VLDB 2026 Research / reviewers in the wild / expert
Zhengguang Zhang 0001
dblp:23/8119-1
· DBLP profile ↗
7ranked-venue papers
5as first author
4since 2021 · last 2026
0000-0002-6069-0555ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 5 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Preamble Signaling in WLAN: Vulnerabilities, Attacks, and CountermeasuresabstractThe preamble of a Wi-Fi frame contains multiple Signal (SIG) fields that are crucial for communications. Through measurements and security analysis, we reveal confidentiality, predictability, and integrity vulnerabilities in the SIG fields. We then introduce a SIG tampering attack (SIGTAM), in which the attacker exploits these vulnerabilities to craft and transmit a signal that tampers with legitimate SIG fields while passing parity and cyclic redundancy check (CRC). The tampered SIG fields cause frame discard or decoding errors, and disrupt channel access of neighboring devices. We also develop strategies that make SIGTAM robust to channel impairments and synchronization errors. SIGTAM operates stealthily, affecting$\lt 20\%$of the subcarriers for only 4$\mu$s. Extensive simulations and over-the-air experiments on IEEE 802.11a/ax devices show that SIGTAM causes nearly 100% packet drop and error rates. Compared to jamming on selected SIG subcarriers, SIGTAM consumes$40\times$less energy to cause 100% packet drop, yet keeps overhearing devices deferring channel access for over$10\times$longer. Beyond denial-of-service (DoS), SIGTAM degrades throughput, increases latency, reduces channel utilization, and disrupts spatial reuse. To mitigate the threat of SIGTAM, we propose and evaluate a defense scheme that detects the attack, identifies affected subcarriers, and recovers legitimate SIG fields from their equalized frequency-domain symbols. Zhengguang Zhang 0001, Marwan Krunz |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Preamble Forgery and Injection in Wi-Fi Networks: Attacks and DefensesabstractIn Wi-Fi networks, the preamble plays a crucial role in frame detection, synchronization, and channel estimation. It also ensures compatibility and interoperability across devices that operate different versions of Wi-Fi (e.g., IEEE 802.11a/g/n/ac/ax/be). Despite its significance, the preamble lacks authenticity and confidentiality guarantees, relying solely on weak integrity protection. In this paper, we introduce novel Preamble Injection and Spoofing (PrInS) attacks that exploit these vulnerabilities. Specifically, we show how an adversary can inject forged preambles without payloads to disrupt legitimate receptions or force legitimate users to defer transmissions. We demonstrate the impact of PrInS attacks both via experiments using software-defined radios (SDRs) and via system-level simulations. Our results show that the adversary can almost silence the channel, degrading the throughput of a legitimate user down to 2% of its normal throughput. Even at$30\,$dB less power than the legitimate signal, the adversary still causes 87% reduction in throughput. Even when the attacker targets only a fraction of legitimate frames, the average packet latency and packet loss rate significantly increase. As a countermeasure, we propose preamble customization and randomization using group keys and timestamps, along with preamble authentication in the receive state machine. Our countermeasure detects forged preambles with nearly 100% accuracy while maintaining low false alarm rates in most scenarios. Most importantly, it remains backward-compatible with existing 802.11 standards and does not impact the synchronization and frame error rates of the Wi-Fi system. Zhengguang Zhang 0001, Marwan Krunz |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Adaptive Preamble Embedding With MIMO to Support User-Defined Functionalities in WLANsabstractAs the Wi-Fi technology transitions into its sixth generation (Wi-Fi 6), there is a growing consensus on the need to support security and coordination functions at the Physical (PHY) layer. In contrast to the costly approach of extending the PHY-layer header to support new functions (e.g., Spatial Reuse field in the Wi-Fi 6 frame), we propose to turn specific parts of the frame preamble into a reliable data field while maintaining its primary functions. Specifically, in this paper, we develop a scheme calledextensible preamble modulation (eP-Mod)for 802.11n/ac/ax protocols that are built on multiple-input-multiple-output (MIMO) and orthogonal frequency-division multiplexing (OFDM). For each frame,eP-Modcan embed up to 144 user bits into the 802.11ac preamble of an$8\times 8$MIMO$40\;$MHz transmission. The proposed scheme is adaptive to channel conditions and enables several promising PHY-layer services, such as PHY-layer encryption and channel/device authentication, and PHY-layer signaling. At the same time, it allows legacy (eP-Mod-unaware) devices to continue to process the received preamble as normal by guaranteeing that the proposed preamble waveforms satisfy the structural properties of a standardized preamble. Through numerical analysis, extensive simulations, and hardware experiments, we validate the practicality and reliability ofeP-Mod. Zhengguang Zhang 0001, Hanif Rahbari, Marwan Krunz |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | Preamble Injection and Spoofing Attacks in Wi-Fi NetworksabstractIn Wi-Fi networks, every frame begins with a preamble that is used to support frame detection, synchro-nization, and channel estimation. The preamble also establishes compatibility and interoperability among devices that operate different Wi-Fi versions (e.g., IEEE 802.11a/g/n/ac/ax). Despite the crucial functions of the preamble, no guarantees can be made on its authenticity or confidentiality. Only weak integrity protection is currently possible. In this paper, we introduce novel Preamble Injection and Spoofing (PrInS) attacks that exploit the vulnerabilities of the preamble. Specifically, an adversary can inject forged preambles without any payload for the purpose of disrupting legitimate receptions or forcing legitimate users to de-fer their transmissions. The proposed PrInS attacks are effective irrespective of the Wi-Fi versions used by the adversary and its targets, as the attacks take advantage of the physical (PHY) layer receive state machine and/or capture effect. The efficacy of our attacks are validated experimentally using software-defined radios (SDRs). Our results show that the adversary can almost silence the channel, bringing the throughput of a legitimate user to 2% of its normal throughput. Even at 30 dB less power, the adversary still causes an 87% reduction in the legitimate users' throughput. To mitigate the PrInS attacks, we propose a backward-compatible scheme for preamble authentication. Zhengguang Zhang 0001, Marwan Krunz |
GLOBECOM | 1 |
| 2020 | Expanding the Role of Preambles to Support User-defined Functionality in MIMO-based WLANsabstractAs the Wi-Fi technology goes through its sixth generation (Wi-Fi 6), there is a growing consensus on the need to support security and coordination functions at the Physical (PHY) layer, beyond traditional functions such as frame detection and rate adaptation. In contrast to the costly approach of extending the PHY-layer header to support new functions (e.g., Target Wake Time field in 802.11ax), we propose to turn a specific part of the frame preamble into a data field while maintaining its primary functions. Specifically, in this paper, we develop a scheme called extensible preamble modulation (ePMod) for the MIMO-based 802.11ac protocol. For each frame, eP-Mod can embed up to 20 bits into the 802.11ac preamble under 1 × 2 or 2 × 1 MIMO transmission modes to support the operations of a given PHY-layer function. The proposed scheme enables several promising PHY-layer services, such as PHY-layer encryption and channel/device authentication, PHYlayer signaling, etc. At the same time, it allows legacy (eP-Modunaware) devices to continue to process the received preamble as normal by guaranteeing that our proposed preamble waveforms satisfy the structural properties of a standardized preamble. Through numerical analysis, extensive simulations, and hardware experiments, we validate the practicality and reliability of ePMod. Zhengguang Zhang 0001, Hanif Rahbari, Marwan Krunz |
INFOCOM | 1 |
| 2017 | Cooperative Jamming Aided Secrecy Enhancement in Wireless Networks with Multiple EavesdroppersabstractIn this paper, we investigate cooperative security in wireless networks, where a source (Alice) intends to transmit a confidential message to a legitimate destination (Bob), with the help of a cooperative node (Charlie), in the presence of multiple independent eavesdroppers (Eves). In particular, cooperative jamming (CJ) is explored to enhance secure communication between Alice and Bob. We provide a transmit design to maximize the secrecy rate, subject to a secrecy outage probability (SOP) constraint. Specifically, we establish a condition under which positive secrecy rate can be guaranteed. In addition to secrecy rate performance, we also pay attention to the secure energy efficiency, defined as the ratio of secrecy rate to total power consumption. Numerical results validate the effectiveness and energy efficiency of our proposed CJ scheme. Lin Hu 0002, Hong Wen 0001, Bin Wu 0002, Jie Tang 0005, Zhengguang Zhang 0001, Yixin Jiang, Aidong Xu |
VTC Fall | 6 |
| 2017 | MISO Secure Transmission with Imperfect Channel State InformationabstractIn this paper, we study artificial noise (AN) assisted beamforming secure transmission system with imperfect main channel state information (CSI) between a friendly cooperative jammer (Oscar) and an authorized receiver (Bob). We deduce out the maximum secrecy rate of secure system and the corresponding optimal power allocation ratio between information signal and AN under the constraint of secrecy outage probability. For realistic security communication system, we use advanced back propagation neural network (BPNN) for channel estimation. The numerical results show that estimation error results in a decrease in secrecy rate, but BPNN channel estimator still can guarantee secure transmission. Analytical derivations and numerical simulations are presented to validate the correctness of obtained expressions. Huanhuan Song 0001, Hong Wen 0001, Lin Hu 0002, Zhengguang Zhang 0001 |
VTC Fall | 4 |