VLDB 2026 Research / reviewers in the wild / expert
Zhenlin An
dblp:203/8833
· DBLP profile ↗
57ranked-venue papers
14as first author
45since 2021 · last 2026
0000-0003-4120-773XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 53 · 14 first-author · 41 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MetaRFence: Protecting Human Motion Privacy Against RFID Sensing via MetasurfaceabstractRadio Frequency Identification (RFID) technology has emerged as a pervasive modality for human motion sensing in applications such as smart environments and healthcare monitoring. However, the inherent through-wall sensing capability of RFID technology raises critical privacy concerns regarding the unintended leakage of human motion information, a challenge that has not been adequately addressed. To fill this gap, we present a metasurface-based RFID sensing defence (MetaRFence), the first system designed to protect human motion privacy against adversarial through-wall RFID sensing. To this end, we first devise a programmable metasurface comprising 1-bit phase shifters to systematically obfuscate motion-induced signal patterns. Then, we characterize the metasurface's impact on RFID signals across temporal and spectral domains through comprehensive theoretical modeling and empirical investigations. However, our analysis reveals that it is non-trivial to achieve effective signal obfuscation in both domains, primarily due to a fundamental trade-off between increasing temporal signal variation and masking human motion in its spectrum. To overcome this, we judiciously devise a metasurface controlling strategy that jointly optimizes the signal entropy, variance, and spectrum distribution to reach a balance between temporal and spectral motion obfuscation. Our comprehensive experiments demonstrate thatMetaRFencereduces adversarial through-wall motion detection rates to$\leq$6%, decreases the F1-score of human gesture recognition to$\leq$0.11 on average, and amplifies respiration rate estimation errors by 3×, establishing a robust defense mechanism for RFID-based motion privacy protection. Zheng Shi 0006, Zhikai Ding, Yanni Yang 0003, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | Toward Scalable Reconfigurable Intelligent Surfaces Using Commercial RFIDsabstractReconfigurable Intelligent Surfaces (RISs) have emerged as cost-effective technologies for improving wireless signal transmission. Conventional RIS designs, however, face challenges such as bulkiness, high production costs, limited scalability, and complex installation due to their reliance on wired connections. In this work, we introduce MetaMosaic, a novel RIS platform that repurposes 920 MHz RFID tags into battery-free unit cells, enabling an affordable, scalable, and flexible one-bit phase-modulated RIS. The system is engineered for compatibility with 2.4 GHz Wi-Fi communications while being controlled at 920 MHz. Our design incorporates two central innovations: the transformation of commercial RFID tags into functional unit cells and the development of a tailored neural radiance field to guide efficient reconfiguration. To further enhance global search capability and support multi-hotspot alignment, we extend the system with a genetic algorithm (GA)-based optimization strategy. Compared with the vanilla MetaMosaic, the GA-based MetaMosaic achieves an additional 3.1 dB signal strength improvement and enables simultaneous enhancement for up to five target points. Extensive testing across ten diverse environments demonstrates that MetaMosaic consistently boosts signal strength, with a mean gain of 19 dB over non-RIS setups. This outperforms current leading RIS systems by a 3-fold improvement. Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | GA-Clip: Semantic-Aware Graph Augmentation for Contrastive LearningabstractRecent advancements in Text-Attributed Graphs (TAGs) have attracted significant attention for their wide-ranging applications in domains such as social networks, academics, and e-commerce. The powerful text-processing capabilities of pre-trained language models offer a promising avenue for effectively integrating textual attributes with graph structures. However, existing methods exhibit two key limitations: (1) reliance on rigid graph construction processes that fail to capture a comprehensive view of the text-attributed graph data; (2) insufficient fusion of textual semantics and graph topology, leading to information loss, unstable training, and limited generalization across diverse downstream tasks. In this work, we propose GA-Clip, a novel semantic-aware graph augmentation contrastive learning model. We leverage the pre-trained language model to generate semantic edges that extract the fine-grained topology within the text feature space to augment the graph structure. We then separately employ the graph and text encoders to sufficiently fuse the different modalities through a modified self-supervised contrastive learning approach. This augmentation mitigates the dependency on cumbersome graph construction processes and integrates information from different modalities, which jointly enables scalable graph learning on coarse-grained, large-scale source data. Experimental results demonstrated that our approach achieved a 2-4% improvement over the SOTA methods in accuracy across multiple datasets, validating the effectiveness of the proposed method. Shuaiqi Lu, Yi Guo 0008, Zhenlin An, Ning Huang 0006 |
ICME | 3 |
| 2025 | Commercial RFIDs as Reconfigurable Intelligent Surfaces
Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025 |
INFOCOM | 5 |
| 2025 | RFNOID: Protecting RFID Motion Privacy via Metasurface
Yanni Yang 0003, Zheng Shi 0006, Zhenlin An, Runyu Pan, Yanling Bu, Pengfei Hu 0001, Jiannong Cao 0001 |
INFOCOM | 3 |
| 2025 | Physics-Informed AI for Wireless Communication and SensingabstractDeep learning models encounter fundamental challenges when directly applied to wireless systems, including limited interpretability, low data efficiency, and poor adaptability in dynamic environments. To overcome these challenges, this extended abstract presents my research on embedding electromagnetic physics into AI frameworks to create physics-informed models for wireless communication and sensing. These hybrid models leverage the structure of physical laws alongside data-driven learning, leading to substantial improvements in accuracy, generalization, interpretability, and robustness across complex scenarios. My work demonstrates how this methodology reforms wireless systems across multiple key applications: channel prediction, indoor localization, antenna design, and hardware fingerprinting. Together, these efforts establish a new paradigm for next-generation wireless system design. Zhenlin An |
MobiSys | 1 |
| 2025 | LeakyFeeder: In-Air Gesture Control Through Leaky Acoustic WavesabstractWe present LeakyFeeder, a mobile application that explores the acoustic signals leaked from headphones to reconstruct gesture motions around the ear for fine-grained gesture control. To achieve this goal, LeakyFeeder repurposes the speaker and a single feedforward microphone on active noise cancellation (ANC) headphones as a SONAR system, using inaudible frequency-modulated continuous-wave (FMCW) signals to track gesture reflections for accurate sensing. Since this single-receiver SONAR system is unable to differentiate reflection angles and further disentangle signal reflections from different gesture parts, we draw on principles of multi-modal learning to frame gesture motion reconstruction as a multi-modal translation task and propose a deep learning-based approach to fill the information gap between low-dimensional FMCW ranging readings and high-dimensional 3D hand movements. We implement LeakyFeeder on a pair of Google Pixel Buds and conduct experiments to examine the efficacy and robustness of LeakyFeeder in various conditions. Experiments based on six gesture types inspired by Apple Vision Pro demonstrate that LeakyFeeder achieves a PCK performance of 89% at 3cm across ten users, with an average MPJPE and MPJRPE error of 2.71cm and 1.88cm, respectively. Yongjie Yang 0008, Tao Chen 0033, Zhenlin An, Shirui Cao, Xiaoran Fan, Longfei Shangguan |
SenSys | 3 |
| 2025 | Wireless Eavesdropping on Wired Audio With Radio-Frequency Retroreflector AttackabstractRecent studies have demonstrated the feasibility of eavesdropping on audio via radio frequency signals or videos, which capture physical surface vibrations from surrounding objects. However, these methods are inadequate for intercepting internally transmitted audio through wired media. In this work, we introduce radio-frequency retroreflector attack (RFRA) and bridge this gap by proposing an RFRA-based eavesdropping system,RF-Parrot${}^{\mathbf {2}}$, capable of wirelessly capturing audio signals transmitted through earphone wires. Our system entails embedding a tiny field-effect transistor within the wire to establish a battery-free retroreflector, whose reflective efficiency is correlated with the amplitude of the audio signal. To preserve the details of audio signals, we designed a unique retroreflector using a depletion-mode MOSFET (D-MOSFET). This MOSFET can be triggered by any voltage level present in the audio signals, thus guaranteeing no information loss during activation. However, the D-MOSFET introduces a nonlinear convolution operation on the original audio, resulting in distorted audio eavesdropping. Thus, we devised an engineering solution which utilized a novel convolutional neural network in conjunction with an efficient Parallel WaveGAN vocoder to reconstruct the original audio. Our comprehensive experiments demonstrate a strong similarity between the reconstructed audio and the original, achieving an impressive 95% accuracy in speech command recognition. Genglin Wang, Zheng Shi 0006, Yanni Yang 0003, Zhenlin An, Pengfei Hu 0001, Xiuzhen Cheng, Jiannong Cao 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Romeo: Fault Detection of Rotating Machinery via Fine-Grained mmWave Velocity SignatureabstractReal-time velocity monitoring is pivotal for fault detection of rotating machinery. However, existing methods rely on either troublesome deployments of optical encoders and IMU sensors or various tachometers delivering coarse-grained velocity measurements insufficient for fault detection. To overcome these limitations, we proposeRomeoas the first work to exploit the mmWave radar forrotatingmachinery fault detection by extracting a fine-grained velocity signature. Though mmWave radars should capture instant rotation information with their claimed high sensitivity and sampling rate, direct adoption entails significant efforts for high-precision velocity measurement per radar to handle; particularly, exhausted system calibration and noise interference. To this end, we first develop a phase-velocity model to characterize the relationship between the mmWave signal phase and the fine-grained angular velocity. We then explore the geometric properties of specific positions in the rotation trajectory to precisely calibrate the rotation sensing model, leading to an iterative algorithm for accurate angular velocity measurement. Finally, we propose a simple yet effective fault detection algorithm by extracting a unique velocity signature. Our extensive experiments showRomeoachieves a median error of 0.4$^\circ$/s for fine-grained angular speed measurement, outperforming SOTA solutions with over ×16 angular speed granularity and ×7 measurement precision. Yanni Yang 0003, Pengfei Hu 0001, Jun Luo 0001, Zhenlin An, Jiannong Cao 0001, Dongxiao Yu, Xiuzhen Cheng |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Frequency-Aware Neural Radio-Frequency Radiance FieldsabstractAlthough Maxwell discovered the physical laws of electromagnetic waves about 160 years ago, accurately modeling the propagation of RF signals in large and complex electrical environments remains a persistent challenge. This complexity arises from the interactions between the RF signal and various obstacles, including reflection and diffraction. Inspired by the success of neural networks in mapping the optical field in computer vision, we introduce the neural radio-frequency radiance field, or$\mathbf{NeRF}^{2}$. This represents a continuous volumetric scene function that effectively models RF signal propagation. Remarkably, after only a sparse amount of training with signal measurements,$\mathbf{NeRF}^{2}$can accurately predict the nature and origin of signals received at any location, assuming the transmitter's position is known. Additionally, we propose the frequency-aware$\mathbf{NeRF}^{2}$to enhance channel prediction performance for wideband signals using an RF prism module. Compared to the vanilla$\mathbf{NeRF}^{2}$, the frequency-aware$\mathbf{NeRF}^{2}$achieves a 4 dB improvement in SNR for FDD OFDM channel estimation and is nearly 3.5 × faster. Functioning as a physical-layer neural network,$\mathbf{NeRF}^{2}$also supports application-layer artificial neural networks (ANNs) by generating synthetic training datasets. Our empirical results demonstrate that augmented sensing enhances the accuracy of AoA estimation, achieving an approximate 50% improvement. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | RF-Parrot: Wireless Eavesdropping on Wired AudioabstractRecent works demonstrated that we can eavesdrop on audio by using radio frequency signals or videos to capture the physical surface vibrations of surrounding objects. They fall short when it comes to intercepting internally transmitted audio through wires. In this work, we first address this gap by proposing a new eavesdropping system, RF-Parrot, that can wirelessly capture the audio signal transmitted in earphone wires. Our system involves embedding a tiny field-effect transistor in the wire to create a battery-free retroreflector, with its reflective efficiency tied to the audio signal’s amplitude. To capture full details of the analog audio signals, we engineered a novel retroreflector using a depletion-mode MOSFET, which can be activated by any voltage of the audio signals, ensuring no information loss. We also developed a theoretical model to demystify the nonlinear transmission of the retroreflector, identifying it as a convolution operation on the audio spectrum. Subsequently, we have designed a novel convolutional neural network-based model to accurately reconstruct the original audio. Our extensive experimental results demonstrate that the reconstructed audio bears a strong resemblance to the original audio, achieving an impressive 95% accuracy in speech command recognition. Yanni Yang 0003, Genglin Wang, Zhenlin An, Xiuzhen Cheng, Pengfei Hu 0001 |
INFOCOM | 3 |
| 2024 | Enabling Cross-Medium Wireless Networks with Miniature Mechanical AntennasabstractWithin the burgeoning 6G wireless network landscape, there is an intensified push toward achieving all-encompassing accessibility through integrated solutions spanning a multitude of domains. Notwithstanding recent advancements, the conventional relay-centric communication paradigms grapple with scalability and optimal performance issues. In this paper, we introduce MeAnt ---a versatile IoT platform uniquely architected to foster seamless cross-medium communication by leveraging the compact design of piezoelectric-based mechanical antennas (Piezo-MAs). By capitalizing on the propagation attributes of medium-frequency radios emitted from Piezo-MAs, MeAnt promises communication across diverse environments such as air, water, soil, concrete, and even biological tissue, all while maintaining a compact antenna footprint. Moreover, in light of challenges such as potential interference from AM broadcasts and the intrinsic unidirectional nature of Piezo-MAs, we have developed a finely crafted full-stack communication protocol. Comprehensive tests underscore the system's proficiency, demonstrating a penetration depth of up to 10 m in cross-medium environments and realizing a throughput of 8.7 kbps. Zhenlin An, Donghui Dai, Jingyu Tong, Shuijie Long, Lei Yang 0025 |
MobiCom | 2 |
| 2024 | Binary Optical Machine Learning: Million-Scale Physical Neural Networks with Nano NeuronsabstractDeep learning excels in advanced inference tasks using electronic neural networks (ENN), but faces energy consumption and limited computation speed challenges. To mitigate this, optical neural networks (ONNs) were developed, utilizing light for computations. However, their high manufacturing costs limited accessibility. In this work, we first introduce the binary optical neural network (BONN) - a streamlined ONN variant with binarized weights, which significantly reduces fabrication complexities and costs. Specifically, we address (i) the development of a binarization weight function aligned with backward-error propagation, and (ii) a simulation-based training for extra-large neural networks housing millions of neurons. We prototype six BONNs, each comprising four 0.8 × 0.8mm2 layers with one million 800 nm diameter neurons. Costs are cut to 0.13 USD per layer, marking a substantial decrease of 769× from previous ONNs. Experimental results reveal BONNs consume 2, 405× less power than leading ENNs while maintaining an average recognition accuracy of 74% across six datasets. Xueyuan Yang, Zhenlin An, Qingrui Pan, Lei Yang 0025, Dangyuan Lei, Yulong Fan |
MobiCom | 2 |
| 2024 | In-Sensor Machine Learning: Radio Frequency Neural Networks for Wireless SensingabstractGrowing interest in wireless sensing, a cornerstone of the Artificial Intelligence of Things (AIoT), stems from its ability to gauge target states through nearby wireless signals. However, the escalating count of AIoT nodes escalates redundant data flow and exacerbates energy usage in AI cloud infrastructures. This amplifies the urgency for machine learning techniques that function in proximity to, or directly within, sensors. In light of this, we present the Radio-Frequency Neural Network (RFNN), a novel architecture that uses cost-effective transmissive intelligent surfaces to mimic the functions of a traditional neural network near (or in) sensors, transforming sensory nodes into intelligent terminals primed for machine learning. We first devised a unique training algorithm to mitigate the issues arising from unmodelable error-backward propagation; secondly, we incorporated contrastive learning to address the issue of blind labels stemming from environmental uncertainties. Our RFNN prototype, resonating at a 5 GHz WiFi bandwidth, has been honed across nine varied sensing tasks. The rigorous evaluation shows that it achieves a mean accuracy of 91.5% while consuming only 67.2 μJ of energy. This positions RFNN as a match in inferencing prowess to its electronic neural network counterparts but with significantly diminished energy demands. Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025 |
MobiHoc | 2 |
| 2024 | Understanding Localization by a Tailored GPTabstractConventional deep learning approaches for indoor localization often suffer from their reliance on high-quality training samples and display limited adaptability across varied scenarios. To address these challenges, we repurpose the Transformer model, celebrated for its profound contextual insights, to explore the underlying principles of indoor localization. Our microbenchmark results compellingly demonstrate the superiority of our approach, showing improvements of 30% to 70% across a diverse set of 50 scenarios compared to other state-of-the-art methods. In conclusion, we propose a specialized Generative Pre-training Transformer (GPT) variant, termed LocGPT, configured with 36 million parameters that are tailored to facilitate transfer learning. By fine-tuning this pre-trained model, we achieve near-par accuracy using merely half the conventional dataset, thereby heralding a pioneering stride in transfer learning within the indoor localization domain. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiSys | 3 |
| 2024 | RFID+: Spatially Controllable Identification of UHF RFIDs via Controlled Magnetic Fields
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
NSDI | 2 |
| 2024 | Privacy-preserving human activity sensing: A surveyabstractWith the prevalence of various sensors and smart devices in people’s daily lives, numerous types of information are being sensed. While using such information provides critical and convenient services, we are gradually exposing every piece of our behavior and activities. Researchers are aware of the privacy risks and have been working on preserving privacy while sensing human activities. This survey reviews existing studies on privacy-preserving human activity sensing. We first introduce the sensors and captured private information related to human activities. We then propose a taxonomy to structure the methods for preserving private information from two aspects: individual and collaborative activity sensing. For each of the two aspects, the methods are classified into three levels: signal, algorithm, and system. Finally, we discuss the open challenges and provide future directions. Yanni Yang 0003, Pengfei Hu 0001, Jiaxing Shen, Haiming Cheng, Zhenlin An, Xiulong Liu 0001 |
High Confid. Comput. | 5 |
| 2024 | Pushing the Boundaries of High-Precision AoA Estimation With Enhanced Phase Estimation ProtocolabstractThe emergence of high-precision indoor backscatter tag tracking in GPS-deprived environments has advanced applications from virtual reality to factory automation. Despite this, the high-precision tracking range remains limited to just a few meters, restricting the use of backscatters to the vicinity of checkpoints in warehouses, even though they possess a communication range of 50 m. We have identified that this limited localization range primarily originates from the butterfly effect in localization systems, where a slight phase measurement error gradually escalates into a substantial localization error. This article introduces two innovative phase estimation protocols to address the intrinsic challenges in achieving high-accuracy phase estimation over long-distance communication. The first, consistent phase estimator (CPE), resolves the$\boldsymbol {\pi }$-ambiguity commonly encountered with commercial radio-frequency identification readers. Building on this, CPE+ is designed to cancel flicker noise, neutral white noise, and restore spatial and temporal imbalances. Our experimental results demonstrate that CPE+ extends the range of accurate Angle of Arrival (AoA) estimation and centimeter-level localization from 8 to 15 m in stationary scenarios. It maintains decimeter-level accuracy across the entire 50-m communication range for CPE+ with two or more gateways. In dynamic scenarios, the error of CPE+ increases with tag speed, reaching a median localization error of 11.7 cm at 5 m for tag speeds of 50 cm/s. Zhenlin An, Qingrui Pan, Qiongzheng Lin, Lei Yang 0025 |
IEEE Internet Things J. | 3 |
| 2024 | Harnessing NFC to Generate Standard Optical Barcodes for NFC-Missing SmartphonesabstractMobile payments have grown significantly recently, driven by their contactless feature that minimizes COVID-19 transmission risks. While NFC offers more security and convenience than barcodes and benefits those with amblyopia, many smartphones lack NFC due to module shortages or security decisions. In this work, we present${\sf MagCode}$, an innovative method connecting NFC readers with cameras, allowing users to enjoy NFC payment security using prevalent camera technology. At the heart of${\sf MagCode}$is the harmless magnetic interference on the CMOS image sensor of a smartphone placed nearby the NFC reader, resulting in a group of barcode-like stripes appearing on the captured images. We take advantage of these stripes to encode the data and achieve simplex communication from an NFC reader to an NFC-denied or NFC-disabled smartphone. In particular, we developed a comprehensive suite of protocols spanning from the physical layer to the transport layer, and we rigorously tested our proof-of-concept prototype on 11 different smart devices. Our extensive evaluations showcase a maximum throughput of 2.58 kbps–surpassing magnetometer-based alternatives by a factor of 58–and demonstrate an average data exchange time of 1.3 seconds for mobile payment transactions between an NFC reader and a smartphone. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | The Power of Precision: High-Resolution Backscatter Frequency Drift in RFID IdentificationabstractPhysical-layer identification uses manufacturing variations to create unique identifiers for each device. A decade ago, this concept was applied to RFID tags using backscatter frequency drift (BFD), a specific kind of ‘fingerprint’ determined by the difference between the actual backscatter signal received and the expected backscatter link frequency (BLF). However, BFD has been undervalued due to its low performance in tag identification, achieving less than 30% accuracy. In this study, we reevaluate BFD, focusing on the issue of frequency resolution as the cause of its poor performance. The problem doesn't lie in the BFD's uniqueness, but in the inferior way we measure the frequency of a backscatter signal, which is limited by the current air interface protocol. This situation is akin to trying to identify human fingerprints using low-quality imaging. We propose a practical solution to improve the frequency resolution from kilohertz to sub-hertz, without requiring hardware or protocol changes. Our findings show that this high-resolution BFD approach significantly enhances the distinguishability to 99.4% and the identification accuracy to 94% when tested on a dataset of 7,135 RFID tags across nine models. Qingrui Pan, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Jump Out of Resonance: A Practical NFC Tag Fingerprinting SchemeabstractNFC tag authentication is crucial for preventing tag misuse. Existing NFC fingerprinting methods use physical-layer signals, which incorporate tag hardware imperfections, for authentication purposes. However, these methods suffer from limitations such as low scalability for a large number of tags or incompatibility with various NFC protocols, hindering practical application. To address these issues, we propose a new NFC fingerprinting scheme called NFChain$^+$. Instead of sticking to the NFC resonant frequency, NFChain$^+$excavates the tag hardware uniqueness from the protocol-agnostic tag response signal using an agile and compatible frequency band of NFC to extract the tag fingerprint from a chain of tag responses over multiple frequencies. This significantly improves fingerprint scalability. However, extracting the desired fingerprint presents two challenges: fingerprint inconsistency under different configurations, and fingerprint variations due to the signal noise in generic readers. To overcome these challenges, we design an effective signal elimination method to remove the effect of device configurations and employ contrastive learning to reduce fingerprint variations for accurate tag authentication. We further cultivate a data augmentation strategy to save the cost of manually collecting fingerprint measurements for training the authentication model. Extensive experiments show that we can achieve as low as 3.4% FRR and 4.1% FAR for over 600 NFC tags. Yanni Yang 0003, Zhenlin An, Jiannong Cao 0001, Yanwen Wang 0001, Pengfei Hu 0001, Xiuzhen Cheng |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Transfer Beamforming via Beamforming for TransferabstractAlthough billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in the two major performance limitations (i.e., short reading range and high miss reading rate) resulting from the current harvesting inefficiency. The classic beamforming technique is regarded as the most promising solution to address the issue. However, applying it to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new paradigm calledtransfer beamforming(${\sf TBF}$), namely, the beamforming strategies can be transferred from reference tags with known positions to power up other unknown neighbor tags of interest. In short, transfer beamforming (is accomplished) via (launching) beamforming (to reference tags first) for (the purpose of) transfer. To do so, we adopt the semi-active tags as the reference tags, which can be powered up with a normal reader in a wide range. Then the beamforming is initiated and transferred to power up the low-sensitive but cost-effective passive tags surrounded by reference tags. A prototype evaluation of${\sf TBF}$with 8 transmitting antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our comprehensive evaluation reveals that${\sf TBF}$can improve the power transmission by 6.9 dB and boost the inventory speed by 2× compared with state-of-art methods. Xueyuan Yang, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Transfer Beamforming via Beamforming for TransferabstractAlthough billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in performance limitations (i.e., short reading range and high miss-reading rate) resulting from power harvesting inefficiency. However, applying classic beamforming technique to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new beamforming paradigm called transfer beamforming (TBF), namely, beamforming strategies can be transferred from reference tags with known positions to power up unknown neighbor tags of interest. Transfer beamforming (is accomplished) via (launching) beamforming (to reference tags firstly) for (the purpose of) transfer. To do so, we adopt semi-active tags as reference tags, which can be easily powered up with a normal reader. Then beamforming is initiated and transferred to power up passive tags surrounded by reference tags. A prototype evaluation of TBF with 8 antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our evaluation reveals that TBF improves the power transmission by 6.9 dB and boosts the inventory speed by 2 × compared with state-of-art methods. Xueyuan Yang, Zhenlin An, Lei Yang 0025 |
INFOCOM | 2 |
| 2023 | NFChain: A Practical Fingerprinting Scheme for NFC Tag AuthenticationabstractIEEE INFOCOM 2023 - IEEE Conference on Computer Communications, New York City, NY, USA, 17-20 May 2023 Yanni Yang 0003, Jiannong Cao 0001, Zhenlin An, Yanwen Wang 0001, Pengfei Hu 0001 |
INFOCOM | 3 |
| 2023 | MagCode: NFC-Enabled Barcodes for NFC-Disabled SmartphonesabstractMobile payment has achieved explosive growth in recent years due to its contactless feature, which lowers the infection risk of COVID-19. In the market, near-field communication (NFC) and barcodes have become the de facto standard technologies for mobile payment. The NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopia group. Unfortunately, NFC functionality is unavailable in nearly half of smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 2 |
| 2023 | MagCode: Bringing NFC Feature to All SmartphonesabstractMobile payments have experienced a significant surge in recent years, primarily due to their contactless feature that mitigates the risk of COVID-19 transmission. In this landscape, NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopic community. Unfortunately, NFC functionality is unavailable in nearly half of the smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 2 |
| 2023 | Radio Frequency Neural Networks for Wireless SensingabstractWireless sensing has attracted considerable attention because it can sense the state of the targets by analyzing the surrounding wireless signals, which has become the key role of the artificial intelligence of things (AIoT). As the number of sensory nodes increases, large amounts of redundant data are exchanged between sensory terminals and the AI cloud. To process such large amounts of data efficiently and decrease power consumption, a machine-learning approach that operates close to or inside sensors must be developed. To this end, we present the radio-frequency neural network (RFNN), a physical neural network taking advantage of a group of transmissive intelligent surfaces (i.e., metasurfaces) to mimic the computations of a fully-connected neural network. The design is spurred by the capability of RFNNs to perform expensive multiplication and additions at the speed of light, with ultra-low power consumption. We prototype RFNN at 5 GHz for WiFi sensing regarding nine wireless sensing tasks. Extensive evaluations demonstrate the comparably equivalent inference ability as the conventional electronic neural networks while consuming less energy. Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025 |
MobiCom | 2 |
| 2023 | NeRF2: Neural Radio-Frequency Radiance FieldsabstractAlthough Maxwell discovered the physical laws of electromagnetic waves 160 years ago, how to precisely model the propagation of an RF signal in an electrically large and complex environment remains a long-standing problem. The difficulty is in the complex interactions between the RF signal and the obstacles (e.g., reflection, diffraction, etc.). Inspired by the great success of using a neural network to describe the optical field in computer vision, we propose a neural radio-frequency radiance field, NeRF2, which represents a continuous volumetric scene function that makes sense of an RF signal's propagation. Particularly, after training with a few signal measurements, NeRF2 can tell how/what signal is received at any position when it knows the position of a transmitter. As a physical-layer neural network, NeRF2 can take advantage of the learned statistic model plus the physical model of ray tracing to generate a synthetic dataset that meets the training demands of application-layer artificial neural networks (ANNs). Thus, we can boost the performance of ANNs by the proposed turbo-learning, which mixes the true and synthetic datasets to intensify the training. Our experiment results show that turbo-learning can enhance performance with an approximate 50% increase. We also demonstrate the power of NeRF2 in the field of indoor localization and 5G MIMO. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 2 |
| 2023 | Revisiting Backscatter Frequency Drifts for Fingerprinting RFIDs: A Perspective of Frequency ResolutionabstractPhysical-layer identification is to exploit inherent randomness introduced during manufacturing to endow a unique fingerprint to a physical entity. A classic fingerprint, called backscatter frequency drift (BFD), was explored a decade ago for the physical-layer identification of RFID tags. The BFD is defined as the offset between the frequency of the backscatter signal actually received from a tag and the requested backscatter link frequency (BLF). As a context-free fingerprint, the BFD is being seriously underestimated due to its terrible performance in tag classification or identification (e.g., accuracy < 30%). In this work, we revisit BFD from the perspective of frequency resolution to pinpoint the reason behind its underperformance. Namely, the low accuracy is not because BFD is insufficiently unique in nature but rather due to the low-resolution measurement of the frequency of a backscatter signal, which is mainly constrained by the current air interface protocol. This challenge is analogous to the recognition of human fingerprints via low-resolution and blurry imaging devices. To address this issue, we propose a practical solution to improve the frequency resolution from kHz to sub-Hz, without any modification of hardware or protocols. The results demonstrate the distinguishability of high-resolution BFD is significantly increased to 99.4% and the identification accuracy is raised to 94% when in the face of 7,135 RFID tags of nine models. Qingrui Pan, Zhenlin An, Lei Yang 0025 |
SECON | 2 |
| 2023 | XiTuXi: Sealing the Gaps in Cross-Technology Communication by Neural Machine TranslationabstractCross-Technology Communication (CTC) is an emerging technology that enables physical-layer direct communication from a WiFi sender to other Internet of Things (IoT) receivers via waveform emulation. The previous works use the reverse engineering to find the appropriate WiFi payload that can emulate the waveform similar to the desired IoT packet in the format of the IoT protocol (e.g., ZigBee). Unfortunately, the reverse engineering approach suffers from many limitations, such as being non-reversible and unscalable, misaligning symbols, and over-relying on empiricism. In this work, we present XiTuXi, a one-size-fits-all solution to automatically achieve the CTC by taking advantage of the neural machine translation (NMT), inspired by the task comparability between CTC and homophony-based cross-linguistic communication. We employ a well-known NMT model called Transformer to learn the bit-sequence to bit-sequence translation rationale behind the CTC without human intervention. Particularly, we introduce the forward engineering to address the dilemma of acquiring training datasets. By using XiTuXi, we achieved the CTC with 30 protocol combinations (ie., 802.11b, g, n, ax, ah Å ZigBee, Bluetooth, LoRa, and Sigfox) effortlessly, which ultimately liberates the experts from previous tedious tasks. Sicong Liao, Zhenlin An, Qingrui Pan, Jingyu Tong, Lei Yang 0025 |
SenSys | 2 |
| 2023 | Inducing Wireless Chargers to Voice Out for Inaudible Command AttacksabstractRecent works demonstrated that speech recognition systems or voice assistants can be manipulated by malicious voice commands, which are injected through various inaudible media, such as ultrasound, laser, and electromagnetic interference (EMI). In this work, we explore a new kind of inaudible voice attack through the magnetic interference induced by a wireless charger. Essentially, we show that the microphone components of smart devices suffer from severe magnetic interference when they are enjoying wireless charging, due to the absence of effective protection against the EMI at low frequencies (100 kHz or below). By taking advantage of this vulnerability, we design two inaudible voice attacks, HeartwormAttack and ParasiteAttack, both of which aim to inject malicious voice commands into smart devices being wirelessly charged. They make use of a compromised wireless charger or accessory equipment (called parasite) to inject the voice, respectively. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and 6 types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of two proposed attacks with commercial charging settings. Donghui Dai, Zhenlin An, Lei Yang 0025 |
SP | 2 |
| 2023 | Localizing RFIDs in Pixel DimensionsabstractRadio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things (IoT). Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7∘ and 2.9∘ at azimuth and elevation angle estimation, respectively. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈1.3 cm at 96 dpi) in a 640× 480 image. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008, Ping Li 0020 |
ACM Trans. Sens. Networks | 1 |
| 2022 | LSAB: Enhancing Spatio-Temporal Efficiency of AoA Tracking Systems
Qingrui Pan, Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
INFOCOM | 2 |
| 2022 | Inducing wireless chargers to voice outabstractRecent advances have demonstrated that voice assistants or speech recognition systems can be manipulated by malicious and inaudible voice commands. However, the previously proposed attacks require an acoustical generator (e.g., a speaker or a capacitor) to trigger mechanical vibrations at a microphone diaphragm. In this work, we investigate a new type of inaudible command attack using wireless chargers. Specifically, the magnetic interference generated by a wireless charger can induce an inaudible sound at a nearby microphone, without triggering any mechanical vibrations, even if the microphone is equipped with a Faraday cage and an internal electromagnetic interference filter already. By taking advantage of this new insight, we will present a novel inaudible command attack demo that can inject inaudible voice commands into smart devices that are being charged or near to a charger. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and six types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of the proposed attack with commercial charging settings. Donghui Dai, Zhenlin An, Lei Yang 0025 |
MobiCom | 2 |
| 2022 | Constructing smart buildings with in-concrete backscatter networksabstractGiven the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule-a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively. Zhenlin An, Jingyu Tong, Donghui Dai, Lei Yang 0025 |
MobiCom | 2 |
| 2022 | RF-DNA: large-scale physical-layer identifications of RFIDs via dual natural attributesabstractPhysical-layer identification aims to identify wireless devices during RF communication by exploiting the imperfections of their radio circuitry, i.e., hardware fingerprint. Previous work proposed several hardware fingerprints for RFIDs (e.g., TIE, ABD, PSD, etc). However, these proposed fingerprints suffer from either unscalability or acquisition inefficiency. This work presents RF-DNA, a new hardware fingerprint composed of millions of Dual Natural Attributes (DNA) organized in a helical structure, where a pair of DNA represents a tag's intrinsic response at some frequency. We take advantage of the frequency agnostic phenomenon that a commercial RFID tag can respond within a wider band than the regulated, to acquire 10X more features than previous fingerprints. At the heart of this work are the context-free acquisition approach to extracting DNA from backscatter signals; and the accurate DNA matching algorithm for verifying a tag's identity. A total of 160,000 RF-DNA instances were collected from 16,000 tags using a customized automatic acquisition system. We subsequently carried out large-scale experiments to test the identification accuracy of RF-DNA and previously proposed fingerprints. Our comprehensive evaluation reveals that RF-DNA can achieve a mean accuracy of 95.98%. In contrast, those of previous fingerprints fall to 60% below when in face of thousands of tags. Qingrui Pan, Zhenlin An, Xueyuan Yang, Lei Yang 0025 |
MobiCom | 2 |
| 2022 | Empowering smart buildings with self-sensing concrete for structural health monitoringabstractGiven the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. Traditional wireless sensor networks fail to serve in-concrete communication for SHM because of the complexity of battery replacement and the concrete Faraday cage. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule- a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively. Our results demonstrate single link throughputs of up to 13 kbps and power-up ranges of up to 6 m. Finally, we demonstrate a long-term pilot study on the structural health monitoring of a real-life footbridge. Lubing Han, Zhenlin An, Lei Yang 0025, Siqi Ding |
SIGCOMM | 3 |
| 2022 | Tagcaster: Activating Wireless Voice of Electronic Toll Collection Systems With Zero Start-Up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged-fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in the existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented, and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations, and two-thirds of volunteer drivers rate it with a score of 4+ out of 5. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004 |
IEEE/ACM Trans. Netw. | 1 |
| 2022 | LSAB: Enhancing Spatio-temporal Efficiency of AoA Tracking SystemsabstractEstimating the angle-of-arrival (AoA) of an RF source by using a large-sized antenna array is a classical topic in wireless systems. However, AoA tracking systems are not yet used for Internet of Things (IoT) in the real world due to their unaffordable cost. Many efforts, such as a time-sharing array, emulated array, and sparse array, were recently made to cut the cost. This work introduces a log-spiral antenna belt ( LSAB ), a new novel sparse “planar array” that could estimate the AoA of an IoT device in 3D space by using a few antennas connected to a single timeshare channel. Unlike the conventional arrays, LSAB deploys antennas on a log-spiral-shaped belt in a non-linear manner, following the theory of minimum resolution redundancy newly discovered in this work. One physical 8 × 8 uniform planar array (UPA) and four logical sparse arrays, including LSAB , were prototyped to validate the theory and evaluate the performance of sparse arrays. The extensive benchmark demonstrates that the performance of LSAB was comparable to that of a UPA, with similar degree of resolution; and LSAB could provide over 40% performance improvement than existing sparse arrays. We also prototyped a second LSAB adapted to an RFID system for localizing RFID tags at centimeter-level accuracy. Qingrui Pan, Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
ACM Trans. Sens. Networks | 2 |
| 2021 | Turbocharging Deep Backscatter Through Constructive Power Surges with a Single RF SourceabstractBackscatter networks are becoming a promising solution for embedded sensing. In these networks, backscatter sensors are deeply implanted inside objects or living beings and form a deep backscatter network (DBN). The fundamental challenges in DBNs are the significant attenuation of the wireless signal caused by environmental materials (e.g., water and bodily tissues) and the miniature antennas of the implantable backscatter sensors, which prevent existing backscatter networks from powering sensors beyond superficial depths. This study presents RiCharge, a turbocharging solution that enables powering up and communicating with DBNs through a single augmented RF source, which allows existing backscatter sensors to serve DBNs at zero startup cost. The key contribution of RiCharge is the turbocharging algorithm that utilizes RF surges to induce constructive power surges at deep backscatter sensors in accordance with the FCC regulations, for overcoming the turn-on voltage barrier. RiCharge is implemented in commodity devices, and the evaluation result reveals that RiCharge can use only a single RF source to power up backscatter sensors at 60 m distance in the air (i.e., 10x longer than a commercial off-the-shelf reader) and 50 cm-depth under water (i.e., 2x deeper than the previous record). Zhenlin An, Qiongzheng Lin, Qingrui Pan, Lei Yang 0025 |
INFOCOM | 1 |
| 2021 | One tag, two codes: identifying optical barcodes with NFCabstractBarcodes and NFC have become the de facto standards in the field of automatic identification and data capture. These standards have been widely adopted for many applications, such as mobile payments, advertisements, social sharing, admission control, and so on. Recently, considerable demands require the integration of these two codes (barcode and NFC code) into a single tag for the functional complementation. To achieve the goal of "one tag, two codes" (OTTC), this work proposes CoilCode, which takes advantage of the printed electronics to fuse an NFC coil antenna into a QR code on a single layer. The proposed code could be identified by cameras and NFC readers. With the use of the conductive inks, QR code and NFC code have become an essential part of each other: the modules of the QR code facilitate the NFC chip in harvesting energy from the magnetic field, while the NFC antenna itself represents bits of the QR code. Compared to the prior dual-layer OTTC, CoilCode is more compact, cost-effective, flimsy, flexible, and environment-friendly, and also reduces the fabrication complexity considerably. We prototyped hundreds of CoilCodes and conducted comprehensive evaluations (across 4 models of NFC chips and 8 kinds of NFC readers under 13 different system configurations). CoilCode demonstrates high-quality identification results for QR code and NFC functions on a wide range of inputs and under different distortion effects. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Dongliang Zheng, Guiqing Wu, Shan Chang |
MobiCom | 1 |
| 2021 | RegNet: a neural network model for predicting regional desirability with VGI dataabstractVolunteered geographic information can be used to predict regional desirability. A common challenge regarding previous works is that intuitive empirical models, which are inaccurate and bring in perceptual bias, are traditionally used to predict regional desirability. This results from the fact that the hidden interactions between user online check-ins and regional desirability have not been revealed and clearly modelled yet. To solve the problem, a novel neural network model ‘RegNet’ is proposed. The user check-in history is input into a neural network encoder structure firstly for redundancy reduction and feature learning. The encoded representation is then fed into a hidden-layer structure and the regional desirability is predicted. The proposed RegNet is data-driven and can adaptively model the unknown mappings from input to output, without presumed bias and prior knowledge. We conduct experiments with real-world datasets and demonstrate RegNet outperforms state-of-the-art methods in terms of ranking quality and prediction accuracy of rating. Additionally, we also examine how the structure of encoder affects RegNet performance and suggest on choosing proper sizes of encoded representation. This work demonstrates the effectiveness of data-driven methods in modelling the hidden unknown relationships and achieving a better performance over traditional empirical methods. Wenzhong Shi, Zhewei Liu, Zhenlin An |
Int. J. Geogr. Inf. Sci. | 3 |
| 2021 | Revitalizing Ultrasonic Positioning Systems for Ultrasound-Incapable Smart DevicesabstractAn ultrasonic positioning system (UPS) has demonstrated its high accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today’s smart devices, which lack ultrasonic sensors and were considered as being “deaf” to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone’s nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are downconverted to a low-frequency by exploiting the nonlinearity effect at the receiver’s microphone. This underlying property functions as an implicit ultrasonic downconverter without inflicting harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | RFID Harmonic for Vibration SensingabstractConventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome to deploy. Recently research community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by low reading rate and long wavelength, current RFID based solutions can only sense low-frequency (e.g., below 100 Hz) mechanical vibrations with larger amplitude (e.g., >5 mm). To address the issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensingand a newrecovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows (i) TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100 Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500 Hz. (ii) TagSound can achieve a Hz-level frequency estimation even when the vibration amplitude is only 2 mm. Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang, Qiongzheng Lin |
IEEE Trans. Mob. Comput. | 2 |
| 2021 | Identifying UHF RFIDs in Range of Readers With WiFiabstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operate at the spectrum between 840~920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged- fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ> 2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations and two- thirds volunteer drivers rate it with a score of 4+ out of 5. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004 |
INFOCOM | 1 |
| 2020 | General-purpose deep tracking platform across protocols for the internet of thingsabstractIn recent years, considerable effort has been recently exerted to explore the high-precision RF-tracking systems indoors to satisfy various real-world demands. However, such systems are tailored for a particular type of device (e.g., RFID, WSN or Wi-Fi). With the rapid development of the Internet of Things (IoT), various new wireless protocols (e.g., LoRa, Sigfox, and NB-IoT) have been proposed to accommodate different demands. The coexistence of multiple types of IoT devices forces users to deploy multiple tracking systems in a warehouse or a smart home where various IoT devices are running, which causes huge additional costs in installation and maintenance. To address this issue, this work presents iArk, which is a general-purpose tracking platform for all types of IoT devices working at the ultra high frequency band. Our innovation lies in the design of the "K+1"-model hardware, the protocol free middleware, and the multipath resistant learnware. By the virtue of decoupling from wireless protocols, iArk also allows researchers to concentrate on developing a new tracking algorithm without considering the protocol diversity. To date, the platform can support five mainstream types of IoT devices (i.e., NB-IoT, LoRa, RFID, Sigfox and Zigbee) and is scalable to other types with minimal effort. Zhenlin An, Qiongzheng Lin, Ping Li 0020, Lei Yang 0025 |
MobiSys | 1 |
| 2020 | RFCamera: Identifying RFIDs in Pixel DimensionsabstractRadio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things. Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, and vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Many applications would benefit from RFCamera. For instance, the RF-aware image annotation system is able to generate rich annotations for RFID-tagged entities in images at the pixel level for the deep learning; the RF-aware auto-focus allows surveillance camera to exactly focalize the burglar who carries the stolen tagged-property out of a crowd. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image, derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7° and 2.9° at azimuth and elevation angle estimation. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈ 1.3 cm at 96 dpi) in a 640 × 480 image. Qiongzheng Lin, Lei Yang 0025, Zhenlin An, Yi Guo 0008, Ping Li 0020 |
SECON | 3 |
| 2020 | Acquiring Bloom Filters Across Commercial RFIDs in Physical LayerabstractEmbedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address the issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags - allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou, Lei Xie 0004 |
IEEE/ACM Trans. Netw. | 1 |
| 2019 | Embracing Tag Collisions: Acquiring Bloom Filters across RFIDs in Physical LayerabstractEmbedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags -allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou |
INFOCOM | 1 |
| 2019 | Towards Physical-Layer Vibration Sensing with RFIDsabstractConventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome in deployment. In recent years, the community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by lower reading rate and larger wavelength, current RFID based solutions can only sense low-frequency (e.g. below 100Hz) mechanical vibrations with larger amplitude (e.g. (>) 5mm). To address this issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensing and a new recovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500Hz. Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang |
INFOCOM | 2 |
| 2019 | Demo: Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This demo is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g, charged-fees and traffic forecast) to drivers at tollbooths. The prototype of Tagcaster is designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g, Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30m coverage range. Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
MobiCom | 1 |
| 2019 | Rebooting Ultrasonic Positioning Systems for Ultrasound-incapable Smart DevicesabstractAn ultrasonic Positioning System (UPS) has outperformed RF-based systems in terms of its accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today's smart devices, which lack ultrasonic sensors and were considered as being "deaf'' to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone's nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are shifted to a low-frequency by virtue of the nonlinearity effect at the receiver's microphone. This underlying property functions as an implicit ultrasonic downconverter without throwing harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms. Qiongzheng Lin, Zhenlin An, Lei Yang 0025 |
MobiCom | 2 |
| 2019 | Tash: Toward Selective Reading as Hash Primitives for Gen2 RFIDsabstractDeployment of billions of commercial off-the-shelf (COTS) radio frequency identification (RFID) tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predictable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a ten-year untouchable mirage. This paper designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function, and tash operator. All of these hash primitives are implemented through the selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication-a feature allowing zero-cost fast deployment on billions of Gen2 tags. We further apply our hash primitives in one typical HEP application (i.e., missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3000 Alien tags, demonstrate that the new design lowers 70% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%. Qiongzheng Lin, Lei Yang 0025, Chunhui Duan, Zhenlin An |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | Cross-Frequency Communication: Near-Field Identification of UHF RFIDs with WiFi!abstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4 GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4 GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840 - 920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
MobiCom | 1 |
| 2018 | Demo: Near-Field Identification of UHF RFIDs with WiFi!abstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (eg. 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. In this demo, we present a practical CTC application, called øursystem, allowing a 2.4GHz WiFi receiver (eg. a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840~920MHz. øursystem leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement øursystem with commodity WiFi chipsets. Our comprehensive evaluation shows that øursystem allows WiFi receivers to identify UHF RFID tags within the range of $2$ m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
MobiCom | 1 |
| 2017 | Analog On-Tag Hashing: Towards Selective Reading as Hash Primitives in Gen2 RFID SystemsabstractDeployment of billions of Commercial Off-The-Shelf (COTS) RFID tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predicable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a 10-year untouchable mirage. This work designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function and tash operator. All of these hash primitives are implemented through selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication. We further apply our hash primitives in two typical HEP applications (i.e., cardinality estimation and missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3,000 Alien tags, demonstrate that the new design lowers 60% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%. Lei Yang 0025, Qiongzheng Lin, Chunhui Duan, Zhenlin An |
MobiCom | 4 |