VLDB 2026 Research / reviewers in the wild / expert
Boxiang He
dblp:244/8829
· DBLP profile ↗
11ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-9235-1144ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 8 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Large-Scale Aerial Reconfigurable Intelligent Surface-Aided Robust Anti-Jamming TransmissionabstractAerial reconfigurable intelligent surfaces (ARIS), deployed on unmanned aerial vehicles (UAVs), could enhance anti-jamming communication performance by dynamically configuring channel conditions and establishing reliable air-ground links. However, large-scale ARIS faces critical deployment challenges due to the prohibitive computational complexity of conventional discrete optimization methods and sophisticated jamming threats. In this paper, we introduce a mean-field modeling approach to design the spatial configuration of ARIS by a continuous density function, thus bypassing high-dimensional combinatorial optimization. We consider an adaptive jammer which adjusts its position and beamforming to minimize the sum-rate. A key finding reveals that the jammer’s optimal strategy is governed by a proximity-directivity trade-off between reducing path loss and enhancing spatial focusing. To combat the jamming, we propose a robust anti-jamming transmission framework that jointly optimizes the BS beamforming, the ARIS reflection, and the ARIS spatial distribution to maximize the worst-case sum-rate. By leveraging variational optimization and Riemannian manifold methods, we efficiently solve the functional optimization problems. Our analysis further unveils that the optimal ARIS deployment follows a spatial water-filling principle, concentrating resources in high-gain regions while avoiding interference-prone areas. Simulation results demonstrate that the proposed framework remarkably improves the sum-rate. Furthermore, the computational complexity of the proposed algorithm is independent of the number of UAVs, validating its effectiveness for scalable ARIS-assisted anti-jamming communications. Junshan Luo, Shilian Wang, Boxiang He, Yonggang Zhu |
IEEE Trans. Commun. | 3 |
| 2026 | Diffusion-Enabled Secure Semantic Communication Against EavesdroppingabstractThis paper proposes a novel diffusion-enabled pluggable encryption/decryption modules design against semantic eavesdropping, where the pluggable modules are optionally assembled into the semantic communication system for preventing eavesdropping. Inspired by the artificial noise (AN)-based security schemes in traditional wireless communication systems, in this paper, AN is introduced into semantic communication systems to prevent semantic eavesdropping. However, the introduction of AN also poses challenges for the legitimate receiver in extracting semantic information. Recently, denoising diffusion probabilistic models (DDPM) have demonstrated their powerful capabilities in generating multimedia content. Here, the paired pluggable modules are carefully designed using DDPM. Specifically, the pluggable encryption module generates AN and adds it to the output of the semantic transmitter, while the pluggable decryption module before semantic receiver uses DDPM to generate the detailed semantic information by removing both AN and the channel noise. In the scenario where the transmitter lacks eavesdropper’s knowledge, the artificial Gaussian noise (AGN) is used as AN. We first model a power allocation optimization problem to determine the power of AGN, in which the objective is to minimize the weighted sum of data reconstruction error of legal link, the mutual information of illegal link, and the channel input distortion. Then, a deep reinforcement learning framework using deep deterministic policy gradient is proposed to solve the optimization problem. In the scenario where the transmitter is aware of the eavesdropper’s knowledge, we propose an AN generation method based on adversarial residual networks (ARN). Unlike the previous scenario, the mutual information term in the objective function is replaced by the confidence of eavesdropper correctly retrieving private information. The adversarial residual network is then trained to minimize the modified objective function. Simulation results show that the diffusion-enabled pluggable encryption module prevents semantic eavesdropping with high covertness while the pluggable decryption module achieves the high-quality semantic communication. Boxiang He, Zihan Chen 0001, Fanggang Wang 0001, Shilian Wang, Zhijin Qin, Tony Q. S. Quek |
IEEE Trans. Wirel. Commun. | 1 |
| 2026 | Covert Pilot Spoofing Attack via Active Reconfigurable Intelligent SurfaceabstractThe active reconfigurable intelligent surface (RIS) offers a promising solution to overcome the double-fading attenuation inherent in passive RIS-aided systems. However, this capability can be exploited by adversaries to launch potent pilot spoofing attack (PSA). In this paper, we propose a novel active RIS-aided covert PSA scheme for time-division duplex systems, where a passive eavesdropper manipulates the channel state information (CSI) estimation at the legitimate transceiver during the uplink stage and steers downlink data towards itself during the downlink stage. Crucially, without requiring perfect instantaneous CSI, a practical challenge for eavesdroppers, we maximize the average eavesdropping signal-to-noise ratio (SNR) by jointly designing the RIS reflection coefficients for both stages. To ensure covertness, we integrate an anti-energy ratio detection (ERD) mechanism that constrains the detection probability below a predefined threshold. The resulting non-convex optimization problem is solved via an efficient alternating optimization algorithm combined with penalty methods, handling the rank-1 constraints and statistical CSI uncertainties. Simulations demonstrate that the proposed scheme achieves up to 26 dB SNR gain over passive RIS-aided PSA and reduces ERD detection probability compared to traditional PSA. This work reveals the dual-edged nature of the active RIS: while enhancing security, it introduces new attack schemes demanding advanced countermeasures. Junshan Luo, Zhengfei Qu, Boxiang He, Shilian Wang, Giorgio Taricco, Chau Yuen |
IEEE Trans. Wirel. Commun. | 3 |
| 2026 | Tag-Based Physical-Layer Authentication Against Message Interference
Boxiang He, Shilian Wang, Enyu Shi, Chau Yuen |
IEEE Trans. Wirel. Commun. | 2 |
| 2025 | RIS-Assisted Physical-Layer Key Generation for D2D Communications With Correlated and Imperfect ChannelsabstractPhysical-layer key generation (PKG) technology offers a lightweight encryption solution for device-to-device (D2D) communications. However, it faces significant challenges due to the high correlation between the eavesdropping and legitimate channels, as well as the imperfect estimated channel, which cause substantial degradation of secret key capacity. To address the challenges, we propose a novel PKG framework that leverages the reflective beamforming of reconfigurable intelligent surface (RIS) for D2D communications. Specifically, we first derive closed-form expression for the secret key capacity under correlated and imperfect estimated channels. Then, we propose to maximize the minimum secret key capacity by optimizing the reflection coefficient matrix (O-RCM) of RIS, which is a non-convex optimization problem. Next, a semi-definite relaxation and successive convex approximation-based method for O-RCM (SSO-RCM) is proposed to tackle the non-convex max-min-min problem. To further reduce the computational complexity, we propose a low-complexity method based on the path-following algorithm for O-RCM (PFO-RCM). Simulation results show that under correlated and imperfect channels, both proposed methods significantly improve the minimum secret key capacity compared to the existing RIS-assisted methods. Moreover, the PFO-RCM method, while exhibiting lower computational complexity than the SSO-RCM method, incurs a small performance loss. Boxiang He, Junshan Luo, Shilian Wang, Kang An 0001, Symeon Chatzinotas |
IEEE Internet Things J. | 2 |
| 2025 | Secure Communication via Nonlinear Transmit and Collaborative RelayingabstractPhysical layer security (PLS) enables secure communication which is independent of cryptography. It generally requires the legitimate channel being advantageous, otherwise, relaying techniques can be adopted to enhance the legitimate transmission and/or suppress the wiretap one. However, untrusted relays become new threatens since unknown passive eavesdroppers may approach either the transmitter or the receiver to wiretap the secure messages. Regarding the threatens in this setup, we propose a nonlinear transmit and relaying approach to protect the secure messages during the overall transmission. The essential idea is that Alice transmits a nonlinear transform of the original secure signal and the relays collaboratively invert the nonlinear transform at Alice when forwarding it to Bob. By carefully designing the layout of the relays, only a confined region where Bob locates is accessible to the non-distortion version of the original secure signal, and there is no secure signal leakage nearby Alice or the relays. Specifically, the proposed scheme consists of two phases. In the first one, a well-chosen nonlinear transform is applied to the secure signal of Alice, and she then broadcasts the transformed signal to both the relays and the eavesdropper. Each relay determines its forwarding approach by using either the Taylor series or the Lagrange inversion theorem on the nonlinear function of Alice to facilitate the perfect recovery of the original secure signal for Bob. In the second phase, the relays process the received signals using the well-designed forwarding approach and then cooperatively send them to Bob. The forwarding signals are aggregated at Bob and the original secure signal can be recovered directly without any further complicated equalization. We therefore define the region with this property by the secure-information-accessible region, and then provide the secrecy suggestions of laying the relays to shrink it. In contrast, the eavesdropper cannot get any useful secure information from either the first phase or the second one if it locates out of this region. Finally, we analyze both the bit error rate and the secrecy rate, and compare them with the existing secrecy methods. Numerical results validate the proposed nonlinear secrecy approach. Fanggang Wang 0001, Boxiang He, Junshan Luo |
IEEE Trans. Commun. | 3 |
| 2024 | Joint Transceiver Design for Secure Full-duplex Integrated Sensing and CommunicationabstractIn integrated sensing and communication (ISAC) system, the full-duplex is expected to further improve the integration and the efficiency. Here, we focus on the security of the full-duplex ISAC system. The serious interferences pose the challenges to the secure design of the full-duplex ISAC. In this paper, we propose a joint design of the information beamformer, the radar waveform, and the receive filters to minimize the eavesdropper’s signal-to-interference-plus-noise ratio or maximize the sum secrecy rate, where the sum capacity of the multiple access wiretap channel is taken into account in the optimization problems. An iterative algorithm is proposed for solving the formulated problems. Under appropriate conditions, the proposed iterative algorithm converges to the Karush-Kuhn-Tucker optimal point of the original problem without the rank 1 constraint. Then, we construct the new feasible solution without any performance loss while satisfying the rank 1 constraint. The simulation results indicate that our scheme outperforms the existing method, and can achieve a performance close to that of separate designs. Boxiang He, Fanggang Wang 0001 |
PIMRC | 1 |
| 2024 | Anti-Modulation-Classification Transmitter Design Against Deep Learning ApproachesabstractFor the modulation classification problems, the deep learning approaches can determine the unknown modulation formats in high confidence. However, it has been maliciously used by eavesdroppers. In this paper, we consider the wireless communication scenario, in which Alice intends to communicate with Bob confidentially in the threat of Eve, who tries to determine the unknown modulation formats of Alice using some deep learning approach. Recent advancements in adversarial machine learning have demonstrated that the deep learning techniques are vulnerable to crafted perturbations. To prevent Eve from classifying Alice’s modulation formats, Alice transmits the modulation signal with the well-designed adversarial perturbation. We first formulate an optimization problem to determine the optimized adversarial perturbation, in which the objective is to mislead the modulation classifier of Eve subject to the communication constraints, i.e., the power efficiency, the achievable rate, and the reliability. Then, the augmented Lagrangian method is adopted to solve the perturbation optimization problem, in which the implicit objective is evaluated using the Monte Carlo method, and the gradients of the implicit constraints are obtained using the Gaussian-based estimation algorithm. We further extend the perturbation design to the both cases of Alice having and not having the prior knowledge of Eve. Finally, the input-independent universal perturbation for the specific modulation type is proposed, which is deployed via a lookup table method. Numerical results show that the designed perturbation with 10% power of the modulated signal can attack Eve’s modulation classifier with the great success while ensuring both the achievable rate and the reliability close to the ideal case (say, no perturbation). Compared to the existing methods, the designed perturbation achieves the better attack performance and is robust to the filtering, the oversampling, and the time/frequency offset. Furthermore, this paper reveals that the structure type of Eve’s model has a large impact on the attack performance, and verifies that the adversarial perturbation can effectively attack the modulation classifiers that resort to the expert knowledge. Boxiang He, Fanggang Wang 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2024 | Joint Secure Transceiver Design for Integrated Sensing and CommunicationabstractThis paper studies the joint secure transceiver design for the full-duplex integrated sensing and communication (ISAC) system, in which the base station performs the target tracking and communicates with the downlink and the uplink users by reusing the resources. Here, the target, referred to as Eve, is a potential eavesdropper with the intention of intercepting both the downlink and the uplink information. The security problem of the full-duplex ISAC system has not been studied well, where the sensing and communication signals suffer from the serious interference. In this paper, we jointly design the information beamformer, the radar waveform, the uplink communication receive filter, and the radar receive filter to achieve the downlink and uplink communication security and the target tracking. Specifically, both the Eve’s signal-to-interference-plus-noise ratio minimization and the secrecy rate maximization problems, subject to the sensing and the communication constraints, are formulated for the ISAC system from the perspectives of the quality of service and the secrecy rate. An iterative algorithm is proposed for solving the formulated problems. We prove that, under appropriate conditions, the proposed iterative algorithm converges to the Karush-Kuhn-Tucker optimal point of the original problem without the rank 1 constraint. We further extend the joint design to the case of the imperfect wiretap channel and the angle uncertainty. Numerical results show that our scheme remarkably outperforms the benchmark approaches. The performance is close to that of designing the secure communication and the sensing separately. Boxiang He, Fanggang Wang 0001, Julian Cheng 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2023 | Specific Emitter Identification via Sparse Bayesian Learning Versus Model-Agnostic Meta-LearningabstractSpecific emitter identification (SEI) is a technique to identify the unknown emitters by using the hardware impairment of the transmitter. In this paper, we consider the effect of the wireless channel on the SEI, which deteriorates the identification performance severely. Two identifiers are proposed to address the wireless channel effect from the model-based and the data-based perspectives, respectively. From the model-based perspective, the fingerprint extractor using the sparse Bayesian learning (SBL) is first proposed to jointly estimate the fingerprint parameters, the wireless channel, and the noise power in the multipath fading channels. Then, the classifier using the weighted Euclidean distance is designed to identify the unknown emitter. From the data-based perspective, the model-agnostic meta-learning (MAML) algorithm is adopted to meta-train the convolutional neural network (CNN) on the task collection, which is generated based on the transmitter distortion mechanism and the channel distribution. The trained CNN is fine-tuned on the unseen SEI task and then is used to identify the unknown emitter. Moreover, the Cramer-Rao lower bounds of the estimation of the fingerprint parameters are derived to evaluate the performance of the proposed fingerprint extractor. Numerical results show that the SBL identifier outperforms the MAML one in a small number of samples, while the MAML identifier outperforms the SBL one in a large number of samples. Both identifiers are robust to the wireless channel, obtain better identification performance, and require a small number of samples compared to the existing methods. Furthermore, the simulation results indicate that the mean squared error performance of the SBL fingerprint extractor is close to the performance lower bound. Boxiang He, Fanggang Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Cooperative Specific Emitter Identification via Multiple Distorted ReceiversabstractSpecific emitter identification (SEI) is a technique that identifies the unique emitter from its received signal by using the specific characteristics of an emitter. In this paper, we consider an SEI problem with unknown receiver distortion. Two groups of SEI schemes based on signal decomposition are proposed. In the proposed schemes, the received signal is pre-processed by either of the following decomposition, i.e., empirical mode decomposition (EMD), intrinsic time-scale decomposition (ITD), or variational mode decomposition (VMD). In the first group of the proposed schemes, the skewness and the kurtosis are extracted from the decomposed signal, which characterize the non-Gaussian features of the signal. The support vector machine (SVM) or the back-propagation (BP) neural network is applied to fuse the features extracted from the multiple distorted receivers respectively and then determine the unknown emitter. In the second group of the proposed schemes, an approach based on the long short term memory (LSTM) is proposed. The LSTM model learns the deep features rather than the specific non-Gaussian features from the pre-processed signal. In contrast to the first group, the features used to identify the unknown emitter are extracted directly from the pre-processed signal by the trained LSTM model. Simulation results show that the proposed multi-receiver cooperative schemes can achieve the diversity gain in the identification performance. Moreover, we evaluate the identification performance of the proposed schemes in various channels, including the Gaussian channel and the fading channel. Compared to the existing methods based on different time-frequency representations, the proposed schemes possess the merits of high identification accuracy and low complexity. The significance of this paper is that the receive diversity can be achieved by the proposed schemes by using multiple distorted receivers even without compensating the receiver distortion prior to the identification. Boxiang He, Fanggang Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |