Edwin Yang

dblp:286/7946 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2024
0000-0002-1794-5014ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Revisiting Wireless Breath and Crowd Inference Attacks With Defensive Deception
abstract
Breathing rates and crowd counting can be used to verify the human presence, especially the former one can disclose a person’s physiological status. Many studies have demonstrated success in applying channel state information (CSI) to estimate the breathing rates of stationary individuals and count the number of people in motion. Due to the invisibility of radio signals, the ubiquitous deployment of wireless infrastructures, and the elimination of the line-of-sight (LOS) requirement, such wireless inference techniques can surreptitiously work and violate user privacy. However, little research has been conducted specifically in mitigating misuse of those techniques. This paper proposes new proactive countermeasures against all existing CSI-based vital signs and crowd counting inference methods. Specifically, we set up ambush locations with carefully designed wireless signals, allowing eavesdroppers to infer a false breathing rate or person count specified by the transmitter. The true breathing rate or person count is thus protected. Experimental results on software-defined radio platforms with 5 participants demonstrate the effectiveness of the proposed defenses. An eavesdropper can be misled into believing any desired breathing rate with an error of less than 1.2 bpm when the user lies on a bed in a bedroom, and 0.9 bpm when the user sits in a chair in an office room. Additionally, our proposed defense mechanisms can deceive an attacker into believing there are moving individuals in an empty room with a 100% success rate, using both Support Vector Machine (SVM) and Decision Tree (DT) classifiers.
Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao
IEEE/ACM Trans. Netw.2
2023 A Comparative Analysis of Data Augmentation Approaches for Improved Minority Behavior Detection in Digital Games
abstract
Previous research in behavioral- and game analytics showed that data augmentation plays a crucial role against the challenges of detecting minority entities (e.g. premium or retaining users) in behavioral datasets. By putting more emphasis on the minority entities, data augmentation allows us to utilize existing solutions without the need for extensive adjustments. In this study, we build upon previous work in this area by providing a comparison from both a methodology perspective and a data alteration perspective. The comparison focuses on three methods: Synthetic Minority Oversampling Technique (a nearest neighbor based approach), Variational Autoencoders, and Generative Adversarial Networks (both deep learning based approaches). We conduct an empirical evaluation using retention prediction in a freemium mobile game. Our findings indicate that each method offers advantages in terms of improved generalization results for different evaluation measures.
Rafet Sifa, Edwin Yang
IEEE Big Data2
2022 WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal Analysis
abstract
Sensitive numbers play an unparalleled role in identification and authentication. Recent research has revealed plenty of side-channel attacks to infer keystrokes, which require either a training phase or a dictionary to build the relationship between an observed signal disturbance and a keystroke. However, training-based methods are unpractical as the training data about the victim are hard to obtain, while dictionary-based methods cannot infer numbers, which are not combined according to linguistic rules like letters are. We observe that typing a number creates not only a number of observed disturbances in space (each corresponding to a digit), but also a sequence of periods between each disturbance. Based upon existing work that utilizes inter-keystroke timing to infer keystrokes, we build a novel technique called WINK that combines the spatial and time domain information into a spatiotemporal feature of keystroke-disturbed wireless signals. With this spatiotemporal feature, WINK can infer typed numbers without the aid of any training. Experimental results on top of software-defined radio platforms show that WINK can vastly reduce the guesses required for breaking certain 6-digit PINs from 1 million to as low as 16, and can infer over 52% of user-chosen 6-digit PINs with less than 100 attempts.
Edwin Yang, Qiuye He, Song Fang 0001
CCS1
2022 HoneyBreath: An Ambush Tactic Against Wireless Breath Inference
Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao
MobiQuitous2
2022 Wireless Training-Free Keystroke Inference Attack and Defense
abstract
Existing research work has identified a new class of attacks that can eavesdrop on the keystrokes in a non-invasive way without infecting the target computer to install malware. The common idea is that pressing a key of a keyboard can cause a unique and subtle environmental change, which can be captured and analyzed by the eavesdropper to learn the keystrokes. For these attacks, however, a training phase must be accomplished to establish the relationship between an observed environmental change and the action of pressing a specific key. This significantly limits the impact and practicality of these attacks. In this paper, we discover that it is possible to design keystroke eavesdropping attacks without requiring the training phase. We create this attack based on the channel state information extracted from the wireless signal. To eavesdrop on keystrokes, we establish a mapping between typing each letter and its respective environmental change by exploiting the correlation among observed changes and known structures of dictionary words. To defend against this attack, we propose a reactive jamming mechanism that launches the jamming only during the typing period. Experimental results on software-defined radio platforms validate the impact of the attack and the performance of the defense.
Edwin Yang, Song Fang 0001, Ian D. Markwood, Yao Liu 0007, Shangqing Zhao, Haojin Zhu
IEEE/ACM Trans. Netw.1
2021 CommanderGabble: A Universal Attack Against ASR Systems Leveraging Fast Speech
abstract
Automatic Speech Recognition (ASR) systems are widely used in various online transcription services and personal digital assistants. Emerging lines of research have demonstrated that ASR systems are vulnerable to hidden voice commands, i.e., audio that can be recognized by ASRs but not by humans. Such attacks, however, often either highly depend on white-box knowledge of a specific machine learning model or require special hardware to construct the adversarial audio. This paper proposes a new model-agnostic and easily-constructed attack, called CommanderGabble, which uses fast speech to camouflage voice commands. Both humans and ASR systems often misinterpret fast speech, and such misinterpretation can be exploited to launch hidden voice command attacks. Specifically, by carefully manipulating the phonetic structure of a target voice command, ASRs can be caused to derive a hidden meaning from the manipulated, high-speed version. We implement the discovered attacks both over-the-wire and over-the-air, and conduct a suite of experiments to demonstrate their efficacy against 7 practical ASR systems. Our experimental results show that the over-the-wire attacks can disguise as many as 96 out of 100 tested voice commands into adversarial ones, and that the over-the-air attacks are consistently successful for all 18 chosen commands in multiple real-world scenarios.
Zhaohe John Zhang, Edwin Yang, Song Fang 0001
ACSAC2
2020 Virtual Step PIN Pad: Towards Foot-input Authentication Using Geophones
abstract
The use of personal identification numbers (PINs) for authentication is ubiquitous due to their simplicity and flexibility. In this work, we present virtual step PIN pad, a novel and practical PIN entry scheme that allows a user to enter a PIN through foot tapping on the ground. The virtual step PIN pad utilizes geophones to collect structural vibration signals caused by foot tapping. When a user generates the activation signals by performing a predetermined sequence of foot taps within the target area, the virtual step PIN pad will be launched, and takes the foot tapping input by the user. The system then demodulates the corresponding structural vibration signals into a PIN. We have developed a prototype of the virtual step PIN pad and conduct a suite of experiments to evaluate its practicality and security. Experimental results show that the virtual step PIN pad can achieve an average success rate of 96.5% for inputting a human-chosen 4-digit PIN. Meanwhile, the success rate for an adversary at a distance of more than 2.5 meters away from the PIN pad to infer the target PIN decreases to below 3%.
Hanyan Zhang, Edwin Yang, Song Fang 0001
MASS3