Weiye Xu 0001

dblp:219/2395-1 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-2892-7903ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 3 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Anti-Spoofing and Mask-Supported Face Authentication Using mmWave Without On-Site Registration
abstract
Face authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and susceptible to masks and vulnerable to spoofing attacks. This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans faces by moving a commodity mmWave radar along a specific trajectory. The signals bounced off the face carry facial biometric and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well when users wear masks. To en- hance security, we develop a liveness detection method and an amplitude modulation-based method to defend against spoofing attacks and replay attacks. We enhance the basic version of mmFace [1] by improving its performance under mask occlusion and replay attack resilience. Besides, we explore a distance-resistant structure feature to suppress the impact of unstable face- to-device distance. To avoid on-site registration, we propose a novel virtual registration approach based on the cross-modal transformation from photos to mmWave. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments demonstrate mmFace's accuracy in FA and effectiveness in attack detection.
Wenfan Song, Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Xinhuai Wang, Jinsong Han
IEEE Trans. Dependable Secur. Comput.2
2025 DiskSpy: Exploring a Long-Range Covert-Channel Attack via mmWave Sensing of μm-level HDD Vibrations
Weiye Xu 0001, Danli Wen, Jianwei Liu 0008, Zixin Lin, Yuanqing Zheng, Jinsong Han
USENIX Security Symposium1
2024 Manipulating Semantic Communication by Adding Adversarial Perturbations to Wireless Channel
abstract
To break through the transmission rate bottleneck of traditional communication, semantic communication is proposed to support emerging applications with extremely low latency requirements such as remote surgery and autonomous vehicle. Unlike the transmission of verbose symbols in traditional communication, mainstream semantic communications use deep learning technology to extract compact semantic information from data and convey it. However, the application of deep neural networks also poses security concerns, i.e., vulnerabilities to adversarial attacks. In this paper, we perform the first study on the security of semantic communication against both whitebox and black-box attacks by compromising the wireless channel between the transmitter and receiver. To launch practical and effective attacks, a systematic and universal attack framework is designed to craft content-agnostic, undetectable, robust whitebox perturbation signals as well as highly-transferable blackbox ones. Extensive experiments on two open-source datasets demonstrate that our attack framework can achieve over 87%, 99%, and 89% success rates in untargeted white-box, targeted white-box, and untargeted black-box attacks. This means that the proposed attack methods could severely threaten the quality of service of current semantic communications. We also propose two mitigation methods to resist such attacks.
Jianwei Liu 0008, Yinghui He, Weiye Xu 0001, Jinsong Han
IWQoS3
2024 Anti-Spoofing Facial Authentication Based on COTS RFID
abstract
Current facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, but they are still vulnerable to feature manipulation, e.g., 3D-printed human faces. In this article, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. Unlike images, RF signals are not perceptible to human eyes, so RFace protects user's privacy. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between facial features and RF signals. To enhance the security of RFace, we specify the tag reading order for each authentication to defend against the signal replay attack. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7$\%$and an EER of 4.4$\%$. More importantly, no replay attack or spoofing attack succeeds in deceiving RFace in the experiments.
Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.1
2023 Mobile Communication Among COTS IoT Devices via a Resonant Gyroscope With Ultrasound
abstract
Incompatible protocols and electromagnetic interference obstruct the realization of an everything-connected Internet of Things (IoT) communication network. Our system, Deaf-Aid, utilizes a stealthy speaker-to-gyroscope channel to build robust communication. Compared with existing solutions adopting physical covert channels, Deaf-Aid is free from the limitations of manual receiver distinction, additional hardware, conditional placement, or physical contact. It exploits ultrasounds to force gyroscopes embedded in receivers to resonate, so as to convey information. We investigate the relationship among axes in a gyroscope to deal with frequency offset and support multi-channel communication. Meanwhile, receivers are identified automatically via device fingerprints consisting of diversity of gyroscopes’ resonant frequency ranges. Furthermore, we enable Deaf-Aid the capability of mobile communication, which is an essential demand for IoT devices. We address the challenge of recovering accurate signals from motion interference. Extensive evaluations, including that on the commercial off-the-shelf devices, demonstrate that Deaf-Aid yields 47 bps with BER below 1%. To our best knowledge, Deaf-Aid is the first work to enable stealthy mobile IoT communication based on inertial sensors.
Feng Lin 0004, Ming Gao 0023, Lingfeng Zhang 0004, Weiye Xu 0001, Jinsong Han, Wenyao Xu, Kui Ren 0001
IEEE/ACM Trans. Netw.5
2022 Mask does not matter: anti-spoofing face authentication using mmWave without on-site registration
abstract
Face authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and hence susceptible to face occlusion (e.g., facial masks) and vulnerable to spoofing attacks (e.g., 3D-printed masks). This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans the human face by moving a commodity off-the-shelf (COTS) mmWave radar along a specific trajectory. The mmWave signals bounced off the human face carry the facial biometric features and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well even if users wear masks. We explore a distance-resistant facial structure feature to suppress the impact of unstable face-to-device distance. To avoid inconvenient on-site registration, we also propose a novel virtual registration approach based on the core idea of cross-modal transformation from photos to mmWave signals. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments show that mmFace can realize accurate FA as well as reliable liveness detection.
Weiye Xu 0001, Wenfan Song, Jianwei Liu 0008, Yuanqing Zheng, Jinsong Han, Xinhuai Wang, Kui Ren 0001
MobiCom1
2021 RFace: Anti-Spoofing Facial Authentication Using COTS RFID
abstract
Current facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, which are still easy to deceive with the feature manipulation, e.g., 3D-printed human faces. In this paper, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. RFace only requires users to pose their faces in front of a tag array for a few seconds, without leaking their visual facial information. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between the facial features and RF signals. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7% and an EER of 4.4%. More importantly, no spoofing attack succeeds in deceiving RFace in the experiments.
Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Jinsong Han, Fu Xiao 0001, Kui Ren 0001
INFOCOM1
2020 Deaf-aid: mobile IoT communication exploiting stealthy speaker-to-gyroscope channel
abstract
Internet of Things (IoT) devices are hindered from communicating with their neighbors by incompatible protocols or electromagnetic interference. Existing solutions adopting physical covert channels have limitations in receiver distinction, additional hardware, conditional placement, or physical contact. Our system, Deaf-Aid, utilizes the stealthy speaker-to-gyroscope channel to build robust protocol-independent communication with automatic receiver identification. Deaf-Aid exploits ultrasonic signals at a frequency corresponding to the target receiver, forcing the gyroscope inside to resonate, so as to convey information. We probe the relationship among axes in a gyroscope to surmount frequency offset ingeniously and support multi-channel communication. Meanwhile, Deaf-Aid identifies the receivers automatically via device fingerprints constituted by the diversity of resonant frequency ranges. Furthermore, we entitle Deaf-Aid the capability of mobile communication which is an essential demand for IoT devices. We address the challenge of accurate signals recovery from motion interference. Extensive evaluations demonstrate that Deaf-Aid yields 47bps with BER lower than 1% under motion interference. To our best knowledge, Deaf-Aid is the first work to enable stealthy mobile IoT communication on the basis of inertial motion sensors.
Ming Gao 0023, Feng Lin 0004, Weiye Xu 0001, Muertikepu Nuermaimaiti, Jinsong Han, Wenyao Xu, Kui Ren 0001
MobiCom3