Zhaoyi Lu 0001

dblp:230/1995-1 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-4096-3322ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 4 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Black-Box RF Fingerprint Spoofing via Surrogate-Guided Generative Perturbations
abstract
We study the feasibility of black-box radio frequency fingerprint (RFF) spoofing, where an adversary lacks access to the target receiver’s data or model. We present a surrogate-guided generative perturbation framework that jointly trains a generator with feedback from multiple surrogate receivers to synthesize low-power, fingerprint-level perturbations. Using real RF fingerprint datasets, we evaluate the spoofing effectiveness of forged perturbations on unseen receivers. Our results show that, even without any feedback from the target, an attacker can successfully impersonate a selected transmitter at an unseen receiver. However, the success remains limited and varies across devices, reflecting both the feasibility and the boundary of black-box RF fingerprint spoofing. These findings provide the first empirical evidence that multi-surrogate training can partially narrow the black-box gap in RF fingerprint spoofing.
Zhaoyi Lu 0001, Wenchao Xu 0001, Cunqing Hua
WISEC1
2024 Physical Layer Overshadowing Attack on Semantic Communication System
abstract
Semantic communication systems (SCS) have gained extensive attention with the advancement of Artificial Intelligence (AI), which transmits the data feature instead of the raw bits, whereby the communication efficiency can be substantially enhanced, e.g., via a neural network or encoder to convert from the massive user data to corresponding light-weight feature map. However, SCS can be vulnerable to adversarial noise when transmitting the feature data, which may mislead the downstream tasks at the receiver side, e.g., leading to misclassification due to the disturbed receiving information. In this paper, we investigate the overshadowing-based attacks by perturbing the physical signal with artificial adversarial noise during the semantic feature transmission. Specifically, we directly attack the waveform after the modulation of the feature bits, and conduct both the white-box and black-box attacks to evaluate the vulnerability. In our attack methods, we use the local transfer model to acquire the gradient details and provide the gradient-based strategy for generating the perturbation. The experiment results demonstrate that both white-box and black-box attacks can be a critical threat for SCS and significantly degrade the performance of downstream tasks.
Zhaoyi Lu 0001, Wenchao Xu 0001, Haozhao Wang, Cunqing Hua
ICC1
2024 Mobile Collaborative Learning Over Opportunistic Internet of Vehicles
abstract
Machine learning models are widely applied for vehicular applications, which are essential to future intelligent transportation system (ITS). Traditional model training methods commonly employ a client-server architecture to perform local training and global iterative aggregations, which can consume significant bandwidth resources that are often absent in vehicular networks, especially in high vehicle density scenarios. Modern vehicle users naturally can collaboratively train machine learning models as they are the data owner and have strong local computing power from the onboard units (OBU). In this paper, we propose a novel collaborative learning scheme for mobile vehicles that can utilize the opportunistic vehicle-to-roadside (V2R) communication to exploit the common priors of vehicular data without interaction with a centralized coordinator. Specifically, vehicles perform local training during the driving journey, and simply upload its local model to roadside unit (RSU) encountered on the way. RSU's model will be updated accordingly and sent back to the vehicle via the V2R communication. We have theoretically shown that RSUs' models can eventually converge without a backhaul connection. Extensive experiments upon various road configurations demonstrate that the proposed scheme can efficiently train models among vehicles without dedicated Internet access and scale well with both the road range and vehicle density.
Wenchao Xu 0001, Haozhao Wang, Zhaoyi Lu 0001, Cunqing Hua, Nan Cheng 0001, Song Guo 0001
IEEE Trans. Mob. Comput.3
2023 Receiver-Agnostic Radio Frequency Fingerprinting Based on Two-stage Unsupervised Domain Adaptation and Fine-tuning
abstract
Radio frequency fingerprint identification (RFFI) has been widely studied as a physical layer security scheme for device identification and authentication in wireless scenarios, such as Internet of Things (IoTs), industrial wireless networks, Internet of Vehicles (IoV), etc. Typical RFFI approaches train a model at the receiver to extract hardware defects of the transmitter RF front-end using a deep learning-based method and achieve classification. However, few works have taken into account its shortage in multiple-receiver scenarios, where the identification accuracy significantly decreases when migrating a model trained on the known receivers to the new ones, directly. In this paper, we propose a novel cross-receiver RFFI scheme to improve the performance and the generalization of the fingerprinting classification tasks on new receivers. This scheme tackles the shortage by two means: 1) we extract receiver- independent features using global domain adaptation based on adversarial training and relevant subdomain adaptation based on local maximum mean discrepancy (LMMD); 2) The performance is further improved by fine-tuning on few labeled samples when domain adaptation is not effective. The second mechanism brings in significant performance advantage, without a large amount of labeled data on new receivers. Experimental results on public datasets show the outstanding performance of the proposed scheme in cross-receiver scenarios.
Jiazhong Bao, Zhaoyi Lu 0001, Jianan Hong, Cunqing Hua
GLOBECOM3
2023 Non-Inducible RF Fingerprint Hiding via Feature Perturbation
abstract
Machine learning mechanisms are applied to detect the unique characteristics of the wireless interface or signaler that can distinguish one device's signal pattern from the others, which has been widely researched as the fingerprint for user identification. However, such fingerprinting can also be used for malicious purposes, i.e., identification tracking, undesired positioning, etc., as the unique features of the radio signal from a device is determined at the manufacturing stage and often cannot be easily removed afterward. To prevent privacy leakage from such radio frequency (RF) fingerprinting, in this paper, we propose an adversarial mechanism to hide the fingerprint whereby the device's identification cannot be induced by machine learning models from the preamble. Specially, we apply the adversarial attack method to attack the fingerprinting model by adding optimized adversarial perturbation to the preamble that can mislead the model classification results. To alleviate the adversarial sample's impact on communications and ensure the execution of packet detection at receivers, we improve the identification protection strategy with sparse perturbed features. In order to prevent further fingerprinting of re-training over the perturbed RF feature, we extend our method with the time-varying perturbations to further hide the device's identity. Extensive experiments are conducted, and we show that the proposed method can effectively hide the device identification from both the dedicated fingerprint model and the re-trained one from perturbed signals without disturbing the preamble functionality, which provides a gratifying confirmation of the proposed method.
Zhaoyi Lu 0001, Jiazhong Bao, Wenchao Xu 0001, Cunqing Hua
ICC1