Leming Shen

dblp:303/7402 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0001-7661-6432ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 6 first-author · 16 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Jailbreaking Embodied LLMs via Action-Level Manipulation
Qiang Yang 0018, Leming Shen, Zijing Ma, Yuanqing Zheng
SenSys3
2026 RANPilot: Making AI Functionalities Robust to Dynamic O-RAN Reconfigurations
abstract
The Open Radio Access Network (O-RAN) promises unprecedented flexibility through its reconfigurable architecture and AI-driven control. However, this agility exposes a critical fragility: AI models trained on one network configuration suffer significant performance degradation after an upgrade due to dramatic data drift. The standard solution, reactive retraining, is unacceptably slow, leaving the network in a suboptimal state for tens of minutes and undermining the core benefits of O-RAN's dynamism. This paper introduces RANPilot, the first framework to address this challenge through proactive AI adaptation. RANPilot constructs a lightweight "virtual O-RAN" (a trace-driven emulator) to synthesize high-fidelity training data representing the post-reconfiguration state before the physical change occurs, allowing AI models to be adapted in advance. Extensive experiments on a real-world 5G testbed demonstrate that RANPilot achieves near interruption-free AI services upon reconfiguration, reducing AI downtime by 85% to 94% against reactive baselines. By shifting the AI evolution paradigm from reactive redevelopment to proactive preparation, RANPilot explores a digital-leadoff approach to enable robust AI in reconfigurable O-RAN deployments.
Shiming Yu, Leming Shen, Xianjin Xia, Yuanqing Zheng, Yaxiong Xie
SIGCOMM2
2026 Toward Privacy-Preserving and Personalized Smart Homes via Tailored Small Language Models
abstract
Large Language Models (LLMs) have showcased remarkable generalizability in language comprehension and hold significant potential to revolutionize human-computer interaction in smart homes. Existing LLM-based smart home assistants typically transmit user commands, along with user profiles and home configurations, to remote servers to obtain personalized services. However, users are increasingly concerned about the potential privacy leaks to the remote servers. To address this issue, we developHomeLLaMA, an on-device assistant for privacy-preserving and personalized smart home serving with a tailored small language model (SLM).HomeLLaMAlearns from cloud LLMs to deliver satisfactory responses and enable user-friendly interactions. Once deployed,HomeLLaMAfacilitates proactive interactions by continuously updating local SLMs and user profiles. To further enhance user interaction while protecting their privacy, we developPrivShieldto offer an optional, privacy-preserving LLM-based smart home service for users who are unsatisfied with local responses and are willing to send less-sensitive queries to remote servers. For evaluation, we develop a comprehensive benchmark,DevFinder, to assess service quality. Extensive experiments and user studies ($M=100$) demonstrate thatHomeLLaMAcan provide personalized services while significantly enhancing user privacy.
Leming Shen, Zijing Ma, Yuanqing Zheng
IEEE Trans. Mob. Comput.2
2025 Poster: LLMalware: An LLM-Powered Robust and Efficient Android Malware Detection Framework
abstract
Android malware pose severe threats to the mobile application ecosystem. Although well-trained malware detection models can initially achieve satisfactory performance, they struggle with unseen Android apps constantly emerging over time, which is known as the concept drift problem. Previous methods frequently collect and label new apps to update the aging models. This process, however, necessitates domain knowledge and incurs prohibitive retraining overhead. To address this problem, this paper presents LLMalware, which integrates three novel technical components. First, we propose full-spectrum automated feature extraction, which automatically extracts diverse malware features from various detection models. Next, we develop cohesive feature fusion, which combines these features to build effective representations for robust malware detection. Lastly, we devise agile knowledge update to enable efficient online malware detection via an LLM-based automated agent and a dynamically maintained malware knowledge base. Extensive experiments demonstrate LLMalware can mitigate concept drift with an average improvement of approximately 10% in F1-score over state-of-the-art baselines.
Zijing Ma, Leming Shen, Yuanqing Zheng
CCS2
2025 Poster: Towards Privacy-Preserving and Personalized Smart Homes via Tailored Small Language Models
abstract
Large Language Models (LLMs) exhibit remarkable language comprehension to revolutionize smart homes. Existing LLM-based smart home assistants typically transmit user commands, along with user profiles and home configurations, to remote servers to obtain personalized services. However, users are increasingly concerned about potential privacy leakage. To address this, we develop HomeLLaMA, an on-device assistant for privacy-preserving personalized smart homes with a tailored small language model (SLM). HomeLLaMA learns from cloud LLMs to deliver satisfactory responses and enable user-friendly interactions. Once deployed, HomeLLaMA facilitates proactive interactions by continuously updating local SLMs and user profiles. To further enhance user interaction while protecting privacy, we develop PrivShield to offer an optional privacy-preserving serving for those users who are unsatisfied with local responses and willing to send less-sensitive queries to remote servers. Experiments demonstrate HomeLLaMA provides satisfactory services while significantly enhancing user privacy.
Leming Shen, Zijing Ma, Yuanqing Zheng
MobiCom2
2025 AutoIOT: LLM-Driven Automated Natural Language Programming for AIoT Applications
abstract
The advent of Large Language Models (LLMs) has profoundly transformed our lives, revolutionizing interactions with AI and lowering the barrier to AI usage. While LLMs are primarily designed for natural language interaction, the extensive embedded knowledge empowers them to comprehend digital sensor data. This capability enables LLMs to engage with the physical world through IoT sensors and actuators, performing a myriad of AIoT tasks. Consequently, this evolution triggers a paradigm shift in conventional AIoT application development, democratizing its accessibility to all by facilitating the design and development of AIoT applications via natural language. However, some limitations need to be addressed to unlock the full potential of LLMs in AIoT application development. First, existing solutions often require transferring raw sensor data to LLM servers, which raises privacy concerns, incurs high query fees, and is limited by token size. Moreover, the reasoning processes of LLMs are opaque to users, making it difficult to verify the robustness and correctness of inference results. This paper introduces AutoIOT, an LLM-based automated program generator for AIoT applications. AutoIOT enables users to specify their requirements using natural language (input) and automatically synthesizes interpretable programs with documentation (output). AutoIOT automates the iterative optimization to enhance the quality of generated code with minimum user involvement. AutoIOT not only makes the execution of AIoT tasks more explainable but also mitigates privacy concerns and reduces token costs with local execution of synthesized programs. Extensive experiments and user studies demonstrate AutoIOT's remarkable capability in program synthesis for various AIoT tasks. The synthesized programs can match and even outperform some representative baselines.
Leming Shen, Qiang Yang 0018, Yuanqing Zheng, Mo Li 0001
MobiCom1
2025 Poster: Towards Federated Embodied AI with FEAI
abstract
Embodied AI (EAI) transforms our daily lives by bridging intelligent agents with various sensors and actuators. Large Language Models (LLMs) further enhance EAI agents in environment comprehension, task decomposition, and action execution for robotic manipulation. However, developing a general EAI agent capable of adapting to and continuously learning from diverse operating environments is extremely challenging: 1) Robots with mobility capture environments from multiple perspectives, leading to heterogeneous semantic interpretations, particularly in large or open settings. 2) Heterogeneous environments further exacerbate the variability of decomposed tasks and corresponding actions required for robotic manipulation. To address these challenges, we propose FEAI, a novel paradigm to enhance the adaptability and self-learning capabilities of EAI agents in heterogeneous environments via federated embodied learning. Specifically, FEAI shares and constructively aggregates environment semantic maps, decomposed task templates, and action-reward rules from federated EAI agents. The aggregated information can further enhance EAI agents' local models through continuous tuning or dynamically updated knowledge databases. We believe that FEAI has significant potential to integrate more advanced technologies, further advancing performance and innovation in the field of EAI.
Leming Shen, Yuanqing Zheng
MobiSys1
2025 GPIoT: Tailoring Small Language Models for IoT Program Synthesis and Development
abstract
Code Large Language Models (LLMs) enhance software development efficiency by automatically generating code and documentation based on user requirements. However, code LLMs cannot synthesize specialized programs when tasked with IoT applications that require domain knowledge. While Retrieval-Augmented Generation (RAG) offers a promising solution by fetching relevant domain knowledge, it necessitates powerful cloud LLMs (e.g., GPT-4) to process user requirements and retrieved contents, which raises significant privacy concerns. This approach also suffers from unstable networks and prohibitive LLM query costs. Moreover, it is challenging to ensure the correctness and relevance of the fetched contents. To address these issues, we propose GPIoT, a code generation system for IoT applications by fine-tuning locally deployable Small Language Models (SLMs) on IoT-specialized datasets. SLMs have smaller model sizes, allowing efficient local deployment and execution to mitigate privacy concerns and network uncertainty. Furthermore, by fine-tuning SLMs with our IoT-specialized datasets, the SLMs' ability to synthesize IoT-related programs can be substantially improved. To evaluate GPIoT's capability in synthesizing programs for IoT applications, we develop a benchmark, IoTBench. Extensive experiments and user trials demonstrate the effectiveness of GPIoT in generating IoT-specialized code, outperforming state-of-the-art code LLMs with an average task accuracy increment of 64.7% and significant improvements in user satisfaction.
Leming Shen, Qiang Yang 0018, Zijing Ma, Yuanqing Zheng
SenSys1
2025 Hierarchical and Heterogeneous Federated Learning via a Learning-on-Model Paradigm
abstract
Federated Learning (FL) collaboratively trains a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., smartphones and wearables) typically have disparate system resources. Traditional FL, however, adopts a one-size-fits-all solution, where a homogeneous large model is sent to and trained on each client. This method results in an overwhelming workload for less capable clients and starvation for others. To tackle this, we proposeFedConv, a client-friendly FL framework, minimizing the system overhead on resource-constrained clients by providing heterogeneous customized sub-models.FedConvfeatures a novellearning-on-modelparadigm that learns the parameters of heterogeneous sub-models viaconvolutional compression. To aggregate heterogeneous sub-models, we proposetransposed convolutional dilationto convert them back to large models with a unified size while retaining personalized information. The compression and dilation processes, transparent to clients, are tuned on the server using a small public dataset. We further propose ahierarchical and clustering-based local trainingstrategy for enhanced performance. Extensive experiments on six datasets show thatFedConvoutperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively).
Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han
IEEE Trans. Mob. Comput.1
2024 Talk2Radar: Talking to mmWave Radars via Smartphone Speaker
abstract
Integrated Sensing and Communication (ISAC) is gaining a tremendous amount of attention from both academia and industry. Recent work has brought communication capability to sensing-oriented mmWave radars, enabling more innovative applications. These solutions, however, either require hardware modifications or suffer from limited data rates. This paper presents Talk2Radar, which builds a faster communication channel between smartphone speakers and mmWave radars, without any hardware modification to either commodity smartphones or off-the-shelf radars. In Talk2Radar, a smartphone speaker sends messages by playing carefully designed sounds. A mmWave radar acting as a data receiver captures the emitted sounds by detecting the sound-induced smartphone vibrations, and then decodes the messages. Talk2Radar characterizes smartphone speakers for speaker-to-mmWave radar communication and addresses a series of technical challenges, including modulation and demodulation of extremely weak sound-induced vibrations, multi-speaker concurrent communication and human motion suppression. We implement and evaluate Talk2Radar in various practical settings. Experimental results show that Talk2Radar can achieve a data rate of up to 400bps with an average BER of less than 5%, outperforming the state-of-the-art by approximately 33×.
Kaiyan Cui, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han
INFOCOM2
2024 IoTCoder: A Copilot for IoT Application Development
abstract
Existing code Large Language Models are primarily designed for generating simple and general algorithms but are not dedicated to IoT applications. To fill this gap, we present IoTCoder, a coding copilot specifically designed to synthesize programs for IoT application development. IoTCoder features three locally deployed small language models (SLMs): a Task Decomposition SLM that decomposes a complex IoT application into multiple tasks with detailed descriptions, a Requirement Transformation SLM that converts the decomposed tasks described in natural language to well-structured specifications, and a Modularized Code Generation SLM that generates modularized code based on the task specifications. Experiment results show that IoTCoder can synthesize programs adopting more IoT-specific algorithms and outperform state-of-the-art code LLMs in terms of both task accuracy (by more than 24.2% on average) and memory usage (by less than 358.4 MB on average).
Leming Shen, Yuanqing Zheng
MobiCom1
2024 FedConv: A Learning-on-Model Paradigm for Heterogeneous Federated Clients
abstract
Federated Learning (FL) facilitates collaborative training of a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., edge servers, smartphones, and wearables) typically have disparate system resources. Conventional FL, however, adopts a one-size-fits-all solution, where a homogeneous large global model is transmitted to and trained on each client, resulting in an overwhelming workload for less capable clients and starvation for other clients. To address this issue, we propose FedConv, a client-friendly FL framework, which minimizes the computation and memory burden on resource-constrained clients by providing heterogeneous customized sub-models. FedConv features a novel learning-on-model paradigm that learns the parameters of the heterogeneous sub-models via convolutional compression. Unlike traditional compression methods, the compressed models in FedConv can be directly trained on clients without decompression. To aggregate the heterogeneous sub-models, we propose transposed convolutional dilation to convert them back to large models with a unified size while retaining personalized information from clients. The compression and dilation processes, transparent to clients, are optimized on the server leveraging a small public dataset. Extensive experiments on six datasets demonstrate that FedConv outperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively).
Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han
MobiSys1
2024 Towards ISAC-Empowered mmWave Radars by Capturing Modulated Vibrations
abstract
Integrated Sensing and Communication (ISAC) has emerged as a promising technology for next-generation mobile networks. Towards ISAC, we developmmRipplethat empowers commodity mmWave radars with communication capabilities through smartphone vibrations. InmmRipple, a smartphone (transmitter) sends messages by modulating smartphone vibrations, while a mmWave radar (receiver) receives the messages by detecting and decoding the smartphone vibrations. By doing so, a smartphone user can not only be passively sensed by a mmWave radar, but also actively send messages to the radar without any hardware modifications. Although promising, the data rate ofmmRippleis limited by Morse-style communication. To address this, we presentmmRipple+, which leverages the Pulse Width and Amplitude Modulation (PWAM) technique and suppresses inter-symbol interference to enable faster communication. We prototypemmRippleandmmRipple+on commodity mmWave radars and different types of smartphones. Experimental results show thatmmRippleachieves an average vibration pattern recognition accuracy of 98.60% within a$ 2$m communication range, and 97.74% within$ 3$m. The maximum communication range extends to$ 5$m. Meanwhile,mmRipple+achieves a bit rate of 100 bps with a BER of less than 3%, improving the data rate by 4× overmmRippewith the same symbol duration. This work pioneers smartphone-to-COTS mmWave radar communication via vibrations, unlocking diverse applications.
Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.3
2024 Exploring Practical Acoustic Transduction Attacks on Inertial Sensors in MDOF Systems
abstract
In cyber-physical systems, inertial sensors are the basis for identifying motion states and making actuation decisions. However, extensive studies have proved the vulnerability of those sensors under acoustic transduction attacks, which leverage malicious acoustics to trigger sensor measurement errors. Unfortunately, the threat from such attacks is not assessed properly because of the incomplete investigation on the attack's potential, especially towards multiple-degree-of-freedom systems, e.g., drones. To thoroughly explore the threat of acoustic transduction attacks, we revisit the attack model and design a new yet practical acoustic modulation-based attack, named KITE. Such an attack enables stable and controllable injections, even under frequency offset based distortions that limit the effect of prior attacking approaches. KITE exploits the potential threat of transduction attacks without the need of strengthening attackers' abilities. Furthermore, we extend the attack surface to multiple-degree-of-freedom (MDOF) systems, which are more widely deployed but ignored by prior work. Our study also covers the scenario of attacking moving targets. By revealing the practical threat from acoustic transduction attacks, we appeal for both the attention to their harm and necessary countermeasures.
Ming Gao 0023, Lingfeng Zhang 0004, Leming Shen, Jinsong Han, Feng Lin 0004, Kui Ren 0001
IEEE Trans. Mob. Comput.3
2023 FedDM: Data and Model Heterogeneity-Aware Federated Learning via Dynamic Weight Sharing
abstract
Federated Learning (FL) plays an indispensable role in edge computing systems. Prevalent FL methods mainly address challenges involved in heterogeneous data distribution across devices. Model heterogeneity, however, has seldom been put under scrutiny. In practice, different devices (e.g., PCs and smartphones) generally have disparate computation and communication resources, necessitating neural network models with varying parameter sizes. Therefore, we propose FedDM, a novel data and model heterogeneity-aware FL system, which improves the FL system's accuracy while reducing edge devices' computation and communication costs for heterogeneous model training. FedDM features: 1) dynamic weight sharing scheme that handles model heterogeneity by dynamically selecting parts of the large model to share with smaller ones; 2) tree-structured layer-wise client cooperation scheme that handles data heterogeneity by allowing clients with similar data distribution to share some network layers. We implement FedDM and evaluate it using five public datasets with different tasks.
Leming Shen, Yuanqing Zheng
ICDCS1
2023 Secure User Verification and Continuous Authentication via Earphone IMU
abstract
Biometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods or inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namelyMandiPass.MandiPassleverages inertial measurement units, which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. It provides not only one-time verification function but also continuous authentication function. Both the two functions are secure and user-friendly. We theoretically validate the feasibility ofMandiPassand develop a series of deep learning techniques for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show thatMandiPasscan achieve low equal error rate, even under various harsh environments.
Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001
IEEE Trans. Mob. Comput.3
2022 Integrated Sensing and Communication between Daily Devices and mmWave Radars
abstract
Millimeter wave (mmWave) radar has demonstrated excellent performance in object tracking and micro-displacement detection. Besides the powerful sensing function, this work brings the communication function, allowing daily devices to communicate with mmWave radars through vibrations. In this work, we present VibBeat, in which a daily device (e.g., smartphone and smartwatch) sends messages by modulating vibrations, while a mmWave radar receives the messages by detecting and decoding the vibrations with reflected mmWave signals. By doing so, the device (user) can not only be passively sensed by a mmWave radar, but also actively send messages to the radar for a personalized response. We implement our system using a COTS mmWave radar and smartphones without any hardware modification. Experimental results show that VibBeat supports multiple object communication and achieves a communication range of up to 5m.
Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Jinsong Han
SenSys3
2022 KITE: Exploring the Practical Threat from Acoustic Transduction Attacks on Inertial Sensors
abstract
In cyber-physical systems, inertial sensors are the basis for identifying motion states and making actuation decisions. However, extensive studies have proved the vulnerability of those sensors under acoustic transduction attacks, which leverage malicious acoustics to trigger sensor measurement errors. Unfortunately, the threat from such attacks is not assessed properly because of the incomplete investigation on the attack's potential, especially towards multiple-degree-of-freedom systems, e.g., drones. To thoroughly explore the threat of acoustic transduction attacks, we revisit the attack model and design a new yet practical acoustic modulation-based attack, named KITE. Such an attack enables stable and controllable injections, even under frequency offset based distortions that limit the effect of prior attacking approaches. KITE exploits the potential threat of transduction attacks without the need of strengthening attackers' abilities. Furthermore, we extend the attack surface to multiple-degree-of-freedom systems, which are more widely deployed but ignored by prior work. Our study also covers the scenario of attacking moving targets. By revealing the practical threat from acoustic transduction attacks, we appeal for both the attention to their harm and necessary countermeasures.
Ming Gao 0023, Lingfeng Zhang 0004, Leming Shen, Jinsong Han, Feng Lin 0004, Kui Ren 0001
SenSys3
2021 MandiPass: Secure and Usable User Authentication via Earphone IMU
abstract
Biometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods and inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namely MandiPass. MandiPass leverages inertial measurement units (IMU), which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. The authentication merely requires user to voice a short ‘EMM’ for generating the vibration. In this way, MandiPass enables a secure and user-friendly biometric-based authentication. We theoretically validate the feasibility of MandiPass and develop a two-branch deep neural network for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show that MandiPass can achieve an equal error rate of 1.28%, even under various harsh environments.
Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001
ICDCS3