VLDB 2026 Research / reviewers in the wild / expert
Tianya Zhao
dblp:339/6534
· DBLP profile ↗
18ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0002-3808-7549ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 10 first-author · 17 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cross-Domain RF Fingerprinting with FDA-based Representations and Few-Shot Learning
Tianya Zhao, Bolin Xiang, Shiwen Mao, Xuyu Wang |
INFOCOM | 3 |
| 2026 | EMPalm: Exfiltrating Palm Biometric Data via Electromagnetic Side-Channel
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Alexander M. Wyglinski, Xiaoyan Sun 0003 |
SenSys | 2 |
| 2026 | Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF FingerprintingabstractWhile supervised deep neural networks (DNNs) have proven effective for device authentication via radio frequency (RF) fingerprinting, they are hindered by domain shift issues and the scarcity of labeled data. The success of large language models has led to increased interest in self-supervised pre-trained models (PTMs), which offer better generalization and do not require labeled datasets, potentially addressing the issues mentioned above. However, the inherent vulnerabilities of PTMs in RF fingerprinting remain insufficiently explored. In this paper, we unveil the potential threat by thoroughly investigating data-free backdoor attacks on such PTMs for RF fingerprinting, focusing on a practical scenario where attackers lack access to downstream data, label information, and training processes. To realize the backdoor attack, we carefully design a set of triggers and predefined output representations (PORs) for the PTMs. By mapping triggers and PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream RF fingerprinting tasks without requiring prior knowledge. Extensive experiments demonstrate the wide applicability of our proposed backdoor attack to various input domains, protocols, and PTMs. Furthermore, we explore potential detection and defense methods, illustrating the difficulty of fully safeguarding against our proposed data-free backdoor attack. Tianya Zhao, Junqing Zhang, Jun Dai 0001, Xiaoyan Sun 0003, Xuyu Wang |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | MagWatch: Exposing Privacy Risks in Smartwatches Through Electromagnetic Signals
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Xiaoyan Sun 0003 |
ICICS (1) | 2 |
| 2025 | Privacy-Preserving Wi-Fi Data Generation via Differential Privacy in Diffusion Models
Tianya Zhao, Shiwen Mao, Xuyu Wang |
INFOCOM | 2 |
| 2025 | Protocol-Agnostic and Data-Free Backdoor Attacks on Pre-Trained Models in RF Fingerprinting
Tianya Zhao, Junqing Zhang, Xuyu Wang |
INFOCOM | 1 |
| 2025 | RFID-Based Vital Sign Monitoring Under Motion Using Physics-Informed Generative ModelsabstractWireless signals are widely used for human sensing, but they require devices and targets to remain stationary, especially for fine-grained motions like respiration. To enable vital sign monitoring under motion using RFID, we employ dual tags to create a relative coordinate system that reduces motion interference. We also propose physics-informed generative models with frequency domain constraints to improve noise reduction, capturing both time and frequency features. Our method, tested across dynamic scenarios including walking, treadmill exercises, and driving and validated using real patient data, demonstrates superior performance compared to traditional approaches in accurately matching real respiratory signals and exhibits robustness against time shifts. Tianya Zhao, Yuwei Dai, Harrison X. Bai, Karthik Suresh 0006, Zhicheng Jiao, Shiwen Mao, Xuyu Wang |
MASS | 3 |
| 2025 | Data-Free Backdoor Attacks on Self-Supervised Human Activity Recognition ModelsabstractSelf-supervised learning (SSL) has emerged as a powerful deep learning paradigm for human activity recognition (HAR) systems. By leveraging large amounts of unlabeled data, SSL enables the development of pre-trained models (PTMs) that can be efficiently fine-tuned with limited labeled data for downstream HAR tasks, reducing labeling costs while improving generalization. Despite these advantages, the potential vulnerabilities of SSL-based PTMs in IoT sensing systems have not been sufficiently explored. This paper investigates data-free backdoor attacks on these PTMs, focusing on a practical scenario where attackers cannot access downstream task data. To realize these attacks, we design a set of triggers and predefined output representations (PORs). By mapping triggers to PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream sensing tasks without requiring prior knowledge. Extensive experiments show our attack applies broadly across various sensing modalities, data, and PTM architectures. Tianya Zhao, Xuyu Wang |
MASS | 1 |
| 2025 | Membership Inference Against Self-supervised IMU Sensing ApplicationsabstractDeep learning has revolutionized the use of inertial measurement unit (IMU) sensors in mobile applications, such as human activity recognition. Building on the success of pre-trained models across various domains, recent studies have increasingly adopted self-supervised learning (SSL) for a range of sensing tasks. While these SSL approaches improve generalization and reduce labeling requirements, their privacy implications have received limited attention. This paper addresses this gap by examining IMU data privacy during pre-training through membership inference. Our work serves two important purposes: First, it enables data owners to verify if their data was used without permission in encoder pre-training. Second, it demonstrates how adversaries might compromise sensitive human sensing data used in pre-training. To enhance the practicality of membership inference on unlabeled IMU sensing data across different SSL algorithms, we introduce an activity labeling module and a novel perturbation strategy to exploit encoder overfitting characteristics on training data. When an encoder over-fits, it memorizes training data rather than learning generalizable patterns. Therefore, when comparing the original data to the perturbed version, the encoder generates more distinct feature vectors for samples from its training set than for samples it has never seen before. We evaluate our membership inference methods on two mainstream SSL methods across multiple datasets, demonstrating that our method can achieve relatively high precision and recall at low false positive rates. Tianya Zhao, Xuyu Wang |
SenSys | 1 |
| 2025 | Explanation-Guided Backdoor Attacks Against Model-Agnostic RF Fingerprinting SystemsabstractDespite the proven capabilities of deep neural networks (DNNs) in identifying devices through radio frequency (RF) fingerprinting, the security vulnerabilities of these deep learning models have been largely overlooked. While the threat of backdoor attacks is well-studied in the image domain, few works have explored this threat in the context of RF signals. In this paper, we thoroughly analyze the susceptibility of DNN-based RF fingerprinting to backdoor attacks, focusing on a more practical scenario where attackers lack access to control model gradients and training processes. We propose leveraging explainable machine learning techniques and autoencoders to guide the selection of trigger positions and values, allowing for the creation of effective backdoor triggers in a model-agnostic manner. To comprehensively evaluate this backdoor attack, we employ four diverse datasets with two protocols (Wi-Fi and LoRa) across various DNN architectures. Given that RF signals are often transformed into the frequency or time-frequency domains, this study also assesses attack efficacy in the time-frequency domain. Furthermore, we experiment with potential detection and defense methods, demonstrating the difficulty of fully safeguarding against our proposed backdoor attack. Additionally, we consider the attack performance in the domain shift case. Tianya Zhao, Junqing Zhang, Shiwen Mao, Xuyu Wang |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Functional Data Analysis Assisted Cross-Domain Wi-Fi Sensing Using Few-Shot LearningabstractRecent years have witnessed rapid development of Wi-Fi sensing applications. However, the domain shift problem is still an open problem. Variations in environment, time, and detected objects can undermine the effectiveness of cross-domain sensing. This paper proposes a few-shot learning framework for Wi-Fi sensing that enables generalization to unseen domains given only a few samples. To better extract stable features, functional data analysis (FDA) is first employed as a preprocessing technique. We thoroughly evaluate our approach to different Wi-Fi sensing tasks: gesture recognition, and activity recognition. Our experimental results demonstrate that FDA assisted system improves cross-domain accuracy by 14%, 10%, and 8% on the respective tasks with five samples per class. Tianya Zhao, Guanqun Cao, Shiwen Mao, Xuyu Wang |
ICC | 1 |
| 2024 | ECG-grained Cardiac Monitoring Using RFIDabstractHeartbeat signals are useful to disease prediction, sub-health diagnosis, fatigue warning, and even emotion estimation. There is a compelling need for contactless, easy-to-deploy, and long-term heartbeat monitoring. This paper presents a contactless Radio Frequency Identification (RFID) based system for heartbeat monitoring that leverages the insight that RFID signal fluctuations induced by chest motion are synchronous with both respiration and heartbeat. The proposed system collects the temporal phase information from the tag pair on the body to extract heartbeat signals using a sequence of signal processing techniques. We propose a signal separation method based on empirical mode decomposition (EMD) to obtain heart rate after preprocessing. Furthermore, the estimated signal is input to an enhanced variational autoencoder (VAE) model to recover the heartbeat waveform. Implemented with commercial off-the-shelf (COTS) RFID devices, the system achieves accurate heart rate monitoring with less than 3% relative errors. The detected waveform exhibits a median cosine similarity of 0.83 as compared with the ground truth, which validate the system’s wide applicability and high reliability for fine-grained, contactless heartbeat monitoring. Tianya Zhao, Shiwen Mao, Harrison X. Bai, Zhicheng Jiao, Xuyu Wang |
ICCCN | 2 |
| 2024 | Cross-domain, Scalable, and Interpretable RF Device FingerprintingabstractIn this paper, we propose a cross-domain, scalable, and interpretable radio frequency (RF) fingerprinting system using a modified prototypical network (PTN) and an explanation-guided data augmentation across various domains and datasets with only a few samples. Specifically, a convolutional neural network is employed as the feature extractor of the PTN to extract RF fingerprint features. The predictions are made by comparing the similarity between prototypes and feature embedding vectors. To further improve the system performance, we design a customized loss function and deploy an eXplainable Artificial Intelligence (XAI) method to guide data augmentation during fine-tuning. To evaluate the effectiveness of our system in addressing domain shift and scalability problems, we conducted extensive experiments in both cross-domain and novel-device scenarios. Our study shows that our approach achieves exceptional performance in the cross-domain case, exhibiting an accuracy improvement of approximately 80% compared to convolutional neural networks in the best case. Furthermore, our approach demonstrates promising results in the novel-device case across different datasets. Our customized loss function and XAI-guided data augmentation can further improve authentication accuracy to a certain degree. Tianya Zhao, Xuyu Wang, Shiwen Mao |
INFOCOM | 1 |
| 2024 | Explanation-Guided Backdoor Attacks on Model-Agnostic RF FingerprintingabstractDespite the proven capabilities of deep neural networks (DNNs) for radio frequency (RF) fingerprinting, their security vulnerabilities have been largely overlooked. Unlike the extensively studied image domain, few works have explored the threat of backdoor attacks on RF signals. In this paper, we analyze the susceptibility of DNN-based RF fingerprinting to backdoor attacks, focusing on a more practical scenario where attackers lack access to control model gradients and training processes. We propose leveraging explainable machine learning techniques and autoencoders to guide the selection of positions and values, enabling the creation of effective backdoor triggers in a model-agnostic manner. To comprehensively evaluate our backdoor attack, we employ four diverse datasets with two protocols (Wi-Fi and LoRa) across various DNN architectures. Given that RF signals are often transformed into the frequency or time-frequency domains, this study also assesses attack efficacy in the time-frequency domain. Furthermore, we experiment with potential defenses, demonstrating the difficulty of fully safeguarding against our attacks. Tianya Zhao, Xuyu Wang, Junqing Zhang, Shiwen Mao |
INFOCOM | 1 |
| 2024 | Few-shot Learning and Data Augmentation for Cross-Domain UAV FingerprintingabstractIn this paper, we propose a novel approach to cross-domain unmanned aerial vehicle (UAV) authentication using radio frequency (RF) fingerprinting based on prototypical networks (PTNs). UAVs present a unique challenge for RF fingerprinting due to their hovering motion, which creates more diverse signal domains compared to other RF devices like Wi-Fi. This results in a severe domain shift problem, where well-trained models struggle to generalize to unseen domains. To address this issue without incurring significant costs in data collection and model retraining, we employ PTNs, a few-shot learning paradigm that enhances cross-domain performance and system viability. We further improve our method's effectiveness by incorporating fine-tuning with data augmentation, maintaining system viability while improving performance. Comprehensive experimental results demonstrate that our approach significantly mitigates domain shift, achieving up to a 20% improvement in cross-domain accuracy for UAV fingerprinting. Tianya Zhao, Shiwen Mao, Xuyu Wang |
MobiCom | 1 |
| 2024 | TFSemantic: A Time-Frequency Semantic GAN Framework for Imbalanced Classification Using Radio SignalsabstractRecently, wireless sensing techniques have been widely used for Internet of Things (IoT) applications. Unlike traditional device-based sensing, wireless sensing is contactless, pervasive, low cost, and non-invasive, making it highly suitable for relevant IoT applications. However, most existing methods are highly dependent on high-quality datasets, and the minority class will not achieve a satisfactory performance when suffering from a class imbalance problem. In this article, we propose a time–frequency semantic generative adversarial network framework (i.e., TFSemantic) to address the imbalanced classification problem in human activity recognition using radio frequency (RF) signals. Specifically, the TFSemantic framework can learn semantic features from the minority classes and then generate high-quality signals to restore data balance. It includes a data pre-processing module, a semantic extraction module, a semantic distribution module, and a data augmenter module. In the data pre-processing module, we process four different RF datasets (i.e., WiFi, RFID, UWB, and mmWave). We also develop Fourier semantic feature convolution and attention semantic feature embedding methods for the semantic extraction module. A discrete wavelet transform is utilized for reconstructed RF samples in the semantic distribution module. In data augmenter module, we design an associated loss function to achieve effective adversarial training. Finally, we validate the effectiveness of the proposed TFSemantic framework using different RF datasets, which outperforms several state-of-the-art methods. Peng Liao 0001, Xuyu Wang, Lingling An, Shiwen Mao, Tianya Zhao, Chao Yang 0025 |
ACM Trans. Sens. Networks | 5 |
| 2023 | Backdoor Attacks Against Deep Learning-Based Massive MIMO LocalizationabstractMillimeter wave (mmWave) communications and massive MIMO play crucial roles in the development of future wireless systems. In addition to offering high data rates, these technologies enable the realization of high-precision localization systems, especially in complicated indoor rich multi-path environments without GPS coverage. While deep neural networks (DNNs) enable high accuracy in fingerprint-based indoor localization, their implementations also introduce security problems. In the field of computer vision, backdoor attacks have proven to be able to effectively deceive models using specific or imperceptible triggers. In this paper, we study the impact of backdoor attacks on 5G massive MIMO localization systems in both indoor and outdoor environments. Two different triggers are investigated: the one-pixel trigger (visible) and the random noise trigger (invisible). We evaluate the localization systems using a public dataset and demonstrate that DNN-based localization systems are vulnerable to backdoor attacks. Tianya Zhao, Xuyu Wang, Shiwen Mao |
GLOBECOM | 1 |
| 2022 | Cross-Domain Adaptation for RF Fingerprinting Using Prototypical NetworksabstractRadio frequency (RF) fingerprinting is a hardware feature used in Internet of Things (IoT) applications to identify wireless devices. In this paper, we propose few-shot learning (FSL) and prototypical networks (PTNs) to create a new model that can adapt to a new domain with very few labeled examples. The proposed model can mitigate the domain shift caused by changing RF environments. Experimental results show the proposed method can improve the performance of RF fingerprinting over different domains. Steven Mackey, Tianya Zhao, Xuyu Wang, Shiwen Mao |
SenSys | 2 |