Yinxin Wan

dblp:224/0803 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0003-1535-5253ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 5 first-author · 9 since 2021
YearPublicationVenuePosition
2026 Characterizing Security and Privacy Risks in Smart Home IoT Device Access Sharing
abstract
Smart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats.
Yinxin Wan, Tran Ngoc Bao Huynh, Jun Dai 0001, Xiaoyan Sun 0003, Kuai Xu, Guoliang Xue
SenSys1
2025 Optimizing IoT Cross-rule Vulnerability Detection through Reinforcement Learning-Based Fuzzing
abstract
Internet of Things (IoT) devices have become increasingly ubiquitous and essential to daily life. These devices are usually controlled based on trigger-action rules, meaning that the devices will take actions according to the rules when trigger conditions are satisfied. As more devices are deployed in smart home systems, the risk of undesirable interactions and cross-rule vulnerabilities increases. In this paper, we propose a reinforcement learning-based fuzzing approach that can automate the modification of environmental variables to generate test cases and increase the likelihood of discovering cross-rule conflicts in smart home systems. Our approach optimizes conflict detection and discovers hidden conditions that lead to vulnerabilities. The preliminary results show that our model can successfully recognize different types of rule conflict.
Tran Ngoc Bao Huynh, Yinxin Wan, Jun Dai 0001, Xiaoyan Sun 0003
SenSys3
2024 Entanglement Distribution in LEO Satellite-based Dynamic Quantum Networks
abstract
Recent advances in space quantum communications envision Low Earth Orbit (LEO) satellites for global entanglement distribution. Entanglement distribution in such a network requires considerations such as satellite mobility, ground station mobility due to the Earth’s rotation, inter-satellite links, and multiple orbital shells, all of which have not been thoroughly studied in the networking literature. We ameliorate this deficit by defining a system model which accounts for all of the aforementioned factors. Using this system model, we formulate the dynamic optimal entanglement distribution (DOED) problem. We convert the DOED problem in a dynamic physical network to an instance of the problem in a static logical graph, the latter of which can be used to solve the former. We obtain a reduced logical graph from a logical graph, which can be used to reduce the complexity of solving the DOED problem. We propose two polynomial-time greedy algorithms for computing entanglement paths, as well as an integer linear programming (ILP)-based algorithm as a benchmark. We present evaluation results to demonstrate the advantages of our model and algorithms.
Alena Chang, Yinxin Wan, Xuanli Lin, Guoliang Xue, Arunabha Sen
GLOBECOM2
2024 Quantum Communication in 6G Satellite Networks: Entanglement Distribution Across Changing Topologies
abstract
As LEO/VLEO satellites offer many attractive features, such as low transmission delay, they are expected to be an integral part of 6G. Global entanglement distribution over LEO and VLEO satellite network must reckon with satellite movement over time. Current studies do not fully capture the dynamic nature of satellite constellations. We model a dynamic LEO/VLEO satellite network as a time-varying graph and construct a sequence of static graphs to represent a dynamic network. We study the entanglement distribution problem between a set of source-destination node pairs in this dynamic network utilizing Multi-commodity Flow (MCF). Solving MCF over a sequence of graphs independently for each graph may produce a completely different set of paths. Changing the set of paths every time the graph topology changes may involve a significant amount of overhead, as an established set of paths must be taken down and a new set of paths established. We propose a technique that will avoid this overhead by computing only one set of paths P to be used over all the graphs in the sequence. The degraded performance offered by$P$may be viewed as the cost of using P. The benefit of using$P$is the overhead cost of path switching that can be avoided. We provide a cost-benefit analysis in a LEO/VLEO constellation for entanglement distribution between multiple source-destination pairs. Our extensive experimentation shows that a significant amount of savings in overhead can be achieved if one is willing to accept a slightly degraded performance.
Arunabha Sen, Christopher Sumnicht, Sandipan Choudhuri, Alena Chang, Guoliang Xue, Yinxin Wan
ICC6
2023 Extracting Spatial Information of IoT Device Events for Smart Home Safety Monitoring
Yinxin Wan, Xuanli Lin, Kuai Xu, Feng Wang 0002, Guoliang Xue
INFOCOM1
2022 Inferring User Activities from IoT Device Events in Smart Homes: Challenges and Opportunities
abstract
The ubiquitous deployment of IoT devices in smart homes has led to growing research interests in studying the home network traffic for various applications such as network measurements, device profiling, and IoT device event inference. Recent studies have shown that user activities can be inferred from a home network using extracted device event logs. However, existing solutions for user activity inference such as IoTMosaic and$\text{E2AP}$have limitations when handling ambiguities caused by device malfunctions. In this paper, we first identify the challenges faced by the existing user activity inference algorithms and the root causes of their poor performances on certain types of inputs. We then show that useful information can still be obtained even in situations where device malfunctions introduce ambiguities in user activity patterns. We achieve so by designing an extension to the existing algorithms. We also apply our extension in a digital forensics application. Our extensive experimental evaluations demonstrate that our solutions can effectively provide insights to user activity inference despite the presence of indistinguishable user activity patterns.
Xuanli Lin, Yinxin Wan, Kuai Xu, Feng Wang 0002, Guoliang Xue
ICCCN2
2022 IoTMosaic: Inferring User Activities from IoT Network Traffic in Smart Homes
abstract
Recent advances in cyber-physical systems, artificial intelligence, and cloud computing have driven the wide deployment of Internet-of-things (IoT) in smart homes. As IoT devices often directly interact with the users and environments, this paper studies if and how we could explore the collective insights from multiple heterogeneous IoT devices to infer user activities for home safety monitoring and assisted living. Specifically, we develop a new system, namely IoTMosaic, to first profile diverse user activities with distinct IoT device event sequences, which are extracted from smart home network traffic based on their TCP/IP data packet signatures. Given the challenges of missing and out-of-order IoT device events due to device malfunctions or varying network and system latencies, IoTMosaic further develops simple yet effective approximate matching algorithms to identify user activities from real-world IoT network traffic. Our experimental results on thousands of user activities in the smart home environment over two months show that our proposed algorithms can infer different user activities from IoT network traffic in smart homes with the overall accuracy, precision, and recall of 0.99, 0.99, and 1.00, respectively.
Yinxin Wan, Kuai Xu, Feng Wang 0002, Guoliang Xue
INFOCOM1
2022 An Effective Machine Learning Based Algorithm for Inferring User Activities From IoT Device Events
abstract
The rapid and ubiquitous deployment of Internet of Things (IoT) in smart homes has created unprecedented opportunities to automatically extract environmental knowledge, awareness, and intelligence. Many existing studies have adopted either machine learning approaches or deterministic approaches to infer IoT device events and/or user activities from network traffic in smart homes. In this paper, we study the problem of inferring user activity patterns from a sequence of device events by first deterministically extracting a small number of representative user activity patterns from the sequence of device events, then applying unsupervised learning to compute an optimal subset of these user activity patterns to infer user activity patterns. Based on extensive experiments with sequences of device events triggered by 2,959 real user activities and up to 30,000 synthetic user activities, we demonstrate that our scheme is resilient to device malfunctions and transient failures/delays, and outperforms the state-of-the-art solution.
Guoliang Xue, Yinxin Wan, Xuanli Lin, Kuai Xu, Feng Wang 0002
IEEE J. Sel. Areas Commun.2
2022 IoTAthena: Unveiling IoT Device Activities From Network Traffic
abstract
The recent spate of cyber attacks towards Internet of Things (IoT) devices in smart homes calls for effective techniques to understand, characterize, and unveil IoT device activities. In this paper, we present a new system, named IoTAthena, to unveil IoT device activities from raw network traffic consisting of timestamped IP packets. IoTAthena characterizes each IoT device activity using an activity signature consisting of an ordered sequence of IP packets with inter-packet time intervals. IoTAthena has two novel polynomial time algorithms,sigMatchandactExtract. For any given signature,sigMatchcan capture all matches of the signature in the raw network traffic. UsingsigMatchas a subfunction,actExtractcan accurately unveil the sequence of various IoT device activities from the raw network traffic. Using the network traffic of heterogeneous IoT devices collected at the router of a real-world smart home testbed and a public IoT dataset, we demonstrate that IoTAthena is able to characterize and generate activity signatures of IoT device activities and accurately unveil the sequence of IoT device activities from raw network traffic.
Yinxin Wan, Kuai Xu, Feng Wang 0002, Guoliang Xue
IEEE Trans. Wirel. Commun.1
2020 IoTArgos: A Multi-Layer Security Monitoring System for Internet-of-Things in Smart Homes
abstract
The wide deployment of IoT systems in smart homes has changed the landscape of networked systems, Internet traffic, and data communications in residential broadband networks as well as the Internet at large. However, recent spates of cyber attacks and threats towards IoT systems in smart homes have revealed prevalent vulnerabilities and risks of IoT systems ranging from data link layer protocols to application services. To address the security challenges of IoT systems in smart homes, this paper introduces IoTArgos, a multi-layer security monitoring system, which collects, analyzes, and characterizes data communications of heterogeneous IoT devices via programmable home routers. More importantly, this system extracts a variety of multi-layer data communication features and develops supervised learning methods for classifying intrusion activities at system, network, and application layers. In light of the potential zero-day or unknown attacks, IoTArgos also incorporates unsupervised learning algorithms to discover unusual or suspicious behaviors towards smart home IoT systems. Our extensive experimental evaluations have demonstrated that IoTArgos is able to detect anomalous activities targeting IoT devices in smart homes with a precision of 0.9876 and a recall of 0.9763.
Yinxin Wan, Kuai Xu, Guoliang Xue, Feng Wang 0002
INFOCOM1
2020 Robust resource provisioning in time-varying edge networks
abstract
Edge computing is one of the revolutionary technologies that enable high-performance and low-latency modern applications, such as smart cities, connected vehicles, etc. Yet its adoption has been limited by factors including high cost of edge resources, heterogeneous and fluctuating demands, and lack of reliability. In this paper, we study resource provisioning in edge computing, taking into account these different factors. First, based on observations from real demand traces, we propose a time-varying stochastic model to capture the time-dependent and uncertain demand and network dynamics in an edge network. We then apply a novel robustness model that accounts for both expected and worst-case performance of a service. Based on these models, we formulate edge provisioning as a multi-stage stochastic optimization problem. The problem is NP-hard even in the deterministic case. Leveraging the multi-stage structure, we apply nested Benders decomposition to solve the problem. We also describe several efficiency enhancement techniques, including a novel technique for quickly solving the large number of decomposed subproblems. Finally, we present results from real dataset-based simulations, which demonstrate the advantages of the proposed models, algorithm and techniques.
Ruozhou Yu, Guoliang Xue, Yinxin Wan, Jian Tang 0008, Dejun Yang, Yusheng Ji
MobiHoc3
2019 P4PCN: Privacy-Preserving Path Probing for Payment Channel Networks
abstract
Recent advances in security and cryptography have enabled new paradigms for secure networking in various scenarios. The payment channel network (PCN) is a notable example, which has emerged from the combination of the traditional credit network in economics and the latest blockchain technology. PCN provides a secure and efficient way for conducting payments, by addressing both the intrinsic financial risk of the credit network and the scalability issue of the blockchain. A crucial challenge in PCN is routing, i.e., to find a set of paths that fulfill a payment request. Due to the fully distributed and dynamic nature of PCN, existing routing algorithms utilize active probing to improve routing success probability. However, while the payment itself is privacy-preserving through existing protocols, the probing process can leak sensitive information including the location of the sender or the recipient. In this paper, we address the privacy of the users in the path probing process, filling in the last piece of the privacy puzzle in PCN. We propose P4PCN, a cryptographic protocol for anonymous active probing without knowing the identities or public keys of the intermediate nodes, while hiding the locations of sender and recipient as well as any path-related information. Our protocol is lightweight and scales with the number of hops a probe explores. We confirm its performance via real-world implementation and simulation experiments.
Ruozhou Yu, Yinxin Wan, Vishnu Teja Kilari, Guoliang Xue, Jian Tang 0008, Dejun Yang
GLOBECOM2
2019 Multidimensional behavioral profiling of internet-of-things in edge networks
abstract
The last decade has witnessed research advances and wide deployment of Internet-of-things (IoT) in smart homes and connected industry. However, the recent spate of cyber attacks exploiting the vulnerabilities and insufficient security management of IoT devices have created serious challenges for securing IoT devices and applications. As a first step towards understanding and mitigating diverse security threats of IoT devices, this paper develops a measurement framework to automatically collect network traffic of IoT devices in edge networks, and build multidimensional behavioral profiles of these devices which characterize who, when, what, and why on the behavioral patterns of IoT devices based on continuously collected traffic data. To the best of our knowledge, this paper is the first effort to shed light on the IP-spatial, temporal, and cloud service patterns of IoT devices in edge networks, and to explore these multidimensional behavioral fingerprints for IoT device classification, anomaly traffic detection, and network security monitoring for millions of vulnerable and resource-constrained IoT devices on the Internet.
Kuai Xu, Yinxin Wan, Guoliang Xue, Feng Wang 0002
IWQoS2
2018 LASA: Lightweight, Auditable and Secure Access Control in ICN with Limitation of Access Times
abstract
Information Centric Networking (ICN), a future network architecture candidate, aims to alleviate the problem of insufficient bandwidth in traditional IP network. In ICN, contents are distributed in the whole network, so access control becomes more intractable. As we know, almost all of existing solutions consider it as a "Yes or No" problem, where a user either has the permission to access the corresponding content or not. However, in many practical situations, a content provider doesn't expect a single authorized user has the ability to access its repertory without times limitation when taking copyright protection into account. In this paper, we propose LASA, a lightweight, auditable and secure solution where legitimate users are limited to access a content provider's data within pre-designate times. In LASA, each content provider sets maximum access times for each legitimate user and edge routers perform authentication and audit based on users' signatures attached to interest packets. Once a legitimate user attempts to exceed his/her limited access times, his/her secret key will be leaked and the dishonest behavior will be detected. Our security analysis shows that LASA can provide signature unforgeability, data confidentiality and other security features. Experiment results show that our scheme LASA brings a little computational cost.
Peixuan He, Yinxin Wan, Qiudong Xia, Shaohua Li 0002, Jianan Hong, Kaiping Xue
ICC2