VLDB 2026 Research / reviewers in the wild / expert
Yimin Chen 0004
dblp:38/1020-4
· DBLP profile ↗
33ranked-venue papers
4as first author
22since 2021 · last 2026
0000-0002-7452-2165ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 3 first-author · 5 since 2021Security and privacy · 12 · 1 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EarlyShield: Early-Stage Screening for Robust Personalized Federated Learning
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
PAKDD (2) | 7 |
| 2025 | BoBa: Boosting Backdoor Detection Through Data Distribution Inference in Federated LearningabstractFederated learning, while being a promising approach for collaborative model training, is susceptible to backdoor attacks due to its decentralized nature. Backdoor attacks have shown remarkable stealthiness, as they compromise model predictions only when inputs contain specific triggers. As a countermeasure, anomaly detection is widely used to filter out backdoor attacks in FL. However, the non-independent and identically distributed (non-IID) data distribution nature of FL clients presents substantial challenges in backdoor attack detection, as the data variety introduces variance among benign models, making them indistinguishable from malicious ones. In this work, we propose a novel distribution-aware backdoor detection mechanism, BoBa, to address this problem. To differentiate outliers arising from data variety versus backdoor attacks, we propose to break down the problem into two steps: clustering clients utilizing their data distribution, and followed by a voting-based detection. We propose a novel data distribution inference mechanism for accurate data distribution estimation. To improve detection robustness, we introduce an overlapping clustering method, where each client is associated with multiple clusters, ensuring that the trustworthiness of a model update is assessed collectively by multiple clusters rather than a single cluster. Through extensive evaluations, we demonstrate that BoBa can reduce the attack success rate to lower than 0.001 while maintaining high main task accuracy across various attack strategies and experimental settings. Zhengyuan Jiang, Xingyu Lyu, Shanghao Shi, Yang Xiao 0010, Yimin Chen 0004, Y. Thomas Hou 0001, Wenjing Lou, Ning Wang 0022 |
ECAI | 5 |
| 2025 | Too Clever by Half: Detecting Sampling-based Model Stealing Attacks by Their Own ClevernessabstractMachine learning as a service (MLaaS) has gained significant popularity and market traction in recent years, driven by advancements in Artificial Intelligence particularly Generative AI (GAI). However, MLaaS faces severe challenges from sampling-based model stealing attacks (MSAs), where attackers strategically query the targeted ML models provided by MLaaS providers to minimize the query burden while closely replicating the model’s functionality. Such MSAs pose severe consequences, including intellectual property (IP) theft and potential leakage of private training data. Unfortunately, existing defenses either sacrifice model utility or fail to generalize across diverse MSAs.In this paper, we propose DIARY, an innovative detection method specifically tailored to sampling-based MSAs by exploiting their inherent sophistication. Our key insight is that ‘clever’ malicious queries tend to extract more information from the targeted (victim) model than typical benign queries, as these attacks iteratively refine their queries by examining and analyzing prior queries and the corresponding responses. Hence we design DIARY to extract timing dependence within a query sequence and incorporate contrastive learning for properly characterizing such dependency that holds for different sampling-based MSAs. Comprehensive evaluations using five different sampling-based MSAs and two state-of-the-art defense baselines across four popular datasets consistently validate DIARY’s superior performance. Xin Yao 0002, Yimin Chen 0004, Kecheng Huang, Ming Zhao 0007 |
ICDCS | 3 |
| 2025 | Physical Backdoor Attacks against mmWave-based Human Activity RecognitionabstractHuman Activity Recognition (HAR) using wireless signals like mmWave technology has promising applications in numerous scenarios, including monitoring and surveillance, healthcare, and smart home. Wireless HAR is non-intrusive and can operate in situations where traditional sensors or cameras may fail. However, these systems also introduce new attack surfaces alongside their benefits. Existing security research on wireless HAR primarily focuses on the vulnerabilities of the AI models used by these systems, without addressing the challenges of physically implementing these attacks in real-world scenarios. In this paper, we present the first physical backdoor attack for mmWave-based HAR systems, manipulating physical signals to deceive the systems into producing targeted outputs. Utilizing passive metal reflectors and optimized attacking strategies, our attack is efficient, stealthy, and easy to implement. Tailored experiments on a mmWave HAR prototype demonstrate the high effectiveness of the proposed attack. Ziqian Bi, Amit Singha, Hongfei Xue, Tao Li 0042, Yimin Chen 0004 |
ICDCS | 5 |
| 2025 | ToxicTextCLIP: Text-Based Poisoning and Backdoor Attacks on CLIP Pre-trainingabstractThe Contrastive Language-Image Pretraining (CLIP) model has significantly advanced vision-language modeling by aligning image-text pairs from large-scale web data through self-supervised contrastive learning. Yet, its reliance on uncurated Internet-sourced data exposes it to data poisoning and backdoor risks. While existing studies primarily investigate image-based attacks, the text modality, which is equally central to CLIP's training, remains underexplored. In this work, we introduce ToxicTextCLIP, a framework for generating high-quality adversarial texts that target CLIP during the pre-training phase. The framework addresses two key challenges: semantic misalignment caused by background inconsistency with the target class, and the scarcity of background-consistent texts. To this end, ToxicTextCLIP iteratively applies: 1) a background-aware selector that prioritizes texts with background content aligned to the target class, and 2) a background-driven augmenter that generates semantically coherent and diverse poisoned samples. Extensive experiments on classification and retrieval tasks show that ToxicTextCLIP achieves up to 95.83\% poisoning success and 98.68% backdoor Hit@1, while bypassing RoCLIP, CleanCLIP and SafeCLIP defenses. The source code can be accessed via https://github.com/xinyaocse/ToxicTextCLIP/. Xin Yao 0002, Yimin Chen 0004, Kecheng Huang, Ming Zhao 0007 |
NeurIPS | 3 |
| 2025 | Beyond Uniformity: Robust Backdoor Attacks on Deep Neural Networks with Trigger Selection
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
PAKDD (6) | 6 |
| 2025 | Buffer is All You Need: Defending Federated Learning against Backdoor Attacks under Non-iids via BufferingabstractFederated Learning (FL) is a popular paradigm enabling clients to jointly train a global model without sharing raw data. However, FL is known to be vulnerable towards backdoor attacks due to its distributed nature. As participants, attackers can upload model updates that effectively compromise FL. More critically, existing defenses are mostly designed under independent-and-identically-distributed (iid) settings, hence neglecting the fundamental non-iid characteristic of FL. Here we propose FLBuff for tackling backdoor attacks even under non-iids. The main challenge for such defenses is that non-iids shorten the distance between benign and malicious updates, rendering them harder to separate. FLBuff is inspired by our insight that non-iids can be modeled as omni-directional expansion in representation space while backdoor attacks as uni-directional. This leads to the key design of FLBuff, i.e., a supervised-contrastive-learning model extracting penultimate-layer representations to create a large in-between buffer layer. Comprehensive evaluations demonstrate that FLBuff consistently outperforms state-of-the-art defenses. Code is at https://github.com/xingyushu/FLBuff. Xingyu Lyu, Ning Wang 0022, Yang Xiao 0010, Shixiong Li, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
TrustCom | 7 |
| 2025 | EchoLLM: LLM-Augmented Acoustic Eavesdropping Attack on Bone Conduction Headphones with mmWave Radar
Xin Yao 0002, Kecheng Huang, Yimin Chen 0004, Ming Zhao 0007 |
USENIX Security Symposium | 3 |
| 2025 | Stealthy and efficient adversarial example attack on video retrieval systems
Xin Yao 0002, Enlang Li, Yimin Chen 0004, Kecheng Huang, Fengxiao Tang, Ming Zhao 0007 |
Neural Networks | 3 |
| 2025 | FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive LearningabstractOver the last decade, Internet of Things (IoT) has permeated our daily life with a broad range of applications. However, a lack of adequate security in IoT devices renders IoT systems vulnerable to various network-based cyberattacks, potentially causing severe damage. Recent works have explored using machine learning to build anomaly detection models for defending against such attacks. In this paper, we propose FeCo, a federated-contrastive-learning framework that coordinates in-network IoT devices to jointly learn intrusion detection models. FeCo utilizes federated learning to alleviate users’ privacy concerns as participating devices only submit their model parameters rather than raw local data. Compared to previous works, we develop a novel representation learning method based on contrastive learning that is able to learn a more accurate model for the benign class. FeCo significantly improves the intrusion detection accuracy compared to previous works. In addition, we implement a two-step feature selection scheme to avoid overfitting and reduce computation time. Through extensive experiments on the NSL-KDD dataset and the BaIoT dataset, we demonstrate that FeCo achieves as high as 8% accuracy improvement compared to the state-of-the-art and is robust to non-independent and identically distributed (non-IID) data. Our implementation of FeCo on a Raspberry Pi device further confirms the applicability of FeCo for resource-constrained IoT devices. Ning Wang 0022, Shanghao Shi, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | FLARE: Defending Federated Learning Against Model Poisoning Attacks via Latent Space RepresentationsabstractFederated learning (FL) has been shown vulnerable to a new class of adversarial attacks, known asmodel poisoning attacks (MPA), where one or more malicious clients try to poison the global model by sending carefully crafted local model updates to the central parameter server. Existing defenses that have been fixated on analyzing model parameters show limited effectiveness in detecting such malicious models. In this work, we proposeFLARE, a robust model aggregation mechanism for FL, which is resilient against state-of-the-art MPAs. Instead of solely depending on model parameters,FLAREleverages thepenultimate layer representations (PLRs)of the model for characterizing the adversarial influence on each local model update. We further propose a trust evaluation method that estimates a trust score for each model update based on pairwise PLR discrepancies among all model updates. Under the assumption of honest majority,FLAREassigns a low trust score to model updates that are far from the benign cluster.FLAREthen aggregates the model updates weighted by their trust scores and finally updates the global model. Extensive experimental results demonstrate the effectiveness ofFLAREin defending FL against various MPAs, including semantic backdoor attacks, trojan backdoor attacks, and untargeted attacks, in various FL systems. Ning Wang 0022, Chaoyu Zhang, Yang Xiao 0010, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Securing Contrastive mmWave-based Human Activity Recognition against Adversarial Label FlippingabstractWireless Human Activity Recognition (HAR), leveraging their non-intrusive nature, has the potential to revolutionize various sectors, including healthcare, virtual reality, and surveillance. The advent of millimeter wave (mmWave) technology has significantly enhanced the capabilities of wireless HAR systems. This paper presents the first systematic study on the vulnerabilities of mmWave-based HAR to label flipping poisoning attacks in the context of supervised contrastive learning. We identify three label poisoning attacks on the contrastive mmWave-based HAR and propose corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other wireless HAR systems, thereby promoting security considerations in system design and deployment. Amit Singha, Ziqian Bi, Tao Li 0042, Yimin Chen 0004 |
WISEC | 4 |
| 2023 | mmLock: User Leaving Detection Against Data Theft via High-Quality mmWave Radar ImagingabstractThe use of smart devices such as smartphones, tablets, and laptops skyrocketed in the last decade. These devices enable ubiquitous applications for entertainment, communication, productivity, and healthcare but also introduce big concern about user privacy and data security. In addition to various authentication techniques, automatic and immediate device locking based on user leaving detection is an indispensable way to secure the devices. Current user leaving detection techniques mainly rely on acoustic ranging and do not work well in environments with multiple moving objects. In this paper, we present mmLock, a system that enables faster and more accurate user leaving detection in dynamic environments. mmLock uses a mmWave FMCW radar to capture the user's 3D mesh and detects the leaving gesture from the 3D human mesh data with a hybrid PointNet-LSTM model. Based on explainable user point clouds, mmLock is more robust than existing gesture recognition systems which can only identify the raw signal patterns. We implement and evaluate mmLock with a commercial off-the-shelf (COTS) TI mmWave radar in multiple environments and scenarios. We train the PointNet-LSTM model out of over 1 TB mmWave signal data and achieve 100% true-positive rate in most scenarios. Ziqian Bi, Amit Singha, Tao Li 0042, Yimin Chen 0004 |
ICCCN | 5 |
| 2023 | DUO: Stealthy Adversarial Example Attack on Video Retrieval Systems via Frame-Pixel SearchabstractMassive videos are released every day particularly through video-focused social media apps such as TikTok. This trend has fostered the quick emergence of video retrieval systems, which provide cloud-based services to retrieve similar videos using machine learning techniques. Adversarial example (AE) attacks have been shown to be effective on such systems by perturbing an unaltered video subtly to induce false retrieval results. Such AE attacks can be easily detected because the adversarial perturbations are all over pixels and frames. In this paper, we propose DUO, a stealthy targeted black-box AE attack which uses DUal search Over frame-pixel to generate sparse perturbations and improve stealthiness. DUO is motivated by two observations: only “key frames” in a video decide model predictions, and different pixels and frames contribute far differently to AEs. We implement DUO into a sequential attack pipeline consisting of two components (i.e., SparseTransfer and SparseQuery) built upon such intuitions. In particular, DUO uses SparseTransfer to generate initial perturbations and then SparseQuery to further rectify them. Extensive evaluations on two popular datasets confirm the higher efficacy and stealthiness of DUO over existing AE attacks on video retrieval systems. In particular, we show that DUO achieves higher precision while significantly reducing adversarial perturbations by more than ×100 than the state-of-the-art AE attack. Xin Yao 0002, Yimin Chen 0004, Fengxiao Tang, Ming Zhao 0007, Enlang Li |
ICDCS | 3 |
| 2023 | Evaluating the Impact of Noisy Point Clouds on Wireless Gesture Recognition SystemsabstractPoint cloud data gathered through wireless sensors has garnered increasing attention for its critical applications, including automotive radars, security systems, and notably, gesture recognition. It provides a non-intrusive and robust approach towards humancomputer interactions. However, its reliance on real-time data makes resilience of paramount concern and attacks on or imperfections with these sensors can have catastrophic effects. From real-time spoofing to data poisoning attacks or even just faulty data, systems based on 2D and 3D point cloud machine learning models can be extremely vulnerable. Despite this, there exist few studies prioritizing evaluations on the robustness of these systems over noisy time-sensitive point clouds. This study presents an in-depth examination on the effects of noisy data being used in training various millimeter wave based gesture recognition systems. Noisy point clouds can be introduced during the training stage where imperfect data is fed to a model, causing the model to misclassify test-time samples and lowering its overall accuracy. We stage and evaluate the impact of four different, simple data noising scenarios to observe potential vulnerabilities within these systems. Our findings reveal the respective susceptibilities and resiliencies of transformer, long-short term memory, and convolutional models, highlighting the importance to not only dedicate time and research towards innovations in wireless gesture recognition, but also towards optimizing these systems in order to proactively prevent undesirable effects. Paul Jiang, Ellie Fassman, Amit Singha, Yimin Chen 0004, Tao Li 0042 |
MobiHoc | 4 |
| 2023 | MANDA: On Adversarial Example Detection for Network Intrusion Detection SystemabstractWith the rapid advancement in machine learning (ML), ML-based Intrusion Detection Systems (IDSs) are widely deployed to protect networks from various attacks. One of the biggest challenges is that ML-based IDSs suffer from adversarial example (AE) attacks. By applying small perturbations (e.g., slightly increasing packet inter-arrival time) to the intrusion traffic, an AE attack can flip the prediction of a well-trained IDS. We address this challenge by proposingMANDA, a MANifold and Decision boundary-based AE detection system. Through analyzing AE attacks, we notice that 1) an AE tends to be close to its original manifold (i.e., the cluster of samples in its original class) regardless of which class it is misclassified into; and 2) AEs tend to be close to the decision boundary to minimize the perturbation scale. Based on the two observations, we designMANDAfor accurate AE detection by exploiting inconsistency between manifold evaluation and IDS model inference and evaluating model uncertainty on small perturbations. We evaluateMANDAon both binary IDS and multi-class IDS on two datasets (NSL-KDD and CICIDS) under three state-of-the-art AE attacks. Our experimental results show thatMANDAachieves high true-positive rate (98.41%) with a 5% false-positive rate. Ning Wang 0022, Yimin Chen 0004, Yang Xiao 0010, Wenjing Lou, Y. Thomas Hou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Squeezing More Utility via Adaptive Clipping on Differentially Private Gradients in Federated Meta-LearningabstractFederated meta-learning has emerged as a promising AI framework for today’s mobile computing scenes involving distributed clients. It enables collaborative model training using the data located at distributed mobile clients and accommodates clients that need fast model customization with limited new data. However, federated meta-learning solutions are susceptible to inference-based privacy attacks since the global model encoded with clients’ training data is open to all clients and the central server. Meanwhile, differential privacy (DP) has been widely used as a countermeasure against privacy inference attacks in federated learning. The adoption of DP in federated meta-learning is complicated by the model accuracy-privacy trade-off and the model hierarchy attributed to the meta-learning component. In this paper, we introduce DP-FedMeta, a new differentially private federated meta-learning architecture that addresses such data privacy challenges. DP-FedMeta features an adaptive gradient clipping method and a one-pass meta-training process to improve the model utility-privacy trade-off. At the core of DP-FedMeta are two DP mechanisms, namely DP-AGR and DP-AGRLR, to provide two notions of privacy protection for the hierarchical models. Extensive experiments in an emulated federated meta-learning scenario on well-known datasets (Omniglot, CIFAR-FS, and Mini-ImageNet) demonstrate that DP-FedMeta accomplishes better privacy protection while maintaining comparable model accuracy compared to the state-of-the-art solution that directly applies DP-based meta-learning to the federated setting. Ning Wang 0022, Yang Xiao 0010, Yimin Chen 0004, Ning Zhang 0017, Wenjing Lou, Y. Thomas Hou 0001 |
ACSAC | 3 |
| 2022 | FLARE: Defending Federated Learning against Model Poisoning Attacks via Latent Space RepresentationsabstractFederated learning (FL) has been shown vulnerable to a new class of adversarial attacks, known as model poisoning attacks (MPA), where one or more malicious clients try to poison the global model by sending carefully crafted local model updates to the central parameter server. Existing defenses that have been fixated on analyzing model parameters show limited effectiveness in detecting such carefully crafted poisonous models. In this work, we propose FLARE, a robust model aggregation mechanism for FL, which is resilient against state-of-the-art MPAs. Instead of solely depending on model parameters, FLARE leverages the penultimate layer representations (PLRs) of the model for characterizing the adversarial influence on each local model update. PLRs demonstrate a better capability to differentiate malicious models from benign ones than model parameter-based solutions. We further propose a trust evaluation method that estimates a trust score for each model update based on pairwise PLR discrepancies among all model updates. Under the assumption that honest clients make up the majority, FLARE assigns a trust score to each model update in a way that those far from the benign cluster are assigned low scores. FLARE then aggregates the model updates weighted by their trust scores and finally updates the global model. Extensive experimental results demonstrate the effectiveness of FLARE in defending FL against various MPAs, including semantic backdoor attacks, trojan backdoor attacks, and untargeted attacks, and safeguarding the accuracy of FL. Ning Wang 0022, Yang Xiao 0010, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001 |
AsiaCCS | 3 |
| 2022 | FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive LearningabstractOver the last decade, Internet of Things (IoT) has permeated our daily life with a broad range of applications. However, a lack of sufficient security features in IoT devices renders IoT ecosystems vulnerable to various network intrusion attacks, potentially causing severe damage. Previous works have explored using machine learning to build anomaly detection models for defending against such attacks. In this paper, we propose FeCo, a federated-contrastive-learning framework that coordinates in-network IoT devices to jointly learn intrusion detection models. FeCo utilizes federated learning to alleviate users’ privacy concerns as participating devices only submit their model parameters rather than local data. Compared to previous works, we develop a novel representation learning method based on contrastive learning that is able to learn a more accurate model for the benign class. FeCo significantly improves the intrusion detection accuracy compared to previous works. Besides, we implement a two-step feature selection scheme to avoid overfitting and reduce computation time. Through extensive experiments on the NSL-KDD dataset, we demonstrate that FeCo achieves as high as 8% accuracy improvement compared to the state-of-the-art and is robust to non-IID data. Evaluations on convergence, computation overhead, and scalability further confirm the suitability of FeCo for IoT intrusion detection. Ning Wang 0022, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2022 | Clang __usercall: towards native support for user defined calling conventionsabstractIn reverse engineering interfacing with C/C++ functions is of great interest because it provides much more flexibility for product development and security purpose. However, it has been a great challenge when interfacing functions with user defined calling conventions due to the lack of sufficient and user-friendly tooling. In this work, we design and implement Clang __usercall, which aims to provide programmers with an elegant and familiar syntax to specify user defined calling conventions on functions in C/C++ source code. Our key novelties lie in mimicing the most popular syntax and adapting Clang for interfacing purpose. Our preliminary user study shows that our solution outperforms the existing ones in multiple key aspects including user experience and required lines of code. Clang __usercall is already added to the Compiler Explorer website as well. Jared Q. Widberg, Sashank Narain, Yimin Chen 0004 |
ESEC/SIGSOFT FSE | 3 |
| 2022 | NOSnoop: An Effective Collaborative Meta-Learning Scheme Against Property Inference AttackabstractCollaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this article, we focus on the property inference attack during model training and design a novel defense mechanism, namely, NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support data set. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support data set, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility. XinDi Ma, Baopu Li, Qi Jiang 0001, Yimin Chen 0004, Sheng Gao 0002, Jianfeng Ma 0001 |
IEEE Internet Things J. | 4 |
| 2021 | MANDA: On Adversarial Example Detection for Network Intrusion Detection SystemabstractWith the rapid advancement in machine learning (ML), ML-based Intrusion Detection Systems (IDSs) are widely deployed to protect networks from various attacks. Yet one of the biggest challenges is that ML-based IDSs suffer from adversarial example (AE) attacks. By applying small perturbations (e.g. slightly increasing packet inter-arrival time) to the intrusion traffic, an AE attack can flip the prediction of a well-trained IDS. We address this challenge by proposing MANDA, a MANifold and Decision boundary-based AE detection system. Through analyzing AE attacks, we notice that 1) an AE tends to be close to its original manifold (i.e., the cluster of samples in its original class) regardless which class it is misclassified into; and 2) AEs tend to be close to the decision boundary so as to minimize the perturbation scale. Based on the two observations, we design MANDA for accurate AE detection by exploiting inconsistency between manifold evaluation and IDS model inference and evaluating model uncertainty on small perturbations. We evaluate MANDA on NSL-KDD under three state-of-the-art AE attacks. Our experimental results show that MANDA achieves as high as 98.41% true-positive rate with 5% false-positive rate and can be applied to other problem spaces such as image recognition. Ning Wang 0022, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2020 | IndoorWaze: A Crowdsourcing-Based Context-Aware Indoor Navigation SystemabstractIndoor navigation systems are very useful in large complex indoor environments such as shopping malls. Current systems focus on improving indoor localization accuracy and must be combined with an accurate labeled floor plan to provide usable indoor navigation services. Such labeled floor plans are often unavailable or involve a prohibitive cost to manually obtain. In this paper, we present IndoorWaze, a novel crowdsourcing-based context-aware indoor navigation system that can automatically generate an accurate context-aware floor plan with labeled indoor POIs for the first time in literature. IndoorWaze combines the Wi-Fi fingerprints of indoor walkers with the Wi-Fi fingerprints and POI labels provided by POI employees to produce a high-fidelity labeled floor plan. As a lightweight crowdsourcing-based system, IndoorWaze involves very little effort from indoor walkers and POI employees. We prototype IndoorWaze on Android smartphones and evaluate it in a large shopping mall. Our results show that IndoorWaze can generate a high-fidelity labeled floor plan, in which all the stores are correctly labeled and arranged, all the pathways and crossings are correctly shown, and the median estimation error for the store dimension is below 12%. Tao Li 0042, Dianqi Han, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth |
IEEE Trans. Wirel. Commun. | 3 |
| 2018 | Secure Crowdsourced Indoor Positioning SystemsabstractIndoor positioning systems (IPSes) can enable many location-based services in large indoor environments where GPS is not available or reliable. Mobile crowdsourcing is widely advocated as an effective way to construct IPS maps. This paper presents the first systematic study of security issues in crowd-sourced WiFi-based IPSes to promote security considerations in designing and deploying crowdsourced IPSes. We identify three attacks on crowdsourced WiFi-based IPSes and propose the corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other crowdsourced IPSes. Tao Li 0042, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth |
INFOCOM | 2 |
| 2018 | Proximity-Proof: Secure and Usable Mobile Two-Factor AuthenticationabstractMobile two-factor authentication (2FA) has become commonplace along with the popularity of mobile devices. Current mobile 2FA solutions all require some form of user effort which may seriously affect the experience of mobile users, especially senior citizens or those with disability such as visually impaired users. In this paper, we propose Proximity-Proof, a secure and usable mobile 2FA system without involving user interactions. Proximity-Proof automatically transmits a user's 2FA response via inaudible OFDM-modulated acoustic signals to the login browser. We propose a novel technique to extract individual speaker and microphone fingerprints of a mobile device to defend against the powerful man-in-the-middle (MiM) attack. In addition, Proximity-Proof explores two-way acoustic ranging to thwart the co-located attack. To the best of our knowledge, Proximity-Proof is the first mobile 2FA scheme resilient to the MiM and co-located attacks. We empirically analyze that Proximity-Proof is at least as secure as existing mobile 2FA solutions while being highly usable. We also prototype Proximity-Proof and confirm its high security, usability, and efficiency through comprehensive user experiments. Dianqi Han, Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth |
MobiCom | 2 |
| 2018 | EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsabstractKeystroke inference attacks pose an increasing threat to ubiquitous mobile devices. This paper presents EyeTell, a novel video-assisted attack that can infer a victim's keystrokes on his touchscreen device from a video capturing his eye movements. EyeTell explores the observation that human eyes naturally focus on and follow the keys they type, so a typing sequence on a soft keyboard results in a unique gaze trace of continuous eye movements. In contrast to prior work, EyeTell requires neither the attacker to visually observe the victim's inputting process nor the victim device to be placed on a static holder. Comprehensive experiments on iOS and Android devices confirm the high efficacy of EyeTell for inferring PINs, lock patterns, and English words under various environmental conditions. Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | Beware of What You Share: Inferring User Locations in VenmoabstractMobile payment apps are seeing explosive usage worldwide. This paper focuses on Venmo, a very popular mobile person-to-person payment service owned by Paypal. Venmo allows money transfers between users with a mandatory transaction note. More than half of transaction records in Venmo are public information. In this paper, we propose a multilayer location inference (MLLI) technique to infer user locations from public transaction records in Venmo. MLLI explores two observations. First, many Venmo transaction notes contain implicit location cues. Second, the types and temporal patterns of user transactions have strong ties to their location closeness. With a large dataset of 2.12M users and 20.23M Venmo transaction records, we show that MLLI can identify the top-1, top-3, and top-5 possible locations for a Venmo user with accuracy up to 50%, 80%, and 90%, respectively. Our results highlight the danger of sharing transaction notes on Venmo or similar mobile payment apps. Xin Yao 0002, Yimin Chen 0004, Rui Zhang 0007, Yaping Lin |
IEEE Internet Things J. | 2 |
| 2017 | POWERFUL: Mobile app fingerprinting via power analysisabstractWhich apps a mobile user has and how they are used can disclose significant private information about the user. In this paper, we present the design and evaluation of POWERFUL, a new attack which can fingerprint sensitive mobile apps (or infer sensitive app usage) by analyzing the power consumption profiles on Android devices. POWERFUL works on the observation that distinct apps and their different usage patterns all lead to distinguishable power consumption profiles. Since the power profiles on Android devices require no permission to access, POWERFUL is very difficult to detect and can pose a serious threat against user privacy. Extensive experiments involving popular and sensitive apps in Google Play Store show that POWERFUL can identify the app used at any particular time with accuracy up to 92.9%, demonstrating the feasibility of POWERFUL. Yimin Chen 0004, Xiaocong Jin, Jingchao Sun, Rui Zhang 0007 |
INFOCOM | 1 |
| 2017 | Your face your heart: Secure mobile face authentication with photoplethysmogramsabstractFace authentication emerges as a powerful method for preventing unauthorized access to mobile devices. It is, however, vulnerable to photo-based forgery attacks (PFA) and videobased forgery attacks (VFA), in which the adversary exploits a photo or video containing the user's frontal face. Effective defenses against PFA and VFA often rely on liveness detection, which seeks to find a live indicator that the submitted face photo or video of the legitimate user is indeed captured in real time. In this paper, we propose FaceHeart, a novel and practical face authentication system for mobile devices. FaceHeart simultaneously takes a face video with the front camera and a fingertip video with the rear camera on COTS mobile devices. It then achieves liveness detection by comparing the two photoplethysmograms independently extracted from the face and fingertip videos, which should be highly consistent if the two videos are for the same live person and taken at the same time. As photoplethysmograms are closely tied to human cardiac activity and almost impossible to forge or control, FaceHeart is strongly resilient to PFA and VFA. Extensive user experiments on Samsung Galaxy S5 have confirmed the high efficacy and efficiency of FaceHeart. Yimin Chen 0004, Jingchao Sun, Xiaocong Jin, Tao Li 0042, Rui Zhang 0007 |
INFOCOM | 1 |
| 2016 | DPSense: Differentially Private Crowdsourced Spectrum SensingabstractDynamic spectrum access (DSA) has great potential to address worldwide spectrum shortage by enhancing spectrum efficiency. It allows unlicensed secondary users to access the underutilized licensed spectrum when the licensed primary users are not transmitting. As a key enabler for DSA systems, crowdsourced spectrum sensing (CSS) allows a spectrum sensing provider (SSP) to outsource the sensing of spectrum occupancy to distributed mobile users. In this paper, we propose DPSense, a novel framework that allows the SSP to select mobile users for executing spatiotemporal spectrum-sensing tasks without violating the location privacy of mobile users. Detailed evaluations on real location traces confirm that DPSense can provide differential location privacy to mobile users while ensuring that the SSP can accomplish spectrum-sensing tasks with overwhelming probability and also the minimal cost. Xiaocong Jin, Rui Zhang 0007, Yimin Chen 0004, Tao Li 0042 |
CCS | 3 |
| 2016 | iLock: Immediate and Automatic Locking of Mobile Devices against Data TheftabstractMobile device losses and thefts are skyrocketing. The sensitive data hosted on a lost/stolen device are fully exposed to the adversary. Although password-based authentication mechanisms are available on mobile devices, many users reportedly do not use them, and a device may be lost/stolen while in the unlocked mode. This paper presents the design and evaluation of iLock, a secure and usable defense against data theft on a lost/stolen mobile device. iLock automatically, quickly, and accurately recognizes the user's physical separation from his/her device by detecting and analyzing the changes in wireless signals. Once significant physical separation is detected, the device is immediately locked to prevent data theft. iLock relies on acoustic signals and requires at least one speaker and one microphone that are available on most COTS (commodity-off-the-shelf) mobile devices. Extensive experiments on Samsung Galaxy S5 show that iLock can lock the device with negligible false positives and negatives. Tao Li 0042, Yimin Chen 0004, Jingchao Sun, Xiaocong Jin |
CCS | 2 |
| 2016 | VISIBLE: Video-Assisted Keystroke Inference from Tablet Backside Motion
Jingchao Sun, Xiaocong Jin, Yimin Chen 0004, Jinxue Zhang, Rui Zhang 0007 |
NDSS | 3 |
| 2015 | Your song your way: Rhythm-based two-factor authentication for multi-touch mobile devicesabstractMulti-touch mobile devices have penetrated into everyday life to support personal and business communications. Secure and usable authentication techniques are indispensable for preventing illegitimate access to mobile devices. This paper presents RhyAuth, a novel two-factor rhythm-based authentication scheme for multi-touch mobile devices. RhyAuth requires a user to perform a sequence of rhythmic taps/slides on a device screen to unlock the device. The user is authenticated and admitted only when the features extracted from her rhythmic taps/slides match those stored on the device. RhyAuth is a two-factor authentication scheme that depends on a user-chosen rhythm and also the behavioral metrics for inputting the rhythm. Through a 32-user experiment on Android devices, we show that RhyAuth is highly secure against various attacks and also very usable for both sighted and visually impaired people. Yimin Chen 0004, Jingchao Sun, Rui Zhang 0007 |
INFOCOM | 1 |