Hangcheng Cao

dblp:273/7833 · DBLP profile ↗
← Back
34ranked-venue papers
10as first author
34since 2021 · last 2026
0000-0002-0957-8576ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 5 first-author · 15 since 2021Security and privacy · 13 · 4 first-author · 13 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering
abstract
The intellectual property of deep generative networks (GNets) can be protected using a cascaded hiding network (HNet) which embeds watermarks (or marks) into GNet outputs, known as box-free watermarking. Although both GNet and HNet are encapsulated in a black box (called operation network, or ONet), with only the generated and marked outputs from HNet being released to end users and deemed secure, in this paper, we reveal an overlooked vulnerability in such systems. Specifically, we show that the hidden GNet outputs can still be reliably estimated via query-based reverse engineering, leaking the generated and unmarked images, despite the attacker's limited knowledge of the system. Our first attempt is to reverse-engineer an inverse model for HNet under the stringent black-box condition, for which we propose to exploit the query process with specially curated input images. While effective, this method yields unsatisfactory image quality. To improve this, we subsequently propose an alternative method leveraging the equivalent additive property of box-free model watermarking and reverse-engineering a forward surrogate model of HNet, with better image quality preservation. Extensive experimental results on image processing and image generation tasks demonstrate that both attacks achieve impressive watermark removal success rates (100%) while also maintaining excellent image quality (reaching the highest PSNR of 34.69 dB), substantially outperforming existing attacks, highlighting the urgent need for robust defensive strategies to mitigate the identified vulnerability in box-free model watermarking.
Haonan An 0001, Guang Hua 0001, Hangcheng Cao, Zhengru Fang, Guowen Xu, Susanto Rahardja, Yuguang Fang
AAAI3
2026 MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data Marketplaces
abstract
The development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities instead of raw data. Among existing solutions, martFL (CCS 2023) represents the state-of-the-art FL-based data marketplace architecture, integrating privacy-preserving model evaluation and verifiable trading protocols to enable robust and fair model utility trading without revealing raw data. Despite its strengths, martFL suffers from critical weaknesses at the evaluation layer, including plaintext score exposure and unverifiable and manipulable participant selection. To address these challenges, we propose MartDE, a dedicated evaluation framework that builds model-centric data marketplaces with robust, privacy-preserving, and verifiable mechanisms. MartDE introduces encrypted utility scoring with client-side decryption to preserve score confidentiality, formally bounded anomaly filtering, adaptive participant selection based on global model performance, and commitment-based verification to ensure consistency between declared and evaluated scores and selection verification. We implement MartDE and evaluate it across diverse datasets and adversarial conditions. Results show that MartDE achieves superior accuracy, robustness, and cost-efficiency, providing a strong foundation for secure and trustworthy utility-driven data marketplaces.
Xinyuan Qian 0002, Haoyong Wang, Hangcheng Cao, Shuai Yuan 0009, Senkang Hu, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu
AAAI3
2026 Decoder Gradient Shields: A Family of Provable and High-Fidelity Methods Against Gradient-Based Box-Free Watermark Removal
abstract
Box-free model watermarking has gained significant attention in deep neural network (DNN) intellectual property protection due to its model-agnostic nature and its ability to flexibly manage high-entropy image outputs from generative models. Typically operating in a black-box manner, it employs an encoder-decoder framework for watermark embedding and extraction. While existing research has focused primarily on the encoders for the robustness to resist various attacks, the decoders have been largely overlooked, leading to attacks against the watermark. In this paper, we identify one such attack against the decoder, where query responses are utilized to obtain backpropagated gradients to train a watermark remover. To address this issue, we propose Decoder Gradient Shields (DGSs), a family of defense mechanisms, including DGS at the output (DGS-O), at the input (DGS-I), and in the layers (DGS-L) of the decoder, with a closed-form solution for DGS-O and provable performance for all DGS. Leveraging the joint design of reorienting and rescaling of the gradients from watermark channel gradient leaking queries, the proposed DGSs effectively prevent the watermark remover from achieving training convergence to the desired low-loss value, while preserving image quality of the decoder output. We demonstrate the effectiveness of our proposed DGSs in diverse application scenarios. Our experimental results on deraining and image generation tasks with the state-of-the-art box-free watermarking show that our DGSs achieve a defense success rate of 100% under all settings.
Haonan An 0001, Guang Hua 0001, Hangcheng Cao, Yihang Tao, Guowen Xu, Susanto Rahardja, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.4
2026 Security Analysis of WiFi-Based Sensing Systems: Threats From Perturbation Attacks
abstract
Deep learning technologies have seen widespread adoption in WiFi-based wireless sensing systems. However, they are inherently vulnerable to adversarial perturbation attacks, which has received little attention within the WiFi sensing community. To more comprehensively understand the potential threats posed by perturbation attacks, we present a novel attack method, named WiIntruder, distinguishing itself with universality, robustness, and stealthiness. This paper intends to provide a catalyst that promotes the assessment of security in existing WiFi-based sensing systems. We achieve the three aforementioned salient features in WiIntruder through the following three steps: (1) Maximizing transferability by differentiating user-state-specific feature spaces across sensing models, thereby enabling a universal perturbation attack vector applicable to a wide range of applications; (2) Mitigating the impact of perturbation signal distortion by optimizing key factors of device synchronization and wireless propagation through a heuristic particle swarm algorithm; and (3) Enhancing the diversity and stealthiness of attack patterns by randomly switching among perturbation surrogates generated by a generative adversarial network. Experimental results confirm the threat posed by WiIntruder to four common WiFi-based services, with the average accuracy decrease by 72.9% under black-box attack scenarios.
Hangcheng Cao, Wenbin Huang 0003, Guowen Xu, Xianhao Chen, Jingyang Hu, Hongbo Jiang 0001, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.1
2026 GCP: Guarded Collaborative Perception With Spatial-Temporal Aware Malicious Agent Detection
abstract
Collaborative perception significantly enhances autonomous driving safety by extending each vehicle's perception range through message sharing among connected and autonomous vehicles. Unfortunately, it is also vulnerable to adversarial message attacks from malicious agents, resulting in severe performance degradation. While existing defenses employ hypothesis-and-verification frameworks to detect malicious agents based on single-shot outliers, they overlook temporal message correlations, which can be circumvented by subtle yet harmful perturbations in model input and output spaces. This paper reveals a novel blind area confusion (BAC) attack that compromises existing single-shot outlier-based detection methods. As a countermeasure, we propose GCP, a Guarded Collaborative Perception framework based on spatial-temporal aware malicious agent detection, which maintains single-shot spatial consistency through a confidence-scaled spatial concordance loss, while simultaneously examining temporal anomalies by reconstructing historical bird's eye view motion flows in low-confidence regions. Wealso employ a joint spatial-temporal Benjamini-Hochberg test to synthesize dual-domain anomaly results for reliable malicious agent detection. Extensive experiments demonstrate GCP's superior performance under diverse attack scenarios, achieving up to 34.69% improvements in [email protected] compared to the state-of-the art CP defense strategies under BAC attacks, while maintaining consistent 5-8% improvements under other typical attacks. Code will be released at https://github.com/yihangtao/GCP.git.
Yihang Tao, Senkang Hu, Yue Hu 0011, Haonan An 0001, Hangcheng Cao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.5
2026 No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum Cleaner
abstract
Robot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.5
2026 FIGhost: Fluorescent Ink-Based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
abstract
Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Xinyuan Qian 0002, Hangcheng Cao, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.6
2026 Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language Models
abstract
Graph-based Retrieval-Augmented Generation (RAG) has achieved remarkable success in refining the outputs of Large Language Models (LLMs), enabling them to integrate relational and multi-hop knowledge into context-aware responses by constructing a knowledge graph from an external database. In this paper, we focus on the underexplored security risks arising from the external database, and propose the first backdoor attacks against the graph-based RAG of LLMs. Specifically, attackers insert the backdoor into the knowledge graph as entities by poisoning a carefully crafted corpus into the external database, thereby causing LLMs to output attacker-desired answers for trigger-containing queries while preserving correct answers for others. The attacks are formulated as a minimax problem, whose solution is a poison corpus. Powered by the chain-of-thought reasoning capabilities of LLMs, we propose a new strategy to solve the minimax problem. We craft retrieval text to insert triggers into the knowledge graph as entities, exploit hijacking text to redirect LLMs’ attention toward attacker-desired answers, and finally link the hijacking text to the triggers so that it serves as context only for trigger-containing queries. In addition, our attacks involve three types of triggers, including word-level, topic-level, and semantic-level, with progressively increasing stealthiness. Empirical results across multiple knowledge databases and language models indicate that the proposed attacks achieve the desired attack performance. Our findings highlight the substantial risks in LLM applications (e.g., chatbots and agents) built on graph-based RAG systems.
Zhirun Zheng, Young-June Choi, Cheng Huang 0001, Hangcheng Cao, Shujuan Tian, Tingrui Pei
IEEE Trans. Inf. Forensics Secur.4
2026 Learning Based Versatile Voice Eavesdropping Prevention for Mobile Devices
abstract
Voice-enabledmobile applications(apps) are exploding in popularity as they could be manipulated with voice commands to achieve convenient man-machine interaction. These voice-enabled apps also raise security and privacy concerns about whether they would maliciously invoke microphones to realize voice eavesdropping. To explore this issue, in this work, we design baleful apps to access the microphone covertly, the results of test studies demonstrate that covert eavesdropping attacks can bypass existing device detection schemes as well as are unnoticeable to human users. To prevent the covert voice eavesdropping attack, we propose a versatilemicrophone icon detection(MicID) scheme inspired by the groundtruth that authorization of the voice function requires the user to touch the specific microphone icon in most of voice-based apps. Specifically, we devise a deep learning model,lightweight YOLO(L-YOLO), to locate the microphone icon on the screen quickly and accurately. By determining whether the located microphone icon is touched by the user, we can judge whether the current microphone access belongs to the app's normal operation or illegal eavesdropping. Finally, we conduct extensive experiments by deploying the scheme on real devices and collecting dataset. The evaluation results show that the proposed MicID scheme achieves more than 99% accuracy with low computation cost.
Wenbin Huang 0003, Ju Ren 0001, Hangcheng Cao, Hongbo Jiang 0001, Panlong Yang, Zhangjie Fu 0001
IEEE Trans. Mob. Comput.3
2026 Leverage the Duty Ratio of Frequency-Shift Wave to Design a Novel Amplitude Modulation for Backscatter Communications
abstract
The demand for ultra-low-power wireless connectivity motivates the study of backscatter communication technology. There are already some related products on the market based on excitation signals from commercial radios. However, their modulation techniques, which are the key to backscatter communications, mainly focus on the phase or frequency domain while amplitude modulation is largely ignored. Most research works either deploy one finely tuned RF impedance port for every needed reflection state or connect a nonlinear device to antenna and tune the reflection amplitude by adjusting its biasing voltage, where the former is too complex and the latter is unstable under variable incident signal power, limiting the backscatter applications. For this reason, we introduce AMscatter to leverage the duty ratio of the frequency-shift wave (FS-wave) to design a novel amplitude modulation. Both theoretical analysis and experimental results show that the reflection amplitude approximates a sinusoidal function of the duty ratio. This method requires only two fixed RF impedances, making AMscatter simple and stable. Moreover, we show how to use AMscatter to design quadrature amplitude modulation (QAM) and pulse shaping to improve backscatter communication performance. Extensive experimental results show that the throughput can be as high as 3.9 Mbps, the supported operational range can reach 20 m with 16-QAM modulation, and the out-of-band interference can be suppressed by 15 dB without negatively affecting the communication performance through our pulse shaping.
Longzhi Yuan, Hangcheng Cao, Wei Gong 0001, Yuguang Fang
IEEE Trans. Mob. Comput.2
2026 Sub-Symbol Backscatter Using CCK Signal in WiFi
abstract
Throughput is a critical performance metric in backscatter communication systems. Existing approaches either suffer from limited throughput or necessitate modifications to transmitters or receivers, leading to incompatibility with commodity radios. In this paper, we introduce SubScatter, a system that achieves both high throughput and excellent compatibility. It employs a single Complementary Code Keying (CCK)-modulated 802.11b WiFi symbol to transmit eight tag bits by manipulating the phase of the backscattered signal across eight discrete time slots within the symbol, thereby enhancing throughput. To ensure compatibility with commercial-off-the-shelf (COTS) radios, SubScatter exclusively utilizes the physical service data unit (PSDU) for recovering the backscatter modulation that conveys the tag bits. Additionally, SubScatter employs real-time Hamming distance calculations to synchronize the binary envelope from the synchronization circuit with a reference sequence, facilitating the sub-symbol backscatter modulation. In addition, we emphasize SubScatter’s versatility in adapting its modulation scheme to optimize performance across various channel conditions. Extensive experiments conducted with our prototype validate its effectiveness, achieving a throughput approximately 11 times higher than that of leading backscatter systems compatible with COTS radios. Our Hamming-distance-based synchronization method outperforms conventional designs that rely solely on signal power detection, successfully reducing the bit error rate (BER) from over 10% to below 1%. Moreover, SubScatter’s throughput can be flexibly adjusted from 11 Mbps to 1.57 Mbps, while the BER improves from 0.29% to 0.04%.
Longzhi Yuan, Hangcheng Cao, Wei Gong 0001, Yuguang Fang
IEEE Trans. Netw.2
2025 Can Small-scale Evaluation Reflect Real Ability? A Performance Study of Emerging Biometric Authentication
Hangcheng Cao, Guowen Xu, Wenbin Huang 0003, Hongwei Li 0001
AsiaCCS1
2025 Direct Cardiovascular Disease Diagnosis From Multi-Modal Multi-View Ultrasound Via Unified Vision-Language Modeling
abstract
Cardiovascular disease diagnosis via ultrasound screening relies on manually measured metrics and the experience level of human experts, which is time-consuming and may overlook subtle cross-anatomical pathological patterns. Recent vision-language models offer end-to-end diagnostic potential but lack mechanisms to handle heterogeneous multi-modal, multiview ultrasound data while preserving modality-specific semantics. To fill this gap, we propose an end-to-end framework called MMVL that directly fuses raw ultrasound sequences from diverse anatomical regions, bypassing intermediate measurements, and enabling direct diagnosis. We design lightweight adapters for domain-specific multi-modal feature fusion and refinement, a gating mechanism that dynamically reweights modality importance based on global context, and disease-aware prompt-guided classification. MMVL ensures robust performance across both common and rare conditions. The proposed multi-view, multimodal vision-language framework enables end-to-end cardiovascular disease diagnosis with a 10.9% accuracy gain, and opens a new avenue for automated and generalizable diagnostic solutions.
Bin Pu, Jiewen Yang, Hangcheng Cao, Xingguo Lv, Lei Zhao 0013, Qika Lin, Yifan Zhu 0001, Kenli Li 0001
BIBM3
2025 Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition
abstract
Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues such as conspicuousness, limited effectiveness, and insufficient robustness. To address these challenges, we propose a novel approach for adversarial face generation, UVHat, which utilizes ultraviolet (UV) emitters mounted on a hat to enable invisible and potent attacks in black-box settings. Specifically, UVHat simulates UV light sources via video interpolation and models the positions of these light sources on a curved surface, specifically the human head in our study. To optimize attack performance, UVHat integrates a reinforcement learning-based optimization strategy, which explores a vast parameter search space, encompassing factors such as shooting distance, power, and wavelength. Extensive experimental evaluations validate that UVHat substantially improves the attack success rate in black-box settings, enabling adversarial attacks from multiple angles with enhanced robustness.
Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Wenbo Jiang 0001, Tao Ni 0003, Wenshu Fan, Qingchuan Zhao, Guowen Xu
ICML4
2025 Unveiling the Superiority of Unsupervised Learning on GPU Cryptojacking Detection: Practice on Magnetic Side Channel-Based Mechanism
abstract
Ample profits of GPU cryptojacking attract hackers to recklessly invade victims’ devices, for completing specific cryptocurrency mining tasks. Such malicious invasion undoubtedly obstructs normal device usage and wastes computation resources. To resist the threat of GPU cryptojacking, existing works aim to timely detect and clear away it, by distinguishing the dissimilitude between it and legitimate applications. However, these detection mechanisms inappropriately rely on two conflict cornerstones, manifested in leveragingmutable samples of illegitimate cryptojackingto designsupervision-based detection models requiring samples with stable patterns. This limitation compromises the practicability of existing detection mechanisms in the face of mutable cryptojacking samples. To fill the gap, we explore the superiority of unsupervised learning in handling this issue and further propose an unsupervised manner-enabled detection mechanism named MagInspector, only using legitimate applications’ magnetic signatures from GPU side channels for model construction. MagInspector innovates in training an unsupervised autoencoder network by an adversarial mode that well learns the stable signature patterns of legitimate applications, while incompatible with mutable cryptojacking ones. In the process of model training, we elaborately extract mutual energy cumulation distribution features to represent legitimate applications to overcome the impact of their inter-type differences. Meanwhile, a locality sensitive hashing-driven outlier removal algorithm is designed to enhance MagInspector’s robustness to the noise samples. Finally, extensive experiments are conducted on GPUs covering four generations of common NVIDIA architectures and two generations of AMD architectures; the results show that applying MagInspector to mutable cryptojacking signature detection achieves a significant average accuracy improvement of 25.5% and 17.8%, respectively.
Hangcheng Cao, Guowen Xu, Shaoqing Shi, Shengmin Xu, Cong Wu 0003, Jianting Ning
IEEE Trans. Inf. Forensics Secur.1
2025 The Lives of Others: Snooping on Smartphone Usage Behaviors via Attention-Enabled Multi-Channel Spatiotemporal Information Fusion
abstract
Using side-effect sensing information to monitor the behavior of smartphone usage raises privacy leakage concerns. However, existing research typically utilizes only a single sensing channel or performs a simple aggregation of multi-channel data to infer user behavior, without sufficiently leveraging rich spatiotemporal information embedded in the diverse sensing channels. Such a narrow focus of existing works fails to exhibit the real risk of user privacy leakage. To bridge this research gap, we propose HiddenSpy, a comprehensive study assessing the smartphone usage snooping associated with multiple sensing channels, such as accelerometers and magnetometers. We start by examining the relationship between the data gathered from each channel and daily usage behaviors, highlighting information volume differences across channels. Building on this analysis, we propose a multi-layer attention mechanism that dynamically adjusts the importance of spatiotemporal information from different channels and time frames, facilitating the efficient use of multi-channel data for behavior inference. Importantly, our work marks a pivotal shift from addressing information leakage in single channels to managing information exposure throughout the smartphone sensing system, laying the foundation for more comprehensive protective measures. To validate our approach, we collect data from forty widely-used applications and evaluate the corresponding usage behavior snooping performance. The results show that HiddenSpy improves accuracy in three common snooping tasks, while its defense mechanism reduces accuracy to a low level, effectively preventing information leakage.
Hangcheng Cao, Guowen Xu, Shengmin Xu, Xinyuan Qian 0002, Anjia Yang, Jianting Ning
IEEE Trans. Inf. Forensics Secur.1
2025 Mitigating Voice Assistant Eavesdropping via Event Source Review on Mobile Devices
abstract
Voice assistants have been widely adopted for their ability to provide non-touch human-computer interaction. However, while they offer convenience, their continuous listening for specific wake-up words raises privacy concerns, as it may lead to eavesdropping on user conversations. To investigate this issue, we devised covert eavesdropping attacks by perturbing and replaying events generated during the user’s normal activation of the voice assistant. The results demonstrate the feasibility and harmfulness of such eavesdropping attacks. To counter these covert voice eavesdropping attacks, we propose an effective defense scheme called CrossUnwind. This scheme leverages the groundtruth that voice assistant wake-up requires hardware to generate and send wake-up events. Specifically, we designed a novel tombstone file parsing process and an accurate event discrimination algorithm to obtain detailed call station information of the wake-up event without compromising the system. This allows us to determine whether the current wake-up event was generated by hardware. We deployed CrossUnwind on real devices and compared it to well-known machine learning and deep learning methods. The results demonstrate that CrossUnwind can achieve high accuracy in eavesdropping detection with faster speeds and lower resource utilization.
Wenbin Huang 0003, Ju Ren 0001, Hangcheng Cao, Hongbo Jiang 0001, Zhangjie Fu 0001
IEEE Trans. Inf. Forensics Secur.3
2025 RugScreener: Leveraging Temporal Graph Neural Network for Rugpull Detection in DeFi
abstract
The advent of decentralized finance has ushered in a transformative era in the financial sector, leveraging blockchain technology to facilitate peer-to-peer transactions without traditional intermediaries. Amidst this innovation, the DeFi landscape faces the pervasive threat of rugpulls, where developers abruptly abandon projects post-fundraising, leaving investors with devalued assets. This growing concern highlights a critical research gap in the proactive detection and prevention of such fraudulent schemes. To combat this, we propose RUGSCREENER, a temporal graph neural network-based solution to identify rugpull risks within DeFi transactions. It employs a dynamic representation of blockchain interactions, enriched with comprehensive node attributes and effective temporal graph learning techniques based on memory and attention mechanisms, effectively capturing the rapid-moving and complex transaction patterns indicative of potential fraud. Our evaluation is based on a newly compiled Ethereum dataset that includes two subsets: an unlabeled set with 1,882,114 transactions from 29,595 tokens for temporal graph representation learning, and a labeled set with 128,819 transactions from 1,000 tokens (500 rugpull and 500 benign) for downstream evaluation. Using this dataset, RUGSCREENER achieves a balanced accuracy of 95.7% in detecting rugpull tokens. Our extensive evaluation, utilizing the Ethereum dataset comprising 1000 tokens, showcases its robust performance with a balanced accuracy of 95.7% in detecting rugpull tokens. Remarkably, RUGSCREENER surpasses existing state-of-the-art graph learning models in detecting rugpull tokens with enhanced accuracy and reliability.
Cong Wu 0003, Hangcheng Cao, Jing Chen 0003, Xiyu Yan, Guowen Xu, Ziming Zhao 0001, Yang Liu 0003, Hongbo Jiang 0001
IEEE Trans. Inf. Forensics Secur.2
2024 M2-Fi: Multi-person Respiration Monitoring via Handheld WiFi Devices
abstract
Wi-Fi signals are commonly used for conventional communication, yet they can also realize low-cost and non-invasive human sensing. However, Wi-Fi sensing in Multi-person scenarios is still a challenging problem. In this paper, we propose M2-Fi to achieve multi-person respiration monitoring using a handheld device. M2-Fi leverages Wi-Fi BFI (beamforming feedback information) performs respiration monitoring. As a compressed version of the uplink CSI (channel state information), BFI transmission is unencrypted, easily obtained using frame capture, and does not require specific firmware to obtain. M2-Fi is based on an interesting experiment phenomenon that when a Wi-Fi device is very close to a subject, near-field channel changes caused by the subject significantly cancel out changes from other subjects. We employed VMD (Variational Mode Decomposition) to eliminate the interference caused by hand movement in the BFI time series. Subsequently, we devised a deep learning architecture based on GAN (Generative Adversarial Networks) to recover fine-grained respiration waveforms from the respiration patterns extracted from the BFI time series. Our experiments on collected 50-hour data from 8 subjects show that M2-Fi can accurately recover the respiration waveforms of multiple persons with handheld devices.
Jingyang Hu, Hongbo Jiang 0001, Tianyue Zheng, Jingzhi Hu, Hangcheng Cao, Zhe Chen 0015, Jun Luo 0001
INFOCOM6
2024 MIMOCrypt: Multi-User Privacy-Preserving Wi-Fi Sensing via MIMO Encryption
abstract
Wi-Fi signals may help realize low-cost and noninvasive human sensing, yet it can also be exploited by eavesdroppers to capture private information. Very few studies rise to handle this privacy concern so far; they either jam all sensing attempts or rely on sophisticated technologies to support only a single sensing user, rendering them impractical for multi-user scenarios. Moreover, these proposals all fail to exploit Wi-Fi’s multiple-in multiple-out (MIMO) capability. To this end, we propose MIMOCrypt, a privacy-preserving Wi-Fi sensing framework to support realistic multi-user scenarios. To thwart unauthorized eavesdropping while retaining the sensing and communication capabilities for legitimate users, MIMOCrypt innovates in exploiting MIMO to physically encrypt Wi-Fi channels, treating the sensed human activities as physical plaintexts. The encryption scheme is further enhanced via an optimization framework, aiming to strike a balance among i) risk of eavesdropping, ii) sensing accuracy, and iii) communication quality, upon securely conveying decryption keys to legitimate users. We implement a prototype of MIMOCrypt on an SDR platform and perform extensive experiments to evaluate its effectiveness in common application scenarios, especially privacy-sensitive human gesture recognition.
Jun Luo 0001, Hangcheng Cao, Hongbo Jiang 0001, Yanbing Yang 0001, Zhe Chen 0015
SP2
2024 Shield-U: Safeguarding Traffic Sign Recognition Against Perturbation Attacks
abstract
Traffic sign recognition systems are crucial for the navigation and situation awareness of autonomous vehicles. They leverage deep learning technologies to swiftly and accurately identify traffic signs, even in the most challenging traffic environments. However, security researchers have uncovered a critical vulnerability in these systems: learning-based TSRs are particularly susceptible to physical-world perturbation attacks. Through subtle modifications (i.e., attaching well-designed patches on traffic signs), attackers can deceive the recognition system into making erroneous judgments, which can further lead to serious traffic accidents. Although several defense mechanisms have been proposed to enhance the security of sign recognition systems, these solutions generally target only specific types of malicious perturbations and thus lack robustness. To address this issue, we present a robust defense mechanism named Shield-U, which restores traffic sign images contaminated by physical patch perturbations, providing credible data for the recognition model. In the process of implementing Shield-U, we first design a feature difference-aware perturbation generator that outputs potential sign contamination patterns. Incorporating generated perturbations during the training phase enables our restoration model to gain sufficient understanding of diverse perturbation types, thus enhancing its ability to repair various perturbed signs. Following this, we build an attention-driven restoration network to repair sign images. Finally, we evaluate the effectiveness of Shield-U using widely used sign recognition models and public datasets. The results demonstrate that our defense mechanism excels in resisting potential perturbations, increasing the average sign recognition accuracy by 50.4%.
Shengmin Xu, Jianfei Sun, Hangcheng Cao, Yulan Gao, Cong Wu 0003
TrustCom3
2024 LipAuth: Securing Smartphone User Authentication With Lip Motion Patterns
abstract
Modern smartphones hold massive amounts of private and potentially sensitive user data (e.g., identity and messages). User authentication is the key measure to protect such sensitive data from adversaries. In this article, we explore a novel authentication mechanism, LipAuth, leveraging the unique spatial-temporal features (i.e., both static physiological and dynamic behavioral characteristics) of human lips biometrics for secure and convenient user authentication, without requiring any special sensors on smartphones. The key principle behind LipAuth is that the geometric structure of lips is unique across different users while consistent and stable for the same user, which is dependent on three types of static features, i.e., lip width, thicknesses, and the joint characteristic of the former two, and the dynamic features in smiling process, i.e., the bending processes of the boundary lines between the upper and lower lips. On that basis, LipAuth can accurately identify legal users by actively extracting the spatial-temporal features on the lips’ profile changes, while also remaining fast and easy to use. We have implemented the prototype of LipAuth on Android platforms and comprehensively evaluated its performance by recruiting 50 volunteers. The experimental results show that LipAuth can achieve an overall 99.24% accuracy for user authentication and can resist potential intrusion from video replaying and mimic attacks.
Ling Kuang, Fanzi Zeng, Daibo Liu, Hangcheng Cao, Hongbo Jiang 0001, Jiangchuan Liu
IEEE Internet Things J.4
2024 HandKey: Knocking-Triggered Robust Vibration Signature for Keyless Unlocking
abstract
Door lock is regarded as a critical line of defending the privacy and security of personal areas. However, for inner doors in environments like factories, existing locking mechanisms can be poor in user-friendliness and high in cost. For instance, mechanical locks require carrying keys that inevitably compromise user experiences, while smart locks always require non-trivial sensors. Therefore, inner doors urgently require a lightweight unlocking scheme that can properly balance user-friendliness, cost, and security. To this end, we propose HandKey as a keyless unlocking scheme to supplement existing lock systems. HandKey relies on two principles: the simplicity of hand knocking doors and the uniqueness of vibration triggered by the knocking force. In other words, a door and a hand knocking it jointly form a unique physical system that generates hand-dependent and user-specific vibration signatures uniquely representing a user identity. In designing HandKey, we first analyze the vibration mechanism behind it and the impacts of gestures and door materials on vibration signatures. Then we innovatively construct a signal processing and deep learning-based pipeline to extract signatures robust to variable knocking behaviors for representing user identity. Finally, we implement a HandKey prototype and use extensive evaluation to demonstrate its security and effectiveness.
Hangcheng Cao, Daibo Liu, Hongbo Jiang 0001, Chao Cai 0001, Tianyue Zheng, John C. S. Lui, Jun Luo 0001
IEEE Trans. Mob. Comput.1
2024 MagSign: Harnessing Dynamic Magnetism for User Authentication on IoT Devices
abstract
User authentication is a critical module to achieve security and privacy protections, especially for pervasive Internet of Things (IoT) deployments. However, existing methods on IoT devices are significantly short ofimplementabilitythanks to the lack of device uniformity and protocol openness. For instance, password becomes useless for devices void of text entry interfaces. Biometrics may not scale well as they require both non-trivial sensors and cumbersome user involvement. Proximity-based methods exploiting shared ambient contexts are vulnerable to co-located malicious attacks. Therefore, a low-cost authentication scheme widely implementable on heterogeneous IoT devices is urgently demanded. To this end, we proposeMagSignthat leverages two fundamental capabilities owned by common IoT devices: the ubiquity of magnetic induction sensors and the power of screens to change magnetic field. Essentially, MagSign controls screen contents of an authorized device (possessed by a user) to generate specific currents in its electronic components that in turn induce a magnetic signature. This signature, sensed by a nearby device, allows the user to be authenticated and hence to unlock that device. In designing MagSign, we explore critical parameters employable to magnetic signature generation by analyzing electronic components’ workflow. Moreover, we innovatively encode binary sequences into magnetic intensity transitions, so that a sequence issued from a trusted server can be converted into a magnetic signature. Different from existing proximity-based approaches relying on shared static environment information, magnetic signature is directly derived from a server-issued sequence, allowing for dynamic signature generation that effectively thwarts potential attacks. The comprehensive experiments show MagSign has a false acceptance rate (FAR) of 0.38% and a false rejection rate (FRR) of 3.13%.
Hangcheng Cao, Daibo Liu, Hongbo Jiang 0001, Jun Luo 0001
IEEE Trans. Mob. Comput.1
2024 PACP: Priority-Aware Collaborative Perception for Connected and Autonomous Vehicles
abstract
Surrounding perceptions are quintessential for safe driving for connected and autonomous vehicles (CAVs), where the Bird's Eye View has been employed to accurately capture spatial relationships among vehicles. However, severe inherent limitations of BEV, like blind spots, have been identified. Collaborative perception has emerged as an effective solution to overcoming these limitations through data fusion from multiple views of surrounding vehicles. While most existing collaborative perception strategies adopt a fully connected graph predicated on fairness in transmissions, they often neglect the varying importance of individual vehicles due to channel variations and perception redundancy. To address these challenges, we propose a novelPriority-AwareCollaborativePerception (PACP) framework to employ a BEV-match mechanism to determine the priority levels based on the correlation between nearby CAVs and the ego vehicle for perception. By leveraging submodular optimization, we find near-optimal transmission rates, link connectivity, and compression metrics. Moreover, we deploy a deep learning-based adaptive autoencoder to modulate the image reconstruction quality under dynamic channel conditions. Finally, we conduct extensive studies and demonstrate that our scheme significantly outperforms the state-of-the-art schemes by 8.27% and 13.60%, respectively, in terms of utility and precision of the Intersection over Union.
Zhengru Fang, Senkang Hu, Haonan An 0001, Jingjing Wang 0001, Hangcheng Cao, Xianhao Chen, Yuguang Fang
IEEE Trans. Mob. Comput.6
2024 Manipulating Voice Assistants Eavesdropping via Inherent Vulnerability Unveiling in Mobile Systems
abstract
Numerous mobile devices are equipped with voice assistants to facilitate contactless user-device interaction. However, the widespread availability of voice assistants also raises security and privacy concerns, as they can be maliciously triggered to perform voice eavesdropping. Although diverse attacks have been taken to manipulate voice assistants for eavesdropping, they exhibit deficiencies of limited attack scopes and conspicuous attack behaviors because they target specific voice assistants or require extra voice commands to activate them. To manipulate arbitrary voice assistants for covert eavesdropping attack, we conduct a comprehensive analysis of voice assistant implementation in the Android system and refine a universal workflow. Through meticulous analysis and experimental verification, we uncover an inherent vulnerability that in voice assistants across device types that can be awakened by an artificial faking Intent. Building on this significant discovery, we propose an attack termed VoiceEar. It leverages a malicious event generation file and a first-in-first-out Intent generation algorithm to trigger voice assistants within the normal workflow for eavesdropping, without voice commands. Finally, we deploy the VoiceEar attacks on 25 mainstream mobile devices, and invite 95 volunteers for eavesdropping activity perception testing. The results unequivocally demonstrate the seamless execution of VoiceEar attacks, with neither users nor devices awareness.
Wenbin Huang 0003, Hangcheng Cao, Ju Ren 0001, Hongbo Jiang 0001, Zhangjie Fu 0001, Yaoxue Zhang
IEEE Trans. Mob. Comput.3
2024 Two-Factor Authentication for Keyless Entry System via Finger-Induced Vibrations
abstract
Keyless entry systems (KES) have become popular due to their high user-friendliness, while fingerprint and digital password authentication are two of the most widely used unlocking ways. However, current KES are vulnerable to security threats, such as fingerprint films that deceive fingerprint sensors and stolen passcodes. To address these issues, this paper presents${\sf Fingerbeat}$, a two-factor authentication system to defend the security risks of the current widely deployed KES devices.${\sf Fingerbeat}$combines original credentials, such as fingerprints and passcodes, with unique and persistent finger-induced vibrations to create a two-factor secure authentication model, while ensuring user-friendliness.${\sf Fingerbeat}$leverages the fact that each person's finger structure is distinct and can be represented in distinct vibration patterns. During authentication, FIV is triggered and embodied in the mechanical vibration of the force-bearing body (i.e., KES panel), which can be captured by a low-cost accelerometer. We develop a proof-of-concept prototype of${\sf Fingerbeat}$, extracting FIV features from mixed vibration recordings and eliminating the impacts of variable behaviors and external disturbance. Finally, we conduct extensive experiments to demonstrate its security and effectiveness.
Hongbo Jiang 0001, Panyi Ji, Taiyuan Zhang, Hangcheng Cao, Daibo Liu
IEEE Trans. Mob. Comput.4
2024 It's All in the Touch: Authenticating Users With HOST Gestures on Multi-Touch Screen Devices
abstract
As smartphones proliferate, secure and user-friendly authentication methods are increasingly critical. Existing behavioral biometrics, however, are often compromised by behavior variability, leading to poor authentication accuracy and an unsatisfactory user experience. To fill this gap, we proposeBioHold, a new robust and reliable user authentication method, fusing finger behavior and hand geometry, captured via a smartphone's multitouch screen during natural holding gestures. It synergistically fuses behavioral and physiological biometrics. In contrast to traditional methods that require restrictive, unnatural user patterns, our approach utilizes a stable, natural gesture for authentication, effectively mitigating behavior variability. It enables one-handed authentication through familiar smartphone-holding and unlocking gestures. During this interaction, hand geometry and behavioral characteristics are recorded for subsequent authentication. We evaluate our method using a dataset collected from 20 subjects, demonstrating its resilience against behavioral variability over time while maintaining a high level of distinctiveness. With only 10 training samples, our method achieves an equal error rate of 3.59%, which improves to 1.25% with 40 training samples. Importantly, our method is resistant to common security threats such as zero-effort attacks, smudge attacks, and shoulder surfing attacks. A usability study confirms the method's high user acceptance, as measured by the system usability score.
Cong Wu 0003, Hangcheng Cao, Guowen Xu, Jianfei Sun, Ran Yan 0001, Yang Liu 0003, Hongbo Jiang 0001
IEEE Trans. Mob. Comput.2
2024 CORA: Continuous Respiration Monitoring Using Analytical Signal Processing
abstract
Acoustic-based respiration sensing is promising due to its ubiquitous device support and great freedom in signal design. However, existing proposals often either fail to function properly when a target is non-static or is under multipath interference, or address it in an algorithmic manner. To this end, in this paper, we propose CORA, a COntinuous RespirAtion monitoring system using purely analytical signal processing methods. CORA is the first approach that achieves physical separation between motion artifacts and respiration, other than existing algorithmic solutions, and hence can obtain results that are closer to ground truth. CORA leverages the edges of Orthogonal Time Frequency Space signals in monitoring motion states and addressing multipath interference. The ability to tackle these challenges can help to compensate motion-induced artifacts for FMCW-based sensing techniques, enabling continuous respiration monitoring even in non-static scenarios. To achieve high-quality compensation, a pipeline of signal processing techniques is proposed, including robust moving target tracking, accurate frequency bin selection, and effective phase denoising. Unlike existing deep learning-based approaches, CORA is explainable and is readily deployable, without sophisticated adaptation or exhausted training processes. We have implemented a system prototype and evaluated its performance. Experiment results demonstrate a median error of 0.86 respiration per minute.
Junyi Zhou 0004, Henglin Pu, Hangcheng Cao, Chao Cai 0001, Peng Guo 0001, Hongbo Jiang 0001
IEEE Trans. Mob. Comput.3
2023 EarSonar: An Acoustic Signal-Based Middle-Ear Effusion Detection Using Earphones
abstract
Middle ear effusion is a common symptom of otitis media, the reactive physical manifestation of otitis media (OM) in children's middle ear. However, diagnosing MEE for little children at home is troublesome due to their difficulty cooperating and the caregiver's lack of medical knowledge. To this end, we propose EarSonar, a novel acoustic-based MEE diagnostic system. The principle behind EarSonar is that the acoustic absorption effect exists in ear scenarios, and the volume of middle ear fluid can markedly affect the absorbed spectrum energy. By automatically eliminating the impact of potential interference factors and identifying the representative frequency range with the typical reaction of acoustic absorption, EarSonar captures fine-grained signal features on absorbed spectrum energy and models the intrinsic relationship between acoustic absorption and the volume of the filler fluid in the eardrum. On that basis, EarSonar extracts the features of the MEE signal segment and uses k-means clustering to classify middle ear effusion status. We conducted a test on 112 adolescents aged 4–6. We divided the degree of middle ear effusion into three grades. The final average detection accuracy rate exceeds 92%, which is 8 % higher than the previous method. We have implemented a proof-of-concept prototype of EarSonar by building upon earphones embedded with a microphone and speaker. Experimental results demonstrate a feasible and effective way to turn earphones into potential home-use MEE screening tools.
Jingyang Hu, Hongbo Jiang 0001, Daibo Liu, Zhu Xiao, Hangcheng Cao, Schahram Dustdar, Jiangchuan Liu
ICDCS5
2023 LiveProbe: Exploring Continuous Voice Liveness Detection via Phonemic Energy Response Patterns
abstract
Voice assistants support contactless smart device control and thus act as a holy grail of human–computer interaction. However, recent studies reveal that an adversary can manipulate devices by vicious voice commands. This security risk is caused by only executing one-time liveness detection and lacking safeguard modules after service activation. Therefore, identifying speaker type (i.e., human articulators or loudspeakers) is critical in protecting voice-driven services during an entire interaction session. In this article, we propose a continuous voice liveness detection approach LiveProbe, leveraging unique energy response patterns in frequency bands induced by distinct voice generation mechanisms. The rationality behind LiveProbe is presented in two aspects: human articulator reshapes initial voices by exquisitely coordinated movements of vocal organs, which act as band-pass filters generating unique energy responses; nevertheless, the internal modules of loudspeakers are position fixed and cannot reproduce this response characteristic. To that end, we first work on voice generation mechanisms behind two-type speakers that cause spectrum differences. Then, we elaborately construct signal processing and deep-learning modules to extract liveness features. Especially, our approach does not interfere with normal voice interaction and need not to carry customized sensors. The experiment presents its effectiveness against potential attacks with a false acceptance rate of 0.51%.
Hangcheng Cao, Hongbo Jiang 0001, Daibo Liu, Geyong Min, Jiangchuan Liu, Schahram Dustdar, John C. S. Lui
IEEE Internet Things J.1
2023 Data-Augmentation-Enabled Continuous User Authentication via Passive Vibration Response
abstract
Continuous identity authentication is critical for privacy protection throughout an entire user login session. In this article, we propose a continuous user authentication mechanism, namely, HandPass, which employs the vibration responses from hand biometrics and is passively activated by natural user-device interaction. Hand vibration responses are embedded in the mechanical vibration of a force-bearing body consisting of one mobile device and one user hand. A built-in accelerometer of the device can capture hand-dependent vibration signals. Considering the concealment of vibration generation and the nonreplicability of hand structure, it is difficult for attackers to counterfeit user identity. Moreover, for ensuring the robustness of authentication performance to tapping behavior interference, we construct a data augmentation module jointly leveraging a signal processing and learning-based pipeline. It can generate enough vibration responses representing hand structure biometrics under various behaviors, thereby making HandPass comprehensively understand vibration response variation. We prototype HandPass on smartphones, and extensive experiments demonstrate that HandPass can achieve satisfactory authentication accuracy.
Hangcheng Cao, Hongbo Jiang 0001, Kehua Yang, Siyu Chen 0017, Jiangchuan Liu, Schahram Dustdar
IEEE Internet Things J.1
2023 LIPAuth: Hand-dependent Light Intensity Patterns for Resilient User Authentication
abstract
Authentication mechanisms deployed on access control systems undertake the responsibility of judging user identity to prevent unauthorized individuals from illegally approaching. In this article, we propose LIPAuth leveraging hand-dependent L ight I ntensity P attern to Auth enticate users. To be specific, lights released by a screen, are blocked and reflected by one hand above it; in this propagation process, hands exhibit user-specific ability in driving light absorption and attenuation due to owning unique structures, thereby outputting discriminative intensity patterns representing user identity. To implement LIPAuth , we first study the impact of screen contents on light intensity patterns, also explore the possibility of embedding hand structure biometrics into these patterns. We then design a customized dynamic stimulus-response mechanism for LIPAuth and make it resilient to the risks of potential registration profile leakage. Subsequently, we construct a joint pipeline consisting of signal processing and a learning-based generative adversarial network to overcome interference from variable user behaviors. More importantly, LIPAuth just utilizes common sensors to capture light signals, hence achieving low cost. We finally conduct extensive experiments in three scenarios to evaluate the authentication performance of LIPAuth prototype.
Hangcheng Cao, Daibo Liu, Hongbo Jiang 0001, Zhe Chen 0015, Jie Xiong 0001
ACM Trans. Sens. Networks1
2021 Evidence in Hand: Passive Vibration Response-based Continuous User Authentication
abstract
Continuous user authentication is of great importance to maintain security for a mobile system and protect user's privacy throughout a login session. In this paper, we propose HandPass, a continuous user authentication system that employs the vibration responses of concealed hand biometrics, which are passively activated by the natural user-device interactions on the touchscreen. Hand vibration responses are instantly triggered and embodied in the mechanical vibration of the force-bearing body (i.e., the mobile device and the holding hand). Therefore, a built-in accelerometer can effectively capture the intrinsic features of hand vibration responses. The hand vibration response is determined by the trigger force and the complex hand structure, which is unique to each user and is difficult (if not impossible) to counterfeit. HandPass is a passive hand vibration response-based continuous user authentication system hosted on smartphones, with advantages of non-intrusiveness, high efficiency, and user-friendliness. We prototyped HandPass on Android smartphones and comprehensively evaluated its performance by recruiting 43 volunteers. Experiment results show that HandPass can achieve 97.3 % overall authentication accuracy and only 1.8 % false acceptance rate in diverse scenarios.
Hangcheng Cao, Hongbo Jiang 0001, Daibo Liu, Jie Xiong 0001
ICDCS1