VLDB 2026 Research / reviewers in the wild / expert
Qun Song 0001
dblp:29/4368-1
· DBLP profile ↗
29ranked-venue papers
4as first author
27since 2021 · last 2026
0000-0002-3611-9404ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 2 first-author · 15 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TGM-Zero: Text Guided Zero-Day Detection and Fine-Grained Classification of DoS/DDoS Attacks
Tran L. T. Le, David K. Y. Yau, Qun Song 0001 |
INFOCOM | 3 |
| 2026 | ZA-SLAM: Leveraging Vision-Language Model for Zero-Shot Acoustic SLAMabstractExisting acoustic indoor location sensing systems are limited by the need for extensive data collection and model retraining in unseen environments. This paper introduces ZA-SLAM, a novel zero-shot acoustic Simultaneous Localization and Mapping (SLAM) system that can be deployed in unseen environments without model retraining. Our core idea is to train an acoustic encoder that inherits the generalization capabilities of pre-trained Vision-Language Models (VLMs), which show superiority in tasks like zero-shot visual SLAM. To achieve this goal, we perform Acoustic-Visual Feature Alignment to enable the acoustic encoder to generate features aligned with visual features from VLMs. To select high-quality images for effective alignment, we design a Semantic-Guided Image Selection that filters out low-quality collected images caused by factors like abrupt view changes, occlusions, and uninformative views. Furthermore, we address the challenge of false positive loop closures in structurally similar locations with the Learning-Based Trajectory Reachability Matching that validates loop closures leveraging IMU trajectory features. Extensive real-world experiments demonstrate that our system achieves comparable SLAM performance to retraining-based acoustic SLAM, and much improved performance compared to existing zero-shot Wi-Fi and geomagnetic SLAM systems. Our system achieves a mean mapping error of 0.56 m and a localization error of 0.78 m across multiple unseen environments. Zhuochen Yu, David K. Y. Yau, Yijie Shen, Xiaoran Fan, Tao Chen 0033, Qun Song 0001 |
MobiSys | 6 |
| 2026 | SVDefense: Effective Defense against Gradient Inversion Attacks via Singular Value Decomposition
Chenxiang Luo, David K. Y. Yau, Qun Song 0001 |
NDSS | 3 |
| 2026 | Knowledge-aware replay for multi-label class-incremental learning
Chengtai Cao, Xinhong Chen 0003, Qun Song 0001, Rui Tan 0001, Yung-Hui Li, Jianping Wang 0001 |
Expert Syst. Appl. | 3 |
| 2025 | Asymmetry Vulnerability and Physical Attacks on Online Map Construction for Autonomous DrivingabstractHigh-definition (HD) maps provide precise environmental information essential for prediction and planning in autonomous driving (AD) systems. Due to the high cost of labeling and maintenance, recent research has turned to online HD map construction using onboard sensor data, offering wider coverage and more timely updates for autonomous vehicles (AVs). However, the robustness of online map construction under adversarial conditions remains underexplored. In this paper, we present a systematic vulnerability analysis of online map construction models, which reveals that these models exhibit an inherent bias toward predicting symmetric road structures. In asymmetric scenes like forks or merges, this bias often causes the model to mistakenly predict a straight boundary that mirrors the opposite side. We demonstrate that this vulnerability persists in the real-world and can be reliably triggered by obstruction or targeted interference. Leveraging this vulnerability, we propose a novel two-stage attack framework capable of manipulating online constructed maps. First, our method identifies vulnerable asymmetric scenes along the victim AV's potential route. Then, we optimize the location and pattern of camera-blinding attacks and adversarial patch attacks. Evaluations on a public AD dataset demonstrate that our attacks can degrade mapping accuracy by up to 9.9% in average precision, render up to 44% of targeted routes unreachable, and increase unsafe planned trajectory rates—colliding with real-world road boundaries—by up to 27%. These attacks are also validated on a real-world testbed vehicle. We further analyze root causes of the symmetry bias, attributing them to training data imbalance, model architecture, and map element representation. Based on these findings, we propose asymmetric data fine-tuning as a targeted defense, which significantly improves model robustness. To the best of our knowledge, this study presents the first vulnerability assessment of online map construction models and introduces the first digital and physical attack against them. Yang Lou, Qun Song 0001, Qian Xu 0010, Yi Zhu 0012, Rui Tan 0001, Wei-Bin Lee, Jianping Wang 0001 |
CCS | 3 |
| 2025 | Dynamic Defense for Car-Borne LiDAR Vehicle DetectionabstractAdversarial attacks with real objects or lasers on car-borne LiDAR-based object detection are concerning. The existing defense approaches are often designed to address specific attacks and short of considering adaptive attackers who may adapt based on all available information about the deployed defense to maximize attack effect. This paper proposes Hyper3Def, a new defense for the function of detecting vehicle objects, which uses a Hypernet to generate an ensemble of multiple new detection models when needed at run time. The detection results of these models are fused to give the final result. As a dynamic defense, Hyper3Def revokes an important basis of the adaptive attack, i.e., the object detection model is needed to plan effective adversarial perturbations. Evaluation based on open data and real-world experiments with embedded system implementation show that, when confronting adaptive attacks, Hyper3Def outperforms various baseline defenses including the adversarial training, which is often cited as the state of the art. Dongfang Guo, Qun Song 0001, Yang Lou, Yi Zhu 0012, Jianping Wang 0001, Chunming Qiao, Rui Tan 0001 |
MobiSys | 3 |
| 2025 | Poster: Unsupervised Attack Classification in Smart Grid AGC Using Variational Autoencoder Gradient Profiles
Tran L. T. Le, David K. Y. Yau, Qun Song 0001 |
RTCSA | 3 |
| 2025 | Poster Abstract: Mobile Vision Dynamic Layer Dropping against Adversarial AttacksabstractDeep neural networks (DNNs) have achieved notable success in mobile vision tasks, yet they show vulnerability to adversarial attacks. When carefully crafted perturbations are introduced, these models can be easily misled into wrong classifications, posing significant risks for safety-critical mobile systems like autonomous vehicles. Although various defense strategies, both static and dynamic, have been proposed, many fail to address adaptive attacks or overlook the resource constraints of mobile systems. To address these limitations, in this paper, we present GuSoDrop, a lightweight dynamic defense framework that applies stochastic layer dropping. GuSoDrop leverages randomness to counteract adaptive attacks while selectively dropping less important layers to reduce computation overhead. Our preliminary evaluation shows that GuSoDrop outperforms state-of-the-art defense methods against different adaptive attacks and improves efficiency in reducing computational overhead. Zimo Ma, Qun Song 0001, Rui Tan 0001 |
SenSys | 3 |
| 2025 | Demo Abstract: Parameterized Stochastic Ensemble Defense for Object DetectionabstractCamera-based object detection excels but remains vulnerable to adversarial attacks that suppress target detection (object-hiding attacks). Here, we propose PaSED, a Parameterized Stochastic Ensemble Defense, which leverages HyperNetworks to enable rapid and diverse updates for detection models in the ensemble. At its core, we introduce functional diversity to enhance the defense robustness. It adapts each generation process to the input image preprocessing parameterized by HyperNetworks' random noise input. In our preliminary evaluations against physically deployed attacks, PaSED outperforms five baseline defenses without requiring attack knowledge. It recovers attacked objects in 92% and 98% of frames in the indoor and outdoor testbeds, respectively. Dongfang Guo, Qun Song 0001, Rui Tan 0001 |
SenSys | 4 |
| 2025 | Dynamic Layer Routing Defense for Real-Time Embedded VisionabstractDeep neural networks have advanced the perception and decision-making functions of smart embedded systems, such as car-borne driver assistance. Deploying these embedded neural networks often faces two challenges: (i) security vulnerabilities to adversarial examples that can be deployed in the perceived physical environment; (ii) limited computational resources coupled with dynamic conditions that necessitate real-time adaptation of model execution. However, these two challenges are often addressed separately in existing research. This article presents LeapNet, which aims to address both challenges simultaneously. It comprises two versions: LeapNet-1 and LeapNet-2. LeapNet-1 employs dynamic layer routing to counteract adaptive adversarial-example attacks and reduce computational redundancy. Building upon LeapNet-1, LeapNet-2 further adapts its layer routing configurations in real time to meet the frame processing rate requirements under dynamic conditions while maintaining defense performance. Extensive experiments on various representative datasets, neural network models, and adaptive attacks demonstrate the superiority of LeapNet over existing defense methods. On-road tests with a real-time car-borne traffic sign recognition system validate its effectiveness in maintaining frame processing rate under dynamic conditions. Zimo Ma, Qun Song 0001, Rui Tan 0001 |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | CCTR: Calibrating Trajectory Prediction for Uncertainty-Aware Motion Planning in Autonomous DrivingabstractAutonomous driving systems rely on precise trajectory prediction for safe and efficient motion planning. Despite considerable efforts to enhance prediction accuracy, inherent uncertainties persist due to data noise and incomplete observations. Many strategies entail formalizing prediction outcomes into distributions and utilizing variance to represent uncertainty. However, our experimental investigation reveals that existing trajectory prediction models yield unreliable uncertainty estimates, necessitating additional customized calibration processes. On the other hand, directly applying current calibration techniques to prediction outputs may yield sub-optimal results due to using a universal scaler for all predictions and neglecting informative data cues. In this paper, we propose Customized Calibration Temperature with Regularizer (CCTR), a generic framework that calibrates the output distribution. Specifically, CCTR 1) employs a calibration-based regularizer to align output variance with the discrepancy between prediction and ground truth and 2) generates a tailor-made temperature scaler for each prediction using a post-processing network guided by context and historical information. Extensive evaluation involving multiple prediction and planning methods demonstrates the superiority of CCTR over existing calibration algorithms and uncertainty-aware methods, with significant improvements of 11%-22% in calibration quality and 17%-46% in motion planning. Chengtai Cao, Xinhong Chen 0003, Jianping Wang 0001, Qun Song 0001, Rui Tan 0001, Yung-Hui Li |
AAAI | 4 |
| 2024 | Leveraging Foundation Models for Zero-Shot IoT SensingabstractDeep learning models are increasingly deployed on edge Internet of Things (IoT) devices. However, these models typically operate under supervised conditions and fail to recognize unseen classes different from training. To address this, zero-shot learning (ZSL) aims to classify data of unseen classes with the help of semantic information. Foundation models (FMs) trained on web-scale data have shown impressive ZSL capability in natural language processing and visual understanding. However, leveraging FMs’ generalized knowledge for zero-shot IoT sensing using signals such as mmWave, IMU, and Wi-Fi has not been fully investigated. In this work, we align the IoT data embeddings with the semantic embeddings generated by an FM’s text encoder for zero-shot IoT sensing. To utilize the physics principles governing the generation of IoT sensor signals to derive more effective prompts for semantic embedding extraction, we propose to use cross-attention to combine a learnable soft prompt that is optimized automatically on training data and an auxiliary hard prompt that encodes domain knowledge of the IoT sensing task. To address the problem of IoT embeddings biasing to seen classes due to the lack of unseen class data during training, we propose using data augmentation to synthesize unseen class IoT data for fine-tuning the IoT feature extractor and embedding projector. We evaluate our approach on multiple IoT sensing tasks. Results show that our approach achieves superior open-set detection and generalized zero-shot learning performance compared with various baselines. Our code is available at https://github.com/schrodingho/FM_ZSL_IoT. Dinghao Xue, Xiaoran Fan, Tao Chen 0033, Guohao Lan, Qun Song 0001 |
ECAI | 5 |
| 2024 | SGDCL: Semantic-Guided Dynamic Correlation Learning for Explainable Autonomous Driving
Chengtai Cao, Xinhong Chen 0003, Jianping Wang 0001, Qun Song 0001, Rui Tan 0001, Yung-Hui Li |
IJCAI | 4 |
| 2024 | A First Physical-World Trajectory Prediction Attack via LiDAR-induced Deceptions in Autonomous Driving
Yang Lou, Yi Zhu 0012, Qun Song 0001, Rui Tan 0001, Chunming Qiao, Wei-Bin Lee, Jianping Wang 0001 |
USENIX Security Symposium | 3 |
| 2024 | On Credibility of Adversarial Examples Against Learning-Based Grid Voltage Stability AssessmentabstractVoltage stability assessment is essential for maintaining reliable power grid operations. Stability assessment approaches using deep learning address the shortfalls of the traditional time-domain simulation-based approaches caused by increased system complexity. However, deep learning models are shown to be vulnerable to adversarial examples in the field of computer vision. While this vulnerability has been noticed by the power grid cybersecurity research, the domain-specific analysis on the requirements imposed upon effective attack implementation is still lacking. Although these attack requirements are usually reasonable in computer vision tasks, they can be stringent in the context of power grids. In this paper, we conduct a systematic investigation on the attack requirements and credibility of six representative adversarial example attacks based on a voltage stability assessment application for the New England 10-machine 39-bus power system. We show that (1) compromising about half the transmission system buses’ voltage traces is a rule-of-thumb attack requirement; (2) the universal adversarial perturbations regardless of the original clean voltage trajectory possess the same credibility as the widely studied false data injection attacks on power grid state estimation, while the input-specific adversarial perturbations are less credible; (3) the prevailing strong adversarial training thwarts the universal perturbations but fails in defending certain input-specific perturbations. To advance defense to cope with both universal and input-specific adversarial examples, we propose a new approach that simultaneously estimates the predictive uncertainty of any given input of voltage trajectory and thwarts the attacks effectively. Qun Song 0001, Rui Tan 0001, Chao Ren 0006, Yan Xu 0005, Yang Lou, Jianping Wang 0001, Hoay Beng Gooi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Indoor Smartphone SLAM With Acoustic EchoesabstractIndoor self-localization has become a highly desirable system function for smartphones. The existing systems based on imaging, radio frequency, and geomagnetic sensing may have sub-optimal performance when their limiting factors prevail. In this paper, we present a new indoor simultaneous localization and mapping (SLAM) system that is based on the smartphone's built-in audio hardware and inertial measurement unit (IMU). Our system uses a smartphone's loudspeaker to emit near-inaudible chirps and then the microphone to record the acoustic echoes from the indoor environment. The echoes contain the smartphone's location information with sub-meter granularity. To enable SLAM, we apply contrastive learning to train an echoic location feature (ELF) extractor, such that the loop closures on the smartphone's trajectory can be accurately detected from the associated ELF trace. The detection results effectively regulate the IMU-based trajectory reconstruction. The reconstructed trajectories are used fortrajectory map superimpositionandroom geometry reconstruction. Extensive experiments show that our SLAM achieves median localization errors of$\text{0.1}\,\text{m}$,$\text{0.53}\,\text{m}$, and$\text{0.4}\,\text{m}$in a living room, an office, and a shopping mall, and outperforms both the Wi-Fi and geomagnetic SLAM systems. The room geometry reconstruction achieves up to 4× lower errors compared with the latest echo-based approaches. Wenjie Luo 0001, Qun Song 0001, Zhenyu Yan 0002, Rui Tan 0001, Guosheng Lin |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Uncertainty-Encoded Multi-Modal Fusion for Robust Object Detection in Autonomous DrivingabstractMulti-modal fusion has shown initial promising results for object detection of autonomous driving perception. However, many existing fusion schemes do not consider the quality of each fusion input and may suffer from adverse conditions on one or more sensors. While predictive uncertainty has been applied to characterize single-modal object detection performance at run time, incorporating uncertainties into the multi-modal fusion still lacks effective solutions due primarily to the uncertainty’s cross-modal incomparability and distinct sensitivities to various adverse conditions. To fill this gap, this paper proposes Uncertainty-Encoded Mixture-of-Experts (UMoE) that explicitly incorporates single-modal uncertainties into LiDAR-camera fusion. UMoE uses individual expert network to process each sensor’s detection result together with encoded uncertainty. Then, the expert networks’ outputs are analyzed by a gating network to determine the fusion weights. The proposed UMoE module can be integrated into any proposal fusion pipeline. Evaluation shows that UMoE achieves a maximum of 10.67%, 3.17%, and 5.40% performance gain compared with the state-of-the-art proposal-level multi-modal object detectors under extreme weather, adversarial, and blinding attack scenarios. Yang Lou, Qun Song 0001, Qian Xu 0010, Rui Tan 0001, Jianping Wang 0001 |
ECAI | 2 |
| 2023 | VI-Map: Infrastructure-Assisted Real-Time HD Mapping for Autonomous DrivingabstractHD map is a key enabling technology towards fully autonomous driving. We propose VI-Map, the first system that leverages roadside infrastructure to enhance real-time HD mapping for autonomous driving. The core concept of VI-Map is to exploit the unique cumulative observations made by roadside infrastructure to build and maintain an accurate and current HD map. This HD map is then fused with on-vehicle HD maps in real time, resulting in a more comprehensive and up-to-date HD map. By extracting concise bird-eye-view features from infrastructure observations and utilizing vectorized map representations, VI-Map incurs low compute and communication overhead. We conducted end-to-end evaluations of VI-Map on a real-world testbed and a simulator. Experiment results show that VI-Map can construct decentimeter-level (up to 0.3 m) HD maps and achieve real-time (up to a delay of 42 ms) map fusion between driving vehicles and roadside infrastructure. This represents a significant improvement of 2.8× and 3× in map accuracy and coverage compared to the state-of-the-art online HD mapping approaches. A video demo of VI-Map on our real-world testbed is available at https://youtu.be/p2RO65R5Ezg. Chen Bian, Jingfei Xia, Shuyao Shi, Zhenyu Yan 0002, Qun Song 0001, Guoliang Xing |
MobiCom | 6 |
| 2023 | Touch-to-Access Device Authentication For Indoor Smart ObjectsabstractThis paper presents TouchAuth, a new touch-to-access device authentication approach using induced body electric potentials (iBEPs) caused by the indoor ambient electric field that is mainly emitted from the building's electrical network. The design of TouchAuth is based on the electrostatics of iBEP generation and a resulting property, i.e., the iBEPs at two close locations on the same human body are similar, whereas those from different human bodies are distinct. Extensive experiments verify the above property and show that TouchAuth achieves high-profile receiver operating characteristics in implementing the touch-to-access policy. Our experiments also show that a range of possible interfering sources including appliances’ electromagnetic emanations and noise injections into the power network do not affect the performance of TouchAuth. A key advantage of TouchAuth is that the iBEP sensing requires a simple analog-to-digital converter only, which is widely available on microcontrollers. Compared with the existing approaches including intra-body communication and physiological sensing, TouchAuth is a low-cost, faster, and easy-to-use approach for authorized users to access the smart objects found in indoor environments. Zhenyu Yan 0002, Qun Song 0001, Rui Tan 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Physics-directed Data Augmentation for Deep Model Transfer to Specific SensorabstractRuntime domain shifts from the training phase caused by sensor characteristic variation incur performance drops of the deep learning-based sensing systems. To address this problem, existing transfer learning techniques require substantial target-domain data and incur high post-deployment overhead. Differently, we propose to exploit the first principle governing the domain shift to reduce the demand for target-domain data. Specifically, our proposed approach called PhyAug uses the first principle fitted with few labeled or unlabeled data pairs collected by the source sensor and the target sensor to transform the existing source-domain training data into the augmented target-domain data for calibrating the deep neural networks. In two audio sensing case studies of keyword spotting and automatic speech recognition, PhyAug recovers the recognition accuracy losses due to microphones’ characteristic variations by 37% to 72% with 5-second unlabeled data collected from the target microphones. In a case study of acoustics-based room recognition, PhyAug recovers the recognition accuracy loss caused by smartphone microphone variation by 33% to 80%. In the last case study of fisheye image recognition, PhyAug reduces the image recognition error due to the camera-induced distortions by 72%. Wenjie Luo 0001, Zhenyu Yan 0002, Qun Song 0001, Rui Tan 0001 |
ACM Trans. Sens. Networks | 3 |
| 2022 | Sardino: Ultra-Fast Dynamic Ensemble for Secure Visual Sensing at Mobile Edge
Qun Song 0001, Zhenyu Yan 0002, Wenjie Luo 0001, Rui Tan 0001 |
EWSN | 1 |
| 2022 | Telesonar: Robocall Alarm System by Detecting Echo Channel and Breath TimingabstractMassive fraudulent and phishing robocalls present threats to societies. The integration of artificial intelligence technologies, including dialogue and voice generation systems, renders the robocalls more deceptive. Existing countermeasures such as caller ID, call provenance, voiceprint, and fake voice detection have respective limitations and are heavyweight for end users' smartphones. This paper studies detecting the acoustic echo channel on the remote end of a call based on the received voice. The positive detection result evidencing the physical setup of an audio system is indicative of a human caller. However, the acoustic echo cancellation mechanisms of most audio systems and the use of earphone/headset diminish echoes significantly. To address these issues, the proposed Telesonar transmits short chirps during the vulnerable time of echo cancellation, detects the tiny echo remnants from the received voice, and passively analyzes the timing of caller's breath sounds to confirm a human caller. Extensive real experiments under a wide range of settings show that Telesonar correctly recognizes human callers with a rate of over 95%, while wrongly recognizing voice robots as human with a rate of 3.8%. Zhenyu Yan 0002, Rui Tan 0001, Qun Song 0001, Xiaoxuan Lu 0001 |
SenSys | 3 |
| 2022 | PriMask: Cascadable and Collusion-Resilient Data Masking for Mobile Cloud InferenceabstractMobile cloud offloading is indispensable for inference tasks based on large-scale deep models. However, transmitting privacy-rich inference data to the cloud incurs concerns. This paper presents the design of a system called PriMask, in which the mobile device uses a secret small-scale neural network called MaskNet to mask the data before transmission. PriMask significantly weakens the cloud's capability to recover the data or extract certain private attributes. The MaskNet is cascadable in that the mobile can opt in to or out of its use seamlessly without any modifications to the cloud's inference service. Moreover, the mobiles use different MaskNets, such that the collusion between the cloud and some mobiles does not weaken the protection for other mobiles. We devise a split adversarial learning method to train a neural network that generates a new MaskNet quickly (within two seconds) at run time. We apply PriMask to three mobile sensing applications with diverse modalities and complexities, i.e., human activity recognition, urban environment crowdsensing, and driver behavior recognition. Results show PriMask's effectiveness in all the three applications. Linshan Jiang, Qun Song 0001, Rui Tan 0001, Mo Li 0001 |
SenSys | 2 |
| 2022 | Indoor Smartphone SLAM with Learned Echoic Location FeaturesabstractIndoor self-localization is a highly demanded system function for smartphones. The current solutions based on inertial, radio frequency, and geomagnetic sensing may have degraded performance when their limiting factors take effect. In this paper, we present a new indoor simultaneous localization and mapping (SLAM) system that utilizes the smartphone's built-in audio hardware and inertial measurement unit (IMU). Our system uses a smartphone's loud-speaker to emit near-inaudible chirps and then the microphone to record the acoustic echoes from the indoor environment. Our profiling measurements show that the echoes carry location information with sub-meter granularity. To enable SLAM, we apply contrastive learning to construct an echoic location feature (ELF) extractor, such that the loop closures on the smartphone's trajectory can be accurately detected from the associated ELF trace. The detection results effectively regulate the IMU-based trajectory reconstruction. Extensive experiments show that our ELF-based SLAM achieves median localization errors of 0.1 m, 0.53 m, and 0.4m on the reconstructed trajectories in a living room, an office, and a shopping mall, and outperforms the Wi-Fi and geomagnetic SLAM systems. Wenjie Luo 0001, Qun Song 0001, Zhenyu Yan 0002, Rui Tan 0001, Guosheng Lin |
SenSys | 2 |
| 2022 | DeepMTD: Moving Target Defense for Deep Visual Sensing against Adversarial ExamplesabstractDeep learning-based visual sensing has achieved attractive accuracy but is shown vulnerable to adversarial attacks. Specifically, once the attackers obtain the deep model, they can construct adversarial examples to mislead the model to yield wrong classification results. Deployable adversarial examples such as small stickers pasted on the road signs and lanes have been shown effective in misleading advanced driver-assistance systems. Most existing countermeasures against adversarial examples build their security on the attackers’ ignorance of the defense mechanisms. Thus, they fall short of following Kerckhoffs’s principle and can be subverted once the attackers know the details of the defense. This article applies the strategy of moving target defense (MTD) to generate multiple new deep models after system deployment that will collaboratively detect and thwart adversarial examples. Our MTD design is based on the adversarial examples’ minor transferability across different models. The post-deployment of dynamically generated models significantly increase the bar of successful attacks. We also apply serial data fusion with early stopping to reduce the inference time by a factor of up to 5, as well as exploit hardware inference accelerators’ characteristics to strike better tradeoffs between inference time and power consumption. Evaluation based on three datasets including a road sign dataset and two GPU-equipped embedded computing boards shows the effectiveness and efficiency of our approach in counteracting the attack. Qun Song 0001, Zhenyu Yan 0002, Rui Tan 0001 |
ACM Trans. Sens. Networks | 1 |
| 2021 | PhyAug: Physics-Directed Data Augmentation for Deep Sensing Model Transfer in Cyber-Physical SystemsabstractRun-time domain shifts from training-phase domains are common in sensing systems designed with deep learning. The shifts can be caused by sensor characteristic variations and/or discrepancies between the design-phase model and the actual model of the sensed physical process. To address these issues, existing transfer learning techniques require substantial target-domain data and thus incur high post-deployment overhead. This paper proposes to exploit the first principle governing the domain shift to reduce the demand on target-domain data. Specifically, our proposed approach called PhyAug uses the first principle fitted with few labeled or unlabeled source/target-domain data pairs to transform the existing source-domain training data into augmented data for updating the deep neural networks. In two case studies of keyword spotting and DeepSpeech2-based automatic speech recognition, with 5-second unlabeled data collected from the target microphones, PhyAug recovers the recognition accuracy losses due to microphone characteristic variations by 37% to 72%. In a case study of seismic source localization with TDoA fingerprints, by exploiting the first principle of signal propagation in uneven media, PhyAug only requires 3% to 8% of labeled TDoA measurements required by the vanilla fingerprinting approach in achieving the same localization accuracy. Wenjie Luo 0001, Zhenyu Yan 0002, Qun Song 0001, Rui Tan 0001 |
IPSN | 3 |
| 2021 | Infrastructure-Free Smartphone Indoor Localization Using Room Acoustic ResponsesabstractSmartphone indoor location awareness is increasingly demanded by a variety of mobile applications. The existing solutions for accurate smartphone indoor localization rely on additional devices or pre-installed infrastructure (e.g., dense WiFi access points, Bluetooth beacons). In this demo, we present EchoLoc, an infrastructure-free smartphone indoor localization system using room acoustic response to a chirp emitted by the phone. EchoLoc consists of a mobile client for echo data collection and a cloud server hosting a deep neural network for location inference. EchoLoc achieves 95% accuracy in recognizing 101 locations in a large public indoor space and a median localization error of 0.5 m in a typical lab area. Demo video is available at https://youtu.be/5si0Cq6LzT4. Dongfang Guo, Wenjie Luo 0001, Chaojie Gu, Qun Song 0001, Zhenyu Yan 0002, Rui Tan 0001 |
SenSys | 5 |
| 2019 | Towards Touch-to-Access Device Authentication Using Induced Body Electric PotentialsabstractThis paper presents TouchAuth, a new touch-to-access device authentication approach using induced body electric potentials (iBEPs) caused by the indoor ambient electric field that is mainly emitted from the building's electrical cabling. The design of TouchAuth is based on the electrostatics of iBEP generation and a resulting property, i.e., the iBEPs at two close locations on the same human body are similar, whereas those from different human bodies are distinct. Extensive experiments verify the above property and show that TouchAuth achieves high-profile receiver operating characteristics in implementing the touch-to-access policy. Our experiments also show that a range of possible interfering sources including appliances' electromagnetic emanations and noise injections into the power network do not affect the performance of TouchAuth. A key advantage of TouchAuth is that the iBEP sensing requires a simple analog-to-digital converter only, which is widely available on microcontrollers. Compared with existing approaches including intra-body communication and physiological sensing, TouchAuth is a low-cost, lightweight, and convenient approach for authorized users to access the smart objects found in indoor environments. Zhenyu Yan 0002, Qun Song 0001, Rui Tan 0001, Yang Li 0147, Adams Wai-Kin Kong |
MobiCom | 2 |
| 2019 | Moving target defense for embedded deep visual sensing against adversarial examplesabstractDeep learning-based visual sensing has achieved attractive accuracy but is shown vulnerable to adversarial example attacks. Specifically, once the attackers obtain the deep model, they can construct adversarial examples to mislead the model to yield wrong classification results. Deployable adversarial examples such as small stickers pasted on the road signs and lanes have been shown effective in misleading advanced driver-assistance systems. Many existing countermeasures against adversarial examples build their security on the attackers' ignorance of the defense mechanisms. Thus, they fall short of following Kerckhoffs's principle and can be subverted once the attackers know the details of the defense. This paper applies the strategy of moving target defense (MTD) to generate multiple new deep models after system deployment, that will collaboratively detect and thwart adversarial examples. Our MTD design is based on the adversarial examples' minor transferability across different models. The post-deployment dynamically generated models significantly increase the bar of successful attacks. We also apply serial data fusion with early stopping to reduce the inference time by a factor of up to 5. Evaluation based on four datasets including a road sign dataset and two GPU-equipped Jetson embedded computing platforms shows the effectiveness of our approach. Qun Song 0001, Zhenyu Yan 0002, Rui Tan 0001 |
SenSys | 1 |