systems in a warehouse or a smart home where various IoT devices are running, which causes huge additional costs in installation and maintenance. To address this issue, this work presents iArk, which is a general-purpose tracking platform for all types of IoT devices working at the ultra high frequency band. Our innovation lies in the design of the "K+1"-model hardware, the protocol free middleware, and the multipath resistant learnware. By the virtue of decoupling from wireless protocols, iArk also allows researchers to concentrate on developing a new tracking algorithm without considering the protocol diversity. To date, the platform can support five mainstream types of IoT devices (i.e., NB-IoT, LoRa, RFID, Sigfox and Zigbee) and is scalable to other types with minimal effort.
Zhenlin An, Qiongzheng Lin, Ping Li 0020, Lei Yang 0025
MobiSys1
2020 RFCamera: Identifying RFIDs in Pixel Dimensions
abstract
Radio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things. Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, and vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Many applications would benefit from RFCamera. For instance, the RF-aware image annotation system is able to generate rich annotations for RFID-tagged entities in images at the pixel level for the deep learning; the RF-aware auto-focus allows surveillance camera to exactly focalize the burglar who carries the stolen tagged-property out of a crowd. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image, derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7° and 2.9° at azimuth and elevation angle estimation. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈ 1.3 cm at 96 dpi) in a 640 × 480 image.
Qiongzheng Lin, Lei Yang 0025, Zhenlin An, Yi Guo 0008, Ping Li 0020
SECON3
2020 Acquiring Bloom Filters Across Commercial RFIDs in Physical Layer
abstract
Embedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address the issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags - allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou, Lei Xie 0004
IEEE/ACM Trans. Netw.1
2019 Embracing Tag Collisions: Acquiring Bloom Filters across RFIDs in Physical Layer
abstract
Embedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags -allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou
INFOCOM1
2019 Towards Physical-Layer Vibration Sensing with RFIDs
abstract
Conventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome in deployment. In recent years, the community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by lower reading rate and larger wavelength, current RFID based solutions can only sense low-frequency (e.g. below 100Hz) mechanical vibrations with larger amplitude (e.g. (>) 5mm). To address this issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensing and a new recovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500Hz.
Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang
INFOCOM2
2019 Demo: Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up Cost
abstract
This work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This demo is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g, charged-fees and traffic forecast) to drivers at tollbooths. The prototype of Tagcaster is designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g, Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30m coverage range.
Zhenlin An, Lei Yang 0025, Qiongzheng Lin
MobiCom1
2019 Rebooting Ultrasonic Positioning Systems for Ultrasound-incapable Smart Devices
abstract
An ultrasonic Positioning System (UPS) has outperformed RF-based systems in terms of its accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today's smart devices, which lack ultrasonic sensors and were considered as being "deaf'' to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone's nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are shifted to a low-frequency by virtue of the nonlinearity effect at the receiver's microphone. This underlying property functions as an implicit ultrasonic downconverter without throwing harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms.
Qiongzheng Lin, Zhenlin An, Lei Yang 0025
MobiCom2
2019 Tash: Toward Selective Reading as Hash Primitives for Gen2 RFIDs
abstract
Deployment of billions of commercial off-the-shelf (COTS) radio frequency identification (RFID) tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predictable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a ten-year untouchable mirage. This paper designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function, and tash operator. All of these hash primitives are implemented through the selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication-a feature allowing zero-cost fast deployment on billions of Gen2 tags. We further apply our hash primitives in one typical HEP application (i.e., missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3000 Alien tags, demonstrate that the new design lowers 70% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%.
Qiongzheng Lin, Lei Yang 0025, Chunhui Duan, Zhenlin An
IEEE/ACM Trans. Netw.4
2018 Cross-Frequency Communication: Near-Field Identification of UHF RFIDs with WiFi!
abstract
Recent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4 GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4 GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840 - 920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025
MobiCom1
2018 Demo: Near-Field Identification of UHF RFIDs with WiFi!
abstract
Recent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (eg. 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. In this demo, we present a practical CTC application, called øursystem, allowing a 2.4GHz WiFi receiver (eg. a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840~920MHz. øursystem leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement øursystem with commodity WiFi chipsets. Our comprehensive evaluation shows that øursystem allows WiFi receivers to identify UHF RFID tags within the range of $2$ m and with a median goodput of 95%, which is comparable to today's mobile RFID readers.
Zhenlin An, Qiongzheng Lin, Lei Yang 0025
MobiCom1
2017 Analog On-Tag Hashing: Towards Selective Reading as Hash Primitives in Gen2 RFID Systems
abstract
Deployment of billions of Commercial Off-The-Shelf (COTS) RFID tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predicable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a 10-year untouchable mirage. This work designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function and tash operator. All of these hash primitives are implemented through selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication. We further apply our hash primitives in two typical HEP applications (i.e., cardinality estimation and missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3,000 Alien tags, demonstrate that the new design lowers 60% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%.
Lei Yang 0025, Qiongzheng Lin, Chunhui Duan, Zhenlin An
MobiCom4