Xiaoyu Ji 0001

dblp:39/1697-1 · DBLP profile ↗
← Back
130ranked-venue papers
15as first author
95since 2021 · last 2026
0000-0002-1101-0007ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 63 · 4 first-author · 55 since 2021Computer networks · 51 · 11 first-author · 30 since 2021Systems, architecture and hardware · 6 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Phantom Menace: Exploring and Enhancing the Robustness of VLA Models Against Physical Sensor Attacks
abstract
Vision-Language-Action (VLA) models revolutionize robotic systems by enabling end-to-end perception-to-action pipelines that integrate multiple sensory modalities, such as visual signals processed by cameras and auditory signals captured by microphones. This multi-modality integration allows VLA models to interpret complex, real-world environments using diverse sensor data streams. Given the fact that VLA-based systems heavily rely on the sensory input, the security of VLA models against physical-world sensor attacks remains critically underexplored. To address this gap, we present the first systematic study of physical sensor attacks against VLAs, quantifying the influence of sensor attacks and investigating the defenses for VLA models. We introduce a novel ``Real-Sim-Real" framework that automatically simulates physics-based sensor attack vectors, including six attacks targeting cameras and two targeting microphones, and validates them on real robotic systems. Through large-scale evaluations across various VLA architectures and tasks under varying attack parameters, we demonstrate significant vulnerabilities, with susceptibility patterns that reveal critical dependencies on task types and model designs. We further develop an adversarial-training-based defense that enhances VLA robustness against out-of-distribution physical perturbations caused by sensor attacks while preserving model performance. Our findings expose an urgent need for standardized robustness benchmarks and mitigation strategies to secure VLA deployments in safety-critical environments.
Xuancun Lu, Jiaxiang Chen, Shilin Xiao, Zizhi Jin, Zhangrui Chen, Hanwen Yu, Bohan Qian, Ruochen Zhou, Xiaoyu Ji 0001, Wenyuan Xu 0001
AAAI9
2026 Uncovering Frequency Cues for Robust Event-Based UAV Detection
abstract
The increasing popularity of Unmanned Aerial Vehicles (UAVs) raises concerns regarding their misuse, necessitating effective detection systems. Utilizing event cameras for UAV detection is an emergent research topic showing great promise as an alternative.
Xiaoyu Ji 0001, Wenyuan Xu 0001
ICMR3
2026 SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities
Shilin Xiao, Kai Wang 0073, Peiwang Wang, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS7
2026 PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal Fuzzing
Zhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS6
2026 ArchSnoop: LLM Architecture Snooping via Electromagnetic Side-Channel on Edge Devices
abstract
The rapid development of large language models (LLMs) has led to their increasing deployment on edge devices for applications such as autonomous driving. These edge deployments enable efficient localized processing while enhancing user privacy. However, unintentional leaks of model families and hyperparameters during LLM execution serve as critical attack vectors, facilitating high-level threats like model extraction and membership inference. In this paper, we propose ArchSnoop, which is a non intrusive edge LLM architecture eavesdropping attack based on electromagnetic (EM) leakage. Our key insight is that the EM signals emitted by GPU and memory activities during inference reflect hierarchical architectural features ranging from token generation to individual linear projections. We designed a two-stage hierarchical reconstruction model to recover fine-grained architectural information from these EM signals. Our evaluation on the NVIDIA Jetson Orin Nano platform demonstrates that ArchSnoop achieves high accuracy in architecture reconstruction, including 99.12% in model family classification and 97.11% for hyperparameter estimation. We reveal the mapping between EM signals and LLM architectures on edge devices for the first time. By proposing potential countermeasures such as physical EM shielding and software-level perturbations, this work provides a new dimension to secure edge computing platforms against physical threats.
Haozhe Weng, Ruochen Zhou, Yubo Qu, Xiaoyu Ji 0001, Wenyuan Xu 0001
WISEC4
2026 FDsign: A Signature Verification Method Based on Feature Fusion and Time-Series Diffusion Model
abstract
Handwritten signature verification has emerged as the predominant authentication method for paper-based transactions in critical sectors including financial services, legal documentation, and banking operations. While offline approaches utilizing static signature images remain vulnerable to forgery attacks, online methods demonstrate greater reliability by incorporating dynamic biometric features captured during the signing process. The existing methods primarily capture the signature trajectory with built-in sensors of wearable devices, which are constrained by dominant-hand limitations, resulting in poor usability. Besides, relying solely on single-dimensional features renders the system vulnerable. Therefore, in this article, we propose a signature verification prototype FDsign, which performs feature fusion of pressure sensor and IMU sensors that are embedded in a smart pen to accurately capture users’ multi-dimensional signature personality information, which greatly improves the system security. To address the challenges of multi-modal signal fusion, few-shot learning and recognition accuracy, FDsign proposes DiffRNN-ClassNet, a framework that integrates a diffusion model with Bi-LSTM. Extensive experiments validate that FDsign achieves 97.1% authentication accuracy across diverse signing environments while maintaining security in diverse operational scenarios.
Xiaoyu Ji 0001, Haiming Chen 0002
IEEE Internet Things J.4
2026 VoltSiren: Exploiting Power Supply Vulnerabilities to Control IoT Devices
abstract
This paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing, actuating, and communicating. Particularly, we discover a vulnerability in power supply modules and propose VoltSiren attacks. To launch a VoltSiren attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Consequently, VoltSiren attacks can cause sensor measurements irrelevant to reality, maneuver actuators in a way disregarding the desired command, or disrupt communications. To understand VoltSiren, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensors, actuators, or communication modules. Based on these findings, we implement and validate VoltSiren on off-the-shelf products: six sensors, three actuators, and two communication modules, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The root cause of this vulnerability lies in the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks.
Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Ruochen Zhou, Kaixiang Zhang 0002, Wenyuan Xu 0001
IEEE Internet Things J.4
2026 A Lightweight Open-Set Specific Emitter Identification Based on Broad Learning
abstract
Specific Emitter Identification (SEI) exploits subtle, device-specific imperfections in physical-layer signals—known as Radio Frequency Fingerprints (RFFs)—to distinguish authorized transmitters from unauthorized ones. Conventional deep-learning SEI approaches, however, typically require large labeled datasets, incur long training times, consume substantial computational resources, and provide limited interpretability—constraints that hinder deployment on resource-constrained receivers. We propose BLi2, a lightweight Broad Learning (BL) framework engineered to mitigate these challenges for open-set SEI in IoT settings. BLi2 uses an Instantaneous Autocorrelation Representation (IAR) to extract compact, phase-based fingerprints from raw I/Q samples and employs a two-stage open-set recognition pipeline to detect unauthorized emitters before closed-set classification. Experiments on two real-world ADS-B datasets and a Wi-Fi dataset demonstrate that BLi2: (1) attains >98.80% closed-set accuracy for 50 classes (98.72% for 150 classes while using only ≈0.195M parameters—over a half as comparable BL methods) and ≈90% open-set accuracy with 50 unknowns; (2) trains in under 20 s on a Raspberry Pi, maintaining >96.33% accuracy across SNRs; and (3) improves accuracy by >12% compared with raw I/Q baselines in the reported ablation. These results validate that BLi2 provides high identification accuracy while maintaining the computational efficiency required for edge-IoT deployments.
Xiaoyu Ji 0001, Genying Hu
IEEE Internet Things J.3
2026 Critical Information Only: A Content Privacy-Preserving Framework for Detecting Audio Deepfakes
abstract
Text-to-Speech (TTS) and Voice Conversion (VC) models have exhibited remarkable performance in generating realistic and natural audio. However, their dark side, audio deepfake poses a significant threat to both society and individuals. Existing countermeasures largely focus on determining the genuineness of speech based on complete original audio recordings, which however often contain private content. This oversight may refrain deepfake detection from many applications, particularly in scenarios involving sensitive information like business secrets. In this paper, we propose SafeEar, a novel framework that aims to detect deepfake audios without relying on accessing the speech content within. Our key idea is to devise a neural audio codec into a novel decoupling model that well separates the semantic and acoustic information from audio samples, and only use the acoustic information (e.g., prosody and timbre) for deepfake detection. In this way, no semantic content will be exposed to the detector. To overcome the challenge of identifying diverse deepfake audio without semantic clues, we enhance our deepfake detector with real-world augmentation, such as codecs and reverbs. Extensive experiments conducted on five benchmark datasets demonstrate SafeEar's effectiveness in detecting various deepfake techniques with an equal error rate (EER) down to 2.41%. Simultaneously, it shields f ive-language speech content from being deciphered by both machine and human auditory analysis, demonstrated by word error rates (WERs) all above 93.74% and our user study. Furthermore, our benchmark constructed for anti-deepfake and anti-content recovery evaluation helps provide a basis for future research in the realms of audio privacy preservation and deepfake detection.
Xinfeng Li, Yifan Zheng 0001, Chen Yan 0001, Kai Li 0047, Chang Zeng, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.6
2026 Adversarial Attacks on Closed Box Speech Recognition Systems via Laser Injection
abstract
Audio adversarial perturbations are designed to remain imperceptible to humans while deceiving automatic speech recognition (ASR) models. However, operating within the audible frequency range makes existing methods partially detectable in practice. In this paper, we present LaserAdv, a laser-based adversarial attack that injects carefully crafted perturbations via laser signals, which are superimposed on speech rather than masking it. This design exploits a well-established property of adversarial examples—the ability to mislead models through minimal, often imperceptible, modifications—while preserving the underlying speech, thereby enabling higher attack efficiency and a longer effective attack range. To mitigate distortion introduced during laser transmission, we propose SAE-TFI, a selective amplitude enhancement method in the time–frequency domain. LaserAdv enables physically realizable attacks that are inaudible and black-box, while supporting targeted and universal attack settings without requiring signal synchronization. Experimental results demonstrate that a single perturbation can cause DeepSpeech, Whisper, and iFlytek to misinterpret any of the 12,260 voice commands as target with accuracy of up to 100%, 92% and 88%, respectively. The maximum effective attack distance reaches 120 m.
Zhijie Xiang, Yanni Yang 0003, Xiaoyu Ji 0001, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Dependable Secur. Comput.6
2026 Mad or Impossible to Be Mad? Rethinking Load Manipulation Threats in Renewable-Integrated Power Grids and Defenses
Zhouhao Ji, Kaikai Pan, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Trans. Inf. Forensics Secur.3
2026 Sniffing the Application Usage Information With the Leakage Current of Laptops
abstract
Smart devices are proliferating in every aspect of our lives, providing convenience but also exposing us to the risk of information leakage at any moment. Attackers can monitor the user and infer private information such as personality and preferences by stealing the behavioral information. In this paper, we investigated the potential threat of information stealing via the leakage current of laptops and electrodes in wearable devices (e.g., smart watches and bracelets). Specifically, the leakage current in the laptop adapter can flow from the metal casing into the human body and be collected by electrodes in wearable devices when the user is using a laptop with a metal casing (e.g., MacBook). We verified the correlation between leakage current and the working states of the laptop, where different operations corresponding to different CPU instructions can generate different leakage currents. Based on this, we proposeLeakThief, a system that consists of three components: leakage current detection, application operation detection, and application recognition. The experiments in a real-world environment demonstrated that the proposed system can recognize 25 common applications with high accuracy, including launching-based (96.4%) and in-application operation-based recognition (81.2%).
Dian Ding, Yijie Li 0002, Yongzhao Zhang, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Guangtao Xue
IEEE Trans. Mob. Comput.5
2025 MYOPIA: Protecting Face Privacy from Malicious Personalized Text-to-Image Synthesis via Unlearnable Examples
abstract
Personalized text-to-image synthesis models, such as DreamBooth, have demonstrated significant potential in creating lifelike images tailored to a specific individual by fine-tuning from a limited set of face images and simple prompts. However, if misused, these model could pose a serious risk of privacy infringement by generating harmful images containing violent or pornographic content. To tackle this issue, this paper introduces MYOPIA, a method that renders facial images unlearnable by incorporating error-minimizing perturbations. These meticulously designed perturbations enables the model to quickly overfit to them, resulting in a swift reduction in loss and the cessation of model fine-tuning, effectively preventing the model from capturing genuine facial features. Moreover, to ensure the imperceptibility and robustness of the perturbations, we utilize the Just-Noticeable-Difference and Expectation-of-Transformation techniques to regulate both their location and intensity. Evaluation on two face dataset, i.e., VGGFace2 and CelebA-HQ, with various model versions illustrates the effectiveness of our approach in preserving personal privacy. Furthermore, our method showcases robust transferability across diverse model versions and demonstrates resilience against various image pre-processing techniques.
Yushi Cheng, Tianyang Sun, Xiaoyu Ji 0001, Wenyuan Xu 0001
AAAI4
2025 V-Phanton: Voltage-Based Physically-Triggered Backdoor Attack Against Facial Recognition
abstract
Physical backdoor attacks are under increasing scrutiny, yet current methods often necessitate directly applying adversarial perturbations to target objects, like the attacker’s face. These approaches often pose practical challenges and compromise concealment. In this paper, we propose a stealthy, physically-triggered backdoor attack, V-Phanton,enabling attackers to engage in face spoofing and bypass facial recognition without the need for physical alterations to the attacker or model modifications. Specifically, V-Phanton manipulates the power supply voltage of the webcam to introduce adversarial perturbations into the captured image, which undermines the recognition process. Our experiments across three facial recognition models (ArcFace-50, MagFace-18/50) and one commercial facial recognition system (Face++) illustrate that V-Phanton achieves attack and victim success rates of up to 100% and 100% in simulations, and 100% and 99.93% in real-world experiments.
Ruishan Li, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICASSP4
2025 RF-Rock: An Intermodulation-based RFID Unauthorized Identification Attack without Tag Activation
abstract
Following the broad prospect of Radio Frequency Identification (RFID) technology is the security concern of unauthorized tag identification, which poses threats to the privacy of both objects and users. In this paper, we propose RF-Rock, the first RFID unauthorized identification attack that operates without tag activation, thereby evading almost all existing defenses. This attack exposes the vulnerabilities of current RFID networks in identification legitimacy and privacy. It is based on the intermodulation effect originating from intrinsic nonlinearity within tag circuits. To this end, we explore the distinctness and consistency of the intermodulation-based physical layer fingerprint of RFID tags with theoretical analysis and empirical validation, and optimize the attack accuracy and efficiency with delicate excitation plan. Real-world experiments show that RF-Rock achieves an attack success rate of 93.2% on average under various conditions. The entropy of our proposed fingerprint is 15.5 bits and implies sufficient capacity in practical attacks.
Bo Liang 0003, Purui Wang, Xiaoyu Ji 0001, Yin Chen 0001, Chenren Xu
MobiCom4
2025 SADIF: Spoofing Attack on BLE Direction Finding Based Localization System
abstract
Bluetooth Low Energy (BLE) direction finding, a feature introduced in BLE version 5.1, enables precise localization through Angle of Arrival (AoA) estimation. However, this advancement introduces new risk to BLE direction finding based localization system. Specifically, the AoA estimation based on phase sampling of constant-tone-extension (CTE) is susceptible to the signal injection attack. This paper presents SaDiF, a feasible spoofing attack mechanism to mislead the locators into mistaking the positioning result as a continuous path. By eavesdropping on BLE packets and injecting attack signals containing pre-designed disturbing phase shift, SaDiF subtly alters the AoA estimation without detection, thus interfere the localization results. Moreover, SaDiF address the challenges posed by hardware imperfections by proposing an injection timing optimization to improve attack robustness. Extensive experiments demonstrates the effectiveness of SaDiF in successfully attacking multiple BLE targets in real-time scenarios. In conclusion, our findings reveal critical security risks in BLE direction finding feature and provide insights into strengthening its defenses.
Runting Zhang, Yijie Li 0002, Dian Ding, Hao Pan 0003, Yongzhao Zhang, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Jiadi Yu, Guangtao Xue
MobiHoc7
2025 PowerRadio: Manipulate Sensor Measurement via Power GND Radiation
Xiaoyu Ji 0001, Yancheng Jiang, Kai Wang 0073, Chenren Xu, Wenyuan Xu 0001
NDSS2
2025 PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR
Zizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS5
2025 GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference
Yanze Ren, Qinhong Jiang, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS4
2025 LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference
Fengchen Yang, Wenze Cui, Xinfeng Li, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS5
2025 ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters
Fengchen Yang, Zihao Dan, Kaikai Pan, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS5
2025 Neural Invisibility Cloak: Concealing Adversary in Images via Compromised AI-driven Image Signal Processing
Xiaoyu Ji 0001, Xinfeng Li, Ruoyan Xu, Wenyuan Xu 0001
USENIX Security Symposium2
2025 Laser-Based LiDAR Spoofing: Effects Validation, Capability Quantification, and Countermeasures
abstract
Autonomous vehicles (AVs) and robots increasingly exploit light detection and ranging (LiDAR)-based 3-D object detection systems to detect obstacles in the environment. Correct detection and classification are important to ensure safe driving. Although previous work has demonstrated the feasibility of manipulating point clouds to spoof 3-D object detectors, most of these attempts are performed digitally. In this article, we investigate the possibility of physically fooling LiDAR-based 3-D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We further analyze the impact of our attacks on four fusion-based detectors. This article concludes with experiments on defense methods and discussion on potential defense strategies at both the sensor and AV system levels.
Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001
IEEE Internet Things J.2
2025 Multi-Modal Spoofing Attacks on 3D Face Liveness Detection via a Single 2D Photo
abstract
Face authentication technology has been widely used in physical access control to critical infrastructures. The security of a face authentication system has been threatened by photo replay attacks and thus the 3D liveness detection techniques have been deployed to safeguard such systems. In this paper, we conduct a comprehensive analysis of the security aspects pertaining to 3D liveness detection systems that employ structured light depth camera, and propose a novel attack surface targeting 3D face authentication systems involving multiple modalities such as Depth, RGB and IR. We propose theDepthFakeattack, a multi-modal spoofing attack against real-world 3D face authentication using only a single 2D photo. To achieve it,DepthFakefirst reconstruct the depth information of the victim's face from his 2D photo. Then,DepthFakeactively projects a carefully-crafted scatter patterns embedded with the face depth information, in order to empower the 2D photo with 3D authentication properties. We address a range of practical challenges, including mitigating depth estimation errors, achieving depth images forgery techniques based on structured light, ensuring accurate alignment between various modalities of face images, and effectively implementingDepthFakein real world. We validatedDepthFakeon 5 commercial face authentication systems (i.e., Tencent Cloud, Baidu Cloud, 3DiVi, Ali Cloud and ArcSoft) and two commercial access control devices. The results over 50 users demonstrate thatDepthFakeachieves an overall Depth attack success rate of 79.4%, RGB-D attack success rate of 59.4%, IR-D attack success rate of 79.4%, and RGB-IR attack success rate of 83.8% in the real world.
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.3
2025 UltraAdv: An Ultrasonic Adversarial Attack on Closed-Box Speech Recognition Systems
abstract
Attacks on speech recognition systems often use adversarial or inaudible commands. However, a challenge is that adversarial perturbations typically fall within the audible frequency range, making it difficult to achieve inaudibility. Additionally, the non-linear effects of loudspeakers often cause inaudible commands to become audible at higher power levels. Therefore, minimizing the power requirements of the attack is essential to maintain inaudibility. Another significant obstacle is the conversion of variable-length commands, especially longer ones, into shorter target commands. In this paper, we present UltraAdv, a method for generating long-range adversarial perturbations capable of compromising commands of arbitrary length in closed-box setting. By combining the ultrasonic signal with the normal one, rather than negating it as in DolphinAttack, we significantly improve the energy efficiency, thus enhancing its attack distance. We also propose a dynamically adjustable suppression-interference method based on automatic gain control to address the challenge of mismatched durations between long commands and target commands (length-independent). Experiments demonstrate that using a single perturbation, we achieve impressive success rates of 98.84% and 96.62% and 98.32% across a diverse set of 12,260 speeches on DeepSpeech, iFlytek, and Whisper. The attack range reaches up to 15 m, surpassing DolphinAttack's 5 m range at equivalent power.
Riccardo Spolaor, Yanni Yang 0003, Xiaoyu Ji 0001, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Mob. Comput.6
2024 SafeEar: Content Privacy-Preserving Audio Deepfake Detection
Xinfeng Li, Kai Li 0047, Yifan Zheng 0001, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
CCS5
2024 SafeGen: Mitigating Sexually Explicit Content Generation in Text-to-Image Models
abstract
Text-to-image (T2I) models, such as Stable Diffusion, have exhibited remarkable performance in generating high-quality images from text descriptions in recent years. However, text-to-image models may be tricked into generating not-safe-for-work (NSFW) content, particularly in sexually explicit scenarios. Existing countermeasures mostly focus on filtering inappropriate inputs and outputs, or suppressing improper text embeddings, which can block sexually explicit content (e.g., naked) but may still be vulnerable to adversarial prompts -- inputs that appear innocent but are ill-intended. In this paper, we present SafeGen, a framework to mitigate sexual content generation by text-to-image models in a text-agnostic manner. The key idea is to eliminate explicit visual representations from the model regardless of the text input. In this way, the text-to-image model is resistant to adversarial prompts since such unsafe visual representations are obstructed from within. Extensive experiments conducted on four datasets and large-scale user studies demonstrate SafeGen's effectiveness in mitigating sexually explicit content generation while preserving the high-fidelity of benign images. SafeGen outperforms eight state-of-the-art baseline methods and achieves 99.4% sexual content removal performance. Furthermore, our constructed benchmark of adversarial prompts provides a basis for future development and evaluation of anti-NSFW-generation methods.
Xinfeng Li, Jiangyi Deng, Chen Yan 0001, Yanjiao Chen, Xiaoyu Ji 0001, Wenyuan Xu 0001
CCS6
2024 Watch the Rhythm: Breaking Privacy with Accelerometer at the Extremely-Low Sampling Rate of 5Hz
abstract
Considering the threat from on-board eavesdropping with smartphone motion sensors, Android 12 has limited the maximum sampling rate of motion sensors to 200Hz for zero-privilege access to prevent potential wiretapping.Unfortunately, there have been some attacks targeting 200Hz, making it not a safe sampling rate any more.Smartphone manufacturers may further reduce the maximum sampling rate of the accelerometer in response to this privacy concern.It can be expected that, the maximum sampling rate will gradually decrease to a very low level, as the battle between manufacturers and adversaries continues.Existing on-board eavesdropping approaches, utilizing spectral features, cannot provide acceptable accuracy at very low sampling rates, not even at 50Hz.Therefore, this paper explores the feasibility of using the onboard accelerometer for privacy breaking with an extremely-low sampling rate, specifically, 5Hz.5Hz is a minimum sampling rate to meet normal use, otherwise the applications can only choose to work without the accelerometer.Since the lowest fundamental frequency for humans is around 85Hz, such a low sampling rate poses a significant challenge for sound recognition.According to Nyquist's law, it seems impossible to capture 85Hz with the sampling rate of 5Hz.Fortunately, we observe that the rhythm features, including pause rhythm and intensity rhythm, of accelerometer data are relatively stable at various sampling rates.On this basis, we propose an eavesdropping approach with the accelerometer at an extremely-low sampling rate.Introducing the rhythm features, we * He completed his work on this paper as a graduate student at Xidian University, unrelated to his current institution.
Qingsong Yao, Xiongjia Sun, Xuewen Dong, Xiaoyu Ji 0001, Jianfeng Ma 0001
CCS5
2024 GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards
Qinhong Jiang, Yanze Ren, Yan Long 0002, Chen Yan 0001, Yumai Sun, Xiaoyu Ji 0001, Kevin Fu, Wenyuan Xu 0001
NDSS6
2024 Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time
Xinfeng Li, Chen Yan 0001, Xuancun Lu, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS5
2024 EM Eye: Characterizing Electromagnetic Side-channel Eavesdropping on Embedded Cameras
Yan Long 0002, Qinhong Jiang, Chen Yan 0001, Tobias Alam, Xiaoyu Ji 0001, Wenyuan Xu 0001, Kevin Fu
NDSS5
2024 UniID: Spoofing Face Authentication System by Universal Identity
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS4
2024 CamPro: Camera-based Anti-Facial Recognition
Jiani Liu 0009, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS5
2024 Understanding and Benchmarking the Commonality of Adversarial Examples
abstract
Speech recognition system converts audio into texts by utilizing deep learning algorithms. Numerous works have demonstrated various adversarial example (AE) attacks, i.e., adding carefully-crafted noises can trick the speech recognition system into outputting completely incorrect texts. This paper aims to reveal the distinctive properties of adversarial audio in terms of phonetics. We believe analyzing the distinctive properties is critical in understanding adversarial attacks on ASR models, as well as guiding the generation and defense of AEs. Thus, we aim to answer three questions: (1) What are the distinctive properties of adversarial audio that are common to diverse attacks? (2) How to quantify these distinctive properties? (3) How can we use these properties to improve the security of ASR models? To answer these questions, we perform a large-scale measurement based on acoustic features and statistical analysis. By measuring a total of 612,000 acoustic-statistical feature vectors for 2,400 audio samples, we obtain four insights on the distinctive properties, i.e., filling energy gap, speech-like morphology, disordered signal, and abnormal linguistic pattern. Based on these properties, we design a naturalness score to assess the stealthiness of attacks and propose an adversarial example detector with an average accuracy of 91.1%.
He Ruiwen, Yushi Cheng, Junning Ze, Xiaoyu Ji 0001, Wenyuan Xu 0001
SP4
2024 LaserAdv: Laser Adversarial Attacks on Speech Recognition Systems
Zhijie Xiang, Xiaoyu Ji 0001, Yanni Yang 0003, Xiuzhen Cheng, Pengfei Hu 0001
USENIX Security Symposium5
2024 Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack
Zizhi Jin, Xuancun Lu, Yushi Cheng, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
WWW6
2024 Device authentication for 5G terminals via Radio Frequency fingerprints
abstract
The development of wireless communication network technology has provided people with diversified and convenient services. However, with the expansion of network scale and the increase in the number of devices, malicious attacks on wireless communication are becoming increasingly prevalent, causing significant losses. Currently, wireless communication systems authenticate identities through certain data identifiers. However, this software-based data information can be forged or replicated. This article proposes the authentication of device identity using the hardware fingerprint of the terminal’s Radio Frequency (RF) components, which possesses properties of being genuine, unique, and stable, holding significant implications for wireless communication security. Through the collection and processing of raw data, extraction of various features including time-domain and frequency-domain features, and utilizing machine learning algorithms for training and constructing a legal fingerprint database, it is possible to achieve close to a 97% recognition accuracy for Fifth Generation (5G) terminals of the same model. This provides an additional and robust hardware-based security layer for 5G communication security, enhancing monitoring capability and reliability.
Namin Hou, Yuting Tang, Yushi Cheng, Xiaoyu Ji 0001
High Confid. Comput.5
2024 Adversarial robustness analysis of LiDAR-included models in autonomous driving
abstract
In autonomous driving systems, perception is pivotal, relying chiefly on sensors like LiDAR and cameras for environmental awareness. LiDAR, celebrated for its detailed depth perception, is being increasingly integrated into autonomous vehicles. In this article, we analyze the robustness of four LiDAR-included models against adversarial points under physical constraints. We first introduce an attack technique that, by simply adding a limited number of physically constrained adversarial points above a vehicle, can make the vehicle undetectable by the LiDAR-included models. Experiments reveal that adversarial points adversely affect the detection capabilities of both LiDAR-only and LiDAR-camera fusion models, with a tendency for more adversarial points to escalate attack success rates. Notably, voxel-based models are more susceptible to deception by these adversarial points. We also investigated the impact of the distance and angle of the added adversarial points on the attack success rate. Typically, the farther the victim object to be hidden and the closer to the front of the LiDAR, the higher the attack success rate. Additionally, we have experimentally proven that our generated adversarial points possess good cross-model adversarial transferability and validated the effectiveness of our proposed optimization method through ablation studies. Furthermore, we propose a new plug-and-play, model-agnostic defense method based on the concept of point smoothness. The ROC curve of this defense method shows an AUC value of approximately 0.909, demonstrating its effectiveness.
Zizhi Jin, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
High Confid. Comput.4
2024 Fast and Lightweight Voice Replay Attack Detection via Time-Frequency Spectrum Difference
abstract
Due to the open nature of voice and voice interface, an adversary can spoof voice recognition systems by replaying pre-recorded voice commands from legitimate users, known as the voice replay attack. Existing detection methods against voice replay attacks mainly rely on extra hardware to determine the sound source or require excessive computing resources to train a classifier with abundant acoustic features. In this paper, we propose Anti-Replay, a fast and lightweight detection system for voice replay attacks. To overcome the challenge of redundant classification features and complex calculation, we first investigate the time-frequency spectrum difference between the genuine human voice and the replayed audio caused by the non-linear distortion of the attacker’s microphones and speakers. Then, we design 5 types with a total of 77 features in both the time and frequency domains and propose a convolutional neural network classifier SE-ResNet50 for attack detection. Evaluations against the datasets of ASVspoof2017, ASVspoof2019, and ASVspoof2021 demonstrate that Anti-Replay can achieve an average equal error rate (EER) of 1.36% across three datasets. Meanwhile, Anti-Replay decreases the training time by 52.3% and 90.2% and decreases the model size by 83.5% and 99.9% compared with the baseline model CQCC-GMM and the state-of-the-art method Res2Net. We have also confirmed that our system is effective in detecting the adaptive replay attack.
He Ruiwen, Yushi Cheng, Zhicong Zheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Internet Things J.4
2024 Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial Ultrasound
abstract
Automatic Speaker Recognition Systems (SRSs) have been widely used in voice applications for personal identification and access control. A typical SRS consists of three stages, i.e., training, enrollment, and recognition. Previous work has revealed that SRSs can be bypassed by backdoor attacks at the training stage or by adversarial example attacks at the recognition stage. In this paper, we propose TUNER, a new type of backdoor attack against the enrollment stage of SRS via adversarial ultrasound modulation, which is inaudible, synchronization-free, content-independent, and black-box. Our key idea is to first inject the backdoor into the SRS with modulated ultrasound when a legitimate user initiates the enrollment, and afterward, the polluted SRS will grant access to both the legitimate user and the adversary with high confidence. Our attack faces a major challenge of unpredictable user articulation at the enrollment stage. To overcome this challenge, we generate the ultrasonic backdoor by augmenting the optimization process with random speech content, vocalizing time, and volume of the user. Furthermore, to achieve real-world robustness, we improve the ultrasonic signal over traditional methods using sparse frequency points, pre-compensation, and single-sideband (SSB) modulation. We extensively evaluate TUNER on two common datasets and seven representative SRS models, as well as its robustness against seven kinds of defenses. Results show that our attack can successfully bypass speaker recognition systems while remaining effective to various speakers, speech content, etc. To mitigate this newly discovered threat, we also provide discussions on potential countermeasures, limitations, and future works of this new threat.
Xinfeng Li, Junning Ze, Chen Yan 0001, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Internet Things J.5
2024 Toward Pitch-Insensitive Speaker Verification via Soundfield
abstract
Automatic speaker verification systems (ASVs) verify a person’s identity by his/her voice and have been widely deployed for user authentication. However, existing ASVs are based on traditional audio spectral features and hence, perform poorly in verifying pitch-changed utterances from speakers with cold or sore throat. In this article, we propose soundfield tracker(SOFTER), a soundfield-based speaker verification system that can verify speakers regardless of the pitch changes.SOFTERis based on the observation that soundfield features reflect the speaker’s vocal tract, mouth, head, torso, etc., which are less affected by the pitch changes in speech signals.SOFTERcan be integrated into off-the-shelf smartphones without any hardware modifications. One major challenge is that the soundfield is sensitive to the distance between the speaker and the phone. To solve this problem, we propose a two-stage mechanism combining distance sensing and soundfield reconstruction, which enables to reconstruct the soundfield to a setting similar to the one in the enrollment phase, thus, the speaker can be verified from any distance to the phone. We compareSOFTERwith six state-of-the-art academic and commercial ASVs on two data sets of 134 speakers and 31000 speech samples. Results show thatSOFTERhas an equal error rate (EER) of 2.18% and 1.61% on the two data sets, respectively. Moreover,SOFTERoutperforms other ASVs by at least 24.67% on average in verifying pitch-varying or pathological speech samples, denoting an evidence ofSOFTER’s effectiveness in both normal and unhealthy user conditions.
Xinfeng Li, Zhicong Zheng, Chen Yan 0001, Chaohao Li, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Internet Things J.5
2024 Adversarial Computer Vision via Acoustic Manipulation of Camera Sensors
abstract
Autonomous vehicles increasingly rely on camera-based computer vision systems to perceive environments and make critical driving decisions. To improve image quality, image stabilizers with inertial sensors are added to reduce image blurring caused by camera jitters. However, this trend creates a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of emerging image stabilizer hardware susceptible to acoustic manipulation and computer vision algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even when the camera is stable. These blurred images can induce object misclassification, affecting safety-critical decision-making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks: hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against five object detectors (YOLO V3/V4/V5, Faster R-CNN, and Apollo) and two lane detectors (UFLD and LaneAF). We further introduce the concept ofAMpLeattacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware.
Yushi Cheng, Xiaoyu Ji 0001, Kevin Fu, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Scoring Metrics of Assessing Voiceprint Distinctiveness Based on Speech Content and Rate
abstract
A voiceprint is the distinctive pattern of human voices widely used for authentication in voice assistants. This paper investigates the impact of speech contents and speech rates on the distinctiveness of voiceprint, and has obtained answers to three questions by studying 2457 speakers and 21,500,000 test samples: 1) What are the influential factors that users can control to affect the distinctiveness of voiceprints? 2) How to quantify the distinctiveness for given speeches, e.g., the speech of wake-up words when activating voice assistants? 3) How to help users select wake-up words and adjust the speech rate to improve distinctiveness levels? To answer those questions, we break down speeches into phones, and experimentally obtain the correlation between false recognition rates and the richness, order, length, and elements of the phones. Then, we define the PROLE Score that can reflect the voice distinctiveness, and evaluate 30 wake-up words of 19 commercial voice assistant products to provide recommendations on selecting secure voiceprint words. We also measure the correlation between false recognition rates and speech rates, and define the TER Score that reveals the distance of distinctiveness from the secure voiceprint, and it guides users to adjust their speech rate to a secure value.
He Ruiwen, Yushi Cheng, Junning Ze, Xinfeng Li, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.5
2024 Marionette: Manipulate Your Touchscreen via a Charging Cable
abstract
The security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. This paper presentsMarionette, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables and can manipulate the victim's devices with undesired consequences, e.g., establishing malicious Bluetooth connections. Our study provides a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various USB data blockers and power adapters. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affecting the touch measurement mechanism and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks, i.e., injection, alteration, and Denial-of-Service, and the evaluation of 12 commercial electronics, 6 power adapters, and 13 charging cables demonstrate the feasibility ofMarionette.
Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.2
2024 CapSpeaker: Injecting Commands to Voice Assistants Via Capacitors
abstract
Recent studies have exposed that voice assistants can be manipulated by various voice commands without being noticed, however, existing attacks require a nearby speaker to play the attack commands. In this paper, we demonstrate that even without a speaker, we can use capacitors inside electronic devices to produce malicious voice commands, i.e., we convert capacitors into speakers and call itCapSpeaker. The underlying principle ofCapSpeakeris the inverse piezoelectric effect, i.e., varying the voltage across a capacitor to make it vibrate and thus emit acoustic noises. Forcing capacitors to emit target voice commands is challenging because (1) capacitors' response frequency is out of the range of audible voices. (2) We can not directly control the voltage across capacitors to manipulate their emit sounds. To overcome these challenges, we propose a PWM-based modulation scheme to embed the malicious audio onto a high-frequency carrier, e.g., above 20 kHz, and we create malware to induce the designed voltage across the capacitors such thatCapSpeakerplays the chosen malicious commands. Our evaluation of 7 commercial devices demonstrates thatCapSpeakeris feasible to inject voice commands, e.g., ”open the door”, at a distance of up to 10.5 cm.
Xiaoyu Ji 0001, Juchuan Zhang, Yancheng Jiang, Shui Jiang, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Analyzing and Defending GhostTouch Attack Against Capacitive Touchscreens
abstract
Capacitive touchscreens have become the primary human-machine interface for personal devices such as smartphones and tablets. In this paper, we presentGhostTouch, the first active contactless attack against capacitive touchscreens.GhostTouchuses electromagnetic interference (EMI) to inject fake touch points into a touchscreen without the requirement to physically touch it. By tuning the parameters of the electromagnetic signal and adjusting the antenna, we can inject two types of basic touch events, taps and swipes, into targeted locations of the touchscreen and control them to manipulate the underlying device. We successfully launch theGhostTouchattacks on nine smartphone models. We can inject targeted taps continuously with a standard deviation of as low as$14.6 \times 19.2$pixels from the target area, and a distance of up to$40mm$. We show the real-world impact of theGhostTouchattacks in a few proof-of-concept scenarios, including pressing the button, answering an eavesdropping phone call, and swiping up to unlock. Finally, we propose touchscreen reinforcement and attack detection mechanisms to mitigate the threat ofGhostTouchattack.
Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.4
2024 On Tracing Screen Photos - A Moiré Pattern-Based Approach
abstract
Cyber-theft of trade secrets has become a serious business threat. Digital watermarking is a popular technique to help identify the source of the file leakage, whereby a unique watermark for each insider is hidden in sensitive files. However, malicious insiders may use smartphones to photograph the secret file displayed on screens to remove the embedded hidden digital watermarks due to the optical noises introduced during photographing. To identify the leakage source despite suchscreen-photo-based leakage attacks, we leverage Moiré pattern, an optical phenomenon resulted from the optical interaction between electronic screens and cameras. As such, we presentmID, a new watermark-like technique that can create a carefully crafted Moiré pattern on the photo when it is taken towards the screen. We design patterns that appear to be natural yet can be linked to the identity of the leaker. We implementedmIDand evaluated it with 7 display devices and 6 smartphones from various manufacturers and models. The results demonstrate thatmIDcan achieve an average bit error rate (BER) of$0.2\%$and can successfully identify an ID with an average accuracy of$98\%$, with little influence from the type of display devices, cameras, IDs, and ambient lights.
Wenyuan Xu 0001, Yushi Cheng, Xiaoyu Ji 0001, Yi-Chao Chen 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Dr. Defender: Proactive Detection of Autopilot Drones Based on CSI
abstract
The market for consumer drones is growing and drones are becoming ever more pervasive than before in our life. However, drones have also brought about severe privacy violations and even safety issues. Especially, drones with cameras can snap pictures or take private videos. Researchers have designed drone detection mechanisms by passively inspecting the radio frequency (RF) signal in the communication channel between a drone and its controller. However, passive detection solutions shall fail when drones are in autopilot mode without control signals from controllers. In this paper, we seek to detect autopilot drones that transmit no RF signals by developing a proactive detection system named Dr. Defender. To this end, we resort to the Wi-Fi signals prevalent at each house and propose a proactive drone detection mechanism. To facilitate the detection of drones with Wi-Fi, we first study the motion characteristics of drones, including the shifting, moving, and spinning of propellers that can uniquely represent a drone. Then we investigate the physical layer information of Wi-Fi signals, i.e., the channel state information (CSI), to reveal specific motions of a drone. Finally, we implement our CSI-based proactive drone detection system, which requires no signal transmission from a drone or its controller. We extensively validate the feasibility and performance of our solution under different distances and directions of drones relative to a window. Results show that Dr. Defender can accurately detect drones 10 meters away.
Jiangyi Deng, Xiaoyu Ji 0001, Beibei Wang 0001, Bin Wang 0062, Wenyuan Xu 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Watch Your Speed: Injecting Malicious Voice Commands via Time-Scale Modification
abstract
Existing adversarial example (AE) attacks against automatic speech recognition (ASR) systems focus on adding deliberate noises to input audio. In this paper, we propose a new attack that purely speeds up or slows down original audio instead of adding perturbations, and we call it Time-Scale Modification Adversarial Example (TSMAE). By investigating the impact of speed variation on 100, 000 pieces of audio clips, we found that misrecognition manifests in three categories: delete, substitution, and insertion. These are the accumulated results caused by the misrecognition of both the acoustic and language models inside an ASR system. Despite the challenges, i.e., ASR systems are typically black-box and reveal no gradient information, we managed to launch one-segment untargeted and targetedTSMAEattacks based on particle swarm optimization algorithms. Our untargeted attacks only require modifying the speed of one segment (e.g., 20 ms), and our targeted attacks can generate meaningful yet benign audio to cause an ASR system to output a malicious output, e.g., “open the door”. We validate the feasibility ofTSMAEon two open-source ASR models (e.g., DeepSpeech and Sphinx) and four commercial ones (e.g., IBM, Google, Baidu, and iFLYTEK). Results show that our untargeted attack can successfully attack all 6 ASR models with one segment modification, and our targeted attack is robust to various factors, such as model versions and speech sources. Finally, both attacks can bypass existing open-source defense methods, and our insights call attention to the defense’s focus from coping with perturbation to emerging adversarial example attacks.
Xiaoyu Ji 0001, Qinhong Jiang, Chaohao Li, Zhuoyang Shi, Wenyuan Xu 0001
IEEE Trans. Inf. Forensics Secur.1
2024 MagView++: Data Exfiltration via CPU Magnetic Signals Under Video Decoding
abstract
Air-gapped networks achieve security by using physical isolation to keep the computers and network from the Internet. However, magnetic covert channels based on CPU utilization have been proposed to help secret data to exfiltrate from the Faraday-cage and the air gap. Despite the success of such covert channels, they suffer from the high risk of being detected by the transmitter computer and the challenge of installing malware into such a computer. In this article, we proposeMagView++, where sensitive information is embedded in other data such as video and can be transmitted over the internal network. When any computer uses the data such as playing the video, the sensitive information will leak through the magnetic signals. The “separation” of information embedding and leaking, combined with the fact that the data can be exfiltrated from any computer in a distributed manner, overcomes these limitations. We demonstrate that CPU utilization for video decoding can be effectively controlled by changing the video frame type, reducing the quantization parameter, and changing the timestamp of the frame, without video quality degradation. We prototypeMagView++and achieve 8.9 bps throughput with 0.0057 BER when using a smartphone as the receiver, and 59 bps throughput with 0.0025 BER when using a dedicated devices with high sampling rate as the receiver. Experiments under various environments are conducted to show the robustness ofMagView++. Limitations and possible countermeasures are also discussed.
Xiaoyu Ji 0001, Juchuan Zhang, Shan Zou, Yi-Chao Chen 0001, Gang Qu 0001, Wenyuan Xu 0001
IEEE Trans. Mob. Comput.1
2024 Evaluating Compressive Sensing on the Security of Computer Vision Systems
abstract
The rising demand for utilizing fine-grained data in deep-learning (DL) based intelligent systems presents challenges for the collection and transmission abilities of real-world devices. Deep compressive sensing, which employs deep learning algorithms to compress signals at the sensing stage and reconstruct them with high quality at the receiving stage, provides a state-of-the-art solution for the problem of large-scale fine-grained data. However, recent works have proven that fatal security flaws exist in current deep learning methods and such instability is universal for DL-based image reconstruction methods. In this article, we assess the security risks introduced by deep compressive sensing in the widely used computer vision system in the face of adversarial example attacks and poisoning attacks. To implement the security inspection in an unbiased and complete manner, we develop a comprehensive methodology and a set of evaluation metrics to manage all potential combinations of attack methods, datasets (application scenarios), categories of deep compressive sensing models, and image classifiers. The results demonstrate that deep compressive sensing models unknown to adversaries can protect the computer vision system from adversarial example attacks and poisoning attacks, whereas the ones exposed to adversaries can cause the system to become more vulnerable.
Yushi Cheng, Yanjiao Chen, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
ACM Trans. Sens. Networks5
2024 Ultrasound Communication Using the Nonlinearity Effect of Microphone Circuits in Smart Devices
abstract
Acoustic communication has become a research focus without requiring extra hardware and facilitates numerous near-field applications such as mobile payment. To communicate, existing researchers use either an audible frequency band or an inaudible one. The former gains a high throughput but endures being audible, which can be annoying to users. The latter, although inaudible, falls short in throughput due to the available (near) ultrasonic bandwidth. In this article, we achieve both high speed and inaudibility for acoustic communication by utilizing the nonlinearity effect on microphones. We theoretically prove the maximum throughput of inaudible acoustic communication by modulating an audible signal onto an ultrasonic band. Then, we design and implementUltraComm, which utilizes a specially designed OFDM scheme. The scheme takes into account the characteristics of the nonlinear speaker-to-microphone channel, aiming to mitigate the effects of signal distortion. We evaluateUltraCommon different mobile devices and achieve throughput as high as 16.24 kbps.
Xiaoyu Ji 0001, Donglian Qi, Wenyuan Xu 0001
ACM Trans. Sens. Networks2
2024 Detecting Hidden Voice Recorders via ADC Electromagnetic Radiation
abstract
Unauthorized covert voice recording presents a significant threat to privacy-sensitive scenarios, such as confidential meetings and private conversations. Due to their miniaturization and disguise characteristics, hidden voice recorders are difficult to notice. In this article, we present DeHiREC , the first proof-of-concept system capable of detecting offline hidden voice recorders from their electromagnetic radiations (EMR). We first characterize the unique patterns of the emanated EMR signals and then locate the EMR source, i.e., the analog-to-digital converter module embedded in the mixed signal system-on-chips. Since these unintentional EMR signals can be extremely noisy and weak, accurately detecting them can be challenging. To address this challenge, we design an EMR Catalyzing method to actively stimulate the EMR signals and then employ an adaptive-folding algorithm to improve the signal-to-noise ratio of the sensed EMRs. We evaluate the performance of DeHiREC on 18 commercial voice recorders under various impacts, including interference from other devices. Experimental results reveal that DeHiREC is effective in detecting all 18 voice recorders and achieves an overall success rate of 94.72% and a recall rate of 92.03% at a distance of 0.2 m.
Ruochen Zhou, Xiaoyu Ji 0001, Chen Yan 0001, Wenyuan Xu 0001
ACM Trans. Sens. Networks2
2023 MicPro: Microphone-based Voice Privacy Protection
abstract
Hundreds of hours of audios are recorded and transmitted over the Internet for voice interactions such as virtual calls or speech recognitions. As these recordings are uploaded, embedded biometric information, i.e., voiceprints, is unnecessarily exposed. This paper proposes the first privacy-enhanced microphone module (i.e., MicPro) that can produce anonymous audio recordings with biometric information suppressed while preserving speech quality for human perception or linguistic content for speech recognition. Limited by the hardware capabilities of microphone modules, previous works that modify recording at the software level are inapplicable. To achieve anonymity in this scenario, MicPro transforms formants, which are distinct for each person due to the unique physiological structure of the vocal organs, and formant transformations are done by modifying the linear spectrum frequencies (LSFs) provided by a popular codec (i.e., CELP) in low-latency communications.
Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Zhicong Zheng, Wenyuan Xu 0001
CCS2
2023 The Silent Manipulator: A Practical and Inaudible Backdoor Attack against Speech Recognition Systems
abstract
Backdoor Attacks have been shown to pose significant threats to automatic speech recognition systems (ASRs). Existing success largely assumes backdoor triggering in the digital domain, or the victim will not notice the presence of triggering sounds in the physical domain. However, in practical victim-present scenarios, the over-the-air distortion of the backdoor trigger and the victim awareness raised by its audibility may invalidate such attacks. In this paper, we propose SMA, an inaudible grey-box backdoor attack that can be generalized to real-world scenarios where victims are present by exploiting both the vulnerability of microphones and neural networks. Specifically, we utilize the nonlinear effects of microphones to inject an inaudible ultrasonic trigger. To accurately characterize the microphone response to the crafted ultrasound, we construct a novel nonlinear transfer function for effective optimization. We also design optimization objectives to ensure triggers' robustness in the physical world and transferability on unseen ASR models. In practice, SMA can bypass the microphone's built-in filters and human perception, activating the implanted trigger in the ASRs inaudibly, regardless of whether the user is speaking. Extensive experiments show that the attack success rate of SMA can reach nearly 100% in the digital domain and over 85% against most microphones in the physical domains by only poisoning about 0.5% of the training audio dataset. Moreover, our attack can resist typical defense countermeasures to backdoor attacks.
Zhicong Zheng, Xinfeng Li, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
ACM Multimedia4
2023 BitDance: Manipulating UART Serial Communication with IEMI
abstract
Wired serial communication protocols such as UART are widely used in today’s IoT systems for their simple connection and good industry ecology. However, due to the simplicity of these protocols, they are vulnerable to attacks that falsify the communication. In this work, we propose the BitDance attack that can arbitrarily flip the bits of serial communication without any physical contact utilizing intentional electromagnetic interference (IEMI). We describe the physical process of how electromagnetic interference influences the voltage, build up a model to demonstrate the bit-level control principle of our work, and implement the attack on 6 different sensors with UART, a widely used serial communication protocol. The result shows we can inject bit-level information and disable legitimate communication from the system with a maximum success rate of 45.4 and 100. Finally, we propose countermeasures to mitigate the impact of this attack.
Zhixin Xie, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
RAID3
2023 LeakThief: Stealing the Behavior Information of Laptop via Leakage Current
abstract
Smart devices are proliferating in every aspect of our lives, providing convenience but also exposing us to the risk of information leakage at any moment. Attackers can monitor the user and infer private information such as the personality and preferences by stealing the behavior information. In this paper, we investigated the potential threat of information stealing via the leakage current of laptop and electrodes in wearable devices (e.g. smart watches and bracelets). Specifically, the leakage current in the laptop adapter can flow from the metal casing into the human body and be collected by electrodes in wearable devices when the user is using a laptop with a metal casing (e.g. MacBook). We verified the correlation between leakage current and working states of the laptop, where different operations corresponding to different CPU instructions can generate different leakage currents. Based on this, we propose LeakThief, the system consists of three components, leakage current detection, application operation detection and application recognition. The experiments in real-world environment demonstrated that the proposed system is able to recognize 10 common applications with high accuracy, including launching-based (97.5%) and in-application operation-based recognition (83.8%).
Dian Ding, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Guangtao Xue
SECON3
2023 AUDIOSENSE: Leveraging Current to Acoustic Channel to Detect Appliances at Single-Point
abstract
Over the past years, smart ecology has attracted much attention, especially for smart home applications. As a key component, monitoring appliances performs significant impact. However, appliances under monitoring usually contain smart modules such as WiFi or Bluetooth, which are limited to traditional appliances. Existing approaches such as distributed sensing, energy disaggregation, and infrastructure-mediated sensing, require the installation of external hardware or have a limited sensing range. In this study, we developed AUDIOSENSE to leverage the acoustic signal generated by the power supply to monitor electrical appliances throughout the house remotely from a single point. In realizing AUDIOSENSE, we proposed an optimized Variation Mode Decomposition scheme to extract the frequency components, as well as a data augmentation scheme to improve generalizability and enable multi-label classification. In experiments, AUDIOSENSE achieved mAP values of 99.3% in multi-label classification.
Yijie Li 0002, Xiatong Tong, Qianfei Ren, Lanqing Yang, Yi-Chao Chen 0001, Guangtao Xue, Xiaoyu Ji 0001, Jiadi Yu
SECON8
2023 PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous Vehicle
abstract
Autonomous vehicles and robots increasingly exploit LiDAR-based 3D object detection systems to detect obstacles in environment. Correct detection and classification are important to ensure safe driving. Though existing work has demonstrated the feasibility of manipulating point clouds to spoof 3D object detectors, most of the attempts are conducted digitally. In this paper, we investigate the possibility of physically fooling LiDAR-based 3D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, which is 20 times more than prior work, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We also discuss defense strategies at the sensor and AV system levels.
Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001
SP2
2023 Volttack: Control IoT Devices by Manipulating Power Supply Voltage
abstract
This paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing and actuating. Particularly, we discover a vulnerability in power supply modules and propose Volttack attacks. To launch a Volttack attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Eventually, Volttack attacks may cause the sensor measurement irrelevant to reality or maneuver the actuator in a way disregarding the desired command. To understand Volttack, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensor or actuator modules. Derived from these findings, we implement and validate Volttack on off-the-shelf products: 6 sensors and 3 actuators, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The consequences of manipulating the sensor measurement or actuation include doubled car braking distance and a natural gas leak. The root cause of such a vulnerability stems from the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks.
Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Wenyuan Xu 0001
SP3
2023 DepthFake: Spoofing 3D Face Authentication with a 2D Photo
abstract
Face authentication has been widely used in access control, and the latest 3D face authentication systems employ 3D liveness detection techniques to cope with the photo replay attacks, whereby an attacker uses a 2D photo to bypass the authentication. In this paper, we analyze the security of 3D liveness detection systems that utilize structured light depth cameras and discover a new attack surface against 3D face authentication systems. We propose DepthFake attacks that can spoof a 3D face authentication using only one single 2D photo. To achieve this goal, DepthFake first estimates the 3D depth information of a target victim’s face from his 2D photo. Then, DepthFake projects the carefully-crafted scatter patterns embedded with the face depth information, in order to empower the 2D photo with 3D authentication properties. We overcome a collection of practical challenges, e.g., depth estimation errors from 2D photos, depth images forgery based on structured light, the alignment of the RGB image and depth images for a face, and implemented DepthFake in laboratory setups. We validated DepthFake on 3 commercial face authentication systems (i.e., Tencent Cloud, Baidu Cloud, and 3DiVi) and one commercial access control device. The results over 50 users demonstrate that DepthFake achieves an overall Depth attack success rate of 79.4% and RGB-D attack success rate of 59.4% in the real world.
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
SP4
2023 DeHiREC: Detecting Hidden Voice Recorders via ADC Electromagnetic Radiation
abstract
Unauthorized covert voice recording brings a remarkable threat to privacy-sensitive scenarios, such as confidential meetings and private conversations. Due to the miniaturization and disguise characteristics, hidden voice recorders are difficult to be noticed in their surroundings. In this paper, we present DeHiREC, the first proof-of-concept system that can detect offline hidden voice recorders from their electromagnetic radiations (EMR). We first characterize the unique patterns of the emanated EMR signals and then locate the EMR source, i.e., the analog-to-digital converter (ADC) module embedded in the mixed signal system-on-chips (MSoCs). Since these unintentional EMR signals can be extremely noisy and weak, accurately detecting them can be challenging. To address this challenge, we first design an EMR Catalyzing method to stimulate the EMR signals actively and then employ an adaptive-folding algorithm to improve the signal-to-noise ratio (SNR) of the sensed EMRs. Once the sensed EMR variation corresponds to our active stimulation, we can determine that there exists a hidden voice recorder. We evaluate the performance of DeHiREC on 13 commercial voice recorders under various impacts, including interference from other devices. Experimental results reveal that DeHiREC is effective in detecting all 13 voice recorders and achieves an overall success rate of 92.17% and a recall rate of 86.14% at a distance of 0.2 m.
Ruochen Zhou, Xiaoyu Ji 0001, Chen Yan 0001, Yi-Chao Chen 0001, Wenyuan Xu 0001, Chaohao Li
SP2
2023 GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMI
Qinhong Jiang, Xiaoyu Ji 0001, Chen Yan 0001, Zhixin Xie, Haina Lou, Wenyuan Xu 0001
USENIX Security Symposium2
2023 Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice Attacks
Xinfeng Li, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Zhenning Zhang, Wenyuan Xu 0001
USENIX Security Symposium2
2023 Remote Attacks on Speech Recognition Systems Using Sound from Power Supply
Lanqing Yang, Xinqi Chen, Xiangyong Jian, Leping Yang, Yijie Li 0002, Qianfei Ren, Yi-Chao Chen 0001, Guangtao Xue, Xiaoyu Ji 0001
USENIX Security Symposium9
2023 CAPatch: Physical Adversarial Patch against Image Captioning Systems
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
USENIX Security Symposium4
2023 TPatch: A Triggered Physical Adversarial Patch
Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001
USENIX Security Symposium2
2023 No Seeing is Also Believing: Electromagnetic-Emission-Based Application Guessing Attacks via Smartphones
abstract
Mobile devices have emerged as the most popular platforms to access information. However, they have also become a major concern of privacy violation and previous researches have demonstrated various approaches to infer user privacy based on mobile devices. In this paper, we study the electromagnetic (EM) emission of a laptop that could be harvested by a commercial-off-the-shelf (COTS) mobile device, e.g., a smartphone. We proposeMagAttack, which exploits the electromagnetic side channel of a laptop to guess user activities, i.e., application launching and application operation. The key insight ofMagAttackis that applications are discrepant in essence due to the different compositions of instructions, which can be reflected on the CPU power consumption, and thus the corresponding EM emissions.MagAttackis challenging since that EM signals are noisy due to the dynamics of applications and the limited sampling rate of the built-in magnetometers in COTS mobile devices. We overcome these challenges and convert noisy coarse-grained EM signals to robust fine-grained features. We implementMagAttackon both an iOS and an Android smartphone without any hardware modification, and evaluate its performance with 30 popular applications, 30 YouTube videos, and 50 top websites in China. The results demonstrate thatMagAttackcan recognize aforementioned 30 applications with an average accuracy of 98.6 percent, and identify which video out of the 30 candidates being played with an average accuracy of 97.5 percent and visiting which website among the 50 candidates with an average accuracy of 90.4 percent.
Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001, Yuehan Chi, Hao Pan 0003, Zhuangdi Zhu, Chuang-Wen You, Yi-Chao Chen 0001, Lili Qiu
IEEE Trans. Mob. Comput.1
2023 MagneComm+: Near-Field Electromagnetic Induction Communication With Magnetometer
abstract
Near-field communication (NFC) technology emerges as a vital role with appealing benefits for users to improve mobile device’s functionality. Although today’s most smartphones and smartwatches come with NFC support, other mobile devices (e.g., PC and laptops) and IoT devices that don’t equip with dedicated radio modules cannot take advantage of wide-scale NFC capability. We design and developMagneComm+, an NFC-like implementation scheme without dedicated hardware and propose a novel near-field communication protocol that is applicable to almost all mobile devices and IoT devices. The key idea is to utilize the electromagnetic induction (EMI) signal emitted from the computing devices (e.g., CPUs) and captured by magnetometers on mobile devices for communication. We tackle challenges indata encoding/decoding,preamble detection,retransmission and error correction,multi-transmitter, andfull-duplexschemes, to efficiently generate and reliably receive EMI signal with the hardware available on devices. We prototypeMagneComm+on both between laptops and smartphones, as well as between two laptops with an external magnetometer. Extensive evaluation results show that ourMagneComm+supports around$10~cm$10cmcommunication distance with average110 bps(bit per second) data rate on the normal-speed mode, and maximum17.28 kbpson the full-speed mode.
Guangtao Xue, Hao Pan 0003, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Jiadi Yu
IEEE Trans. Mob. Comput.4
2023 ScreenID: Enhancing QRCode Security by Utilizing Screen Dimming Feature
abstract
Quick response (QR) codes have been widely used in mobile applications, especially mobile payments, such as Alipay, WeChat, PayPal, etc due to their convenience and the pervasive built-in cameras on smartphones. Recently, however, attacks against QR codes have been reported and attackers can capture a QR code of the victim and replay it to achieve a fraudulent transaction or intercept private information, just before the original QR code is scanned. In this study, we enhance the security of a QR code by identifying its authenticity. We propose ScreenID, which embeds a QR code with information of the screen which displays it, thereby the QR code can reveal whether it is reproduced by an adversary or not. In ScreenID, PWM frequency of screens is exploited as the unique screen fingerprint. To improve the estimation accuracy of PWM frequency, ScreenID incorporates a model for the interaction between the camera and screen in the temporal and spatial domains. Extensive experiments demonstrate that ScreenID can differentiate screens of different models, types, and manufacturers and thus improve the security of QR codes.
Guangtao Xue, Yijie Li 0002, Hao Pan 0003, Lanqing Yang, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Jiadi Yu
IEEE/ACM Trans. Netw.6
2023 PDGes: An Interpretable Detection Model for Parkinson's Disease Using Smartphones
abstract
Parkinson’s disease (PD) is a neurodegenerative disorder that severely affects the motor system of patients. Early PD detection will greatly improve the quality of lives. However, existing automatic PD detection systems either rely on customized sensors or require users to perform special activities, using machine learning models whose prediction process is not understandable by medical professionals. In this article, we develop a non-disruptive PD detection system on smartphones based on interpretable prediction models. We design an application named PDGes to passively collect touchscreen and Inertial Measurement Unit data of users’ tapping and swiping actions on smartphones. Meaningful features that reflect finger dexterity , tremor , stiffness , and hand movement are extracted to build the prediction model. To better comprehend the decisions made by the model, we conduct a systematic analysis of feature importance to help validate the conformity of the model with clinical PD diagnosis. We collected data from 108 volunteers to evaluate the performance of PDGes . The experiment results show that PDGes achieves a detection accuracy of more than 94.5% on different smartphones.
Yanjiao Chen, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ACM Trans. Sens. Networks3
2022 G-PPG: A Gesture-related PPG-based Two-Factor Authentication for Wearable Devices
abstract
Verifying the user identity of wearable devices is crucial for system security, especially before sensitive operations like making financial payments. A PPG-based two-factor authentication can be a promising solution with widely deployed PPG (Photoplethysmography) sensors within wearable devices. Our observations find PPG readings reveal a significant relevance to the user’s hand motions, i.e., gestures, while the user’s heartbeat characteristics and wearing habits are also implicitly related, which can be utilized for user authentication. In this paper, we design G-PPG, a gesture-related PPG-based two-factor authentication mechanism that can non-intrusively validate the user’s identity. In G-PPG, gesture detection and segmentation and a specific feature set are proposed for accurate gesture-related PPG characteristic extraction. Moreover, an adaptive update scheme is proposed for the high accuracy of long-term authentication. Our experiments among 15 participants demonstrate that G-PPG can achieve a 90% accuracy in the long-term study.
Zenan Zhang, Xiaoyu Ji 0001, Haiming Chen 0002
ICPADS4
2022 UltraBD: Backdoor Attack against Automatic Speaker Verification Systems via Adversarial Ultrasound
abstract
Automatic speaker verification (ASV) systems have been widely applied in voice user interfaces to conduct person identification and access control via voiceprints. A typical ASV system consists of three stages, i.e., training, enrollment, and verification. Previous work has revealed that the ASV system can be bypassed at the training stage by backdoor attacks and at the verification stage by adversarial example attacks. In this paper, we propose a new type of backdoor attack aimed at the enrollment stage via adversarial ultrasound, named UltraBD, which is highly imperceptible, synchronization-free, and content-independent. By simultaneously injecting the ultrasound backdoor examples when the legitimate user initiates the enrollment, the polluted voiceprints stored in the ASV systems grant access to both the legitimate user and the adversary with relatively high confidence. Despite the challenges, i.e., when, what, and how the legitimate user articulates at the enrollment stage can be remarkably unpredictable and various, we managed to launch UltraBD by augmenting the generation and optimization process of the ultrasound backdoor examples with the randomness of synchronous time and relative amplitude ratio. Furthermore, we optimize the modulation mechanism of adversarial ultrasound by tuning the baseband signal on limited signal frequency points to improve its robustness in the physical world setting. We validate UltraBD on two common datasets together with two open-source ASV models. Results show that UltraBD can be robust to various configurations, e.g., different speakers and utterance content. In sum, our attack calls attention to a new attack surface of ASV systems and sheds light on its fundamental mechanisms.
Junning Ze, Xinfeng Li, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICPADS4
2022 OutletGuarder: Detecting DarkSide Ransomware by Power Factor Correction Signals in an Electrical Outlet
abstract
Ransomware is a kind of computer malware that has spread widely in recent years, such as DarkSide, which spread around the world recently. It’s reported that DarkSide extorted ${\$}$ 90 million in nine months. It extorts ransom from users by encrypting user files and other methods, causing huge economic losses to users, including commercial organizations and individuals. Existing ransomware detection methods include the hostbased methods and the network-based methods. However, these methods are either hard to deploy or have the possibility to be evaded. In this paper, we propose OutletGuarder, a non-intrusive detection method against DarkSide ransomware based on the signal generated by the Power Factor Correction module of the host computer’s power supply in electrical outlets, which carries the power consumption information of the host computer during the execution of DarkSide. By utilizing the power consumption variation among different programs, especially the power consumption caused by frequent encryption and I/O operations during the execution of DarkSide, OutletGuarder achieves a detection F1 Score of 97.50%. The impact of classification models and untrained programs, as well as the model transferability and robustness are evaluated.
Shan Zou, Juchuan Zhang, Shui Jiang, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICPADS5
2022 DoCam: depth sensing with an optical image stabilization supported RGB camera
abstract
Optical image stabilizers (OIS) are widely used in digital cameras to counteract motion blur caused by camera shakes in capturing videos and photos. In this paper, we sought to expand the applicability of the lens-shift OIS technology for metric depth estimation, i.e., let a RGB camera to achieve the similar function of a time-of-flight (ToF) camera. Instead of having to move the entire camera for depth estimation, we propose DoCam, which controls the lens motion in the OIS module to achieve 3D reconstruction. After controlling the lens motion by altering the MEMS gyroscopes readings through acoustic injection, we improve the traditional bundle adjustment algorithm by establishing additional constraints from the linearity of the lens control model for high-precision camera pose estimation. Then, we elaborate a dense depth reconstruction algorithm to compute depth maps at real-world scale from multiple captures with micro lens motion (i.e., ≤ 3 mm). Extensive experiments demonstrate that our proposed DoCam can enable a 2D color camera to estimate high-accuracy depth information of the captured scene by means of controlling lens motion in the OIS. DoCam is suitable for a variety of applications that require depth information of the scenes, especially when only a single color camera is available and located at a fixed position.
Hao Pan 0003, Feitong Tan, Yi-Chao Chen 0001, Gaoang Huang, Guangtao Xue, Lili Qiu, Xiaoyu Ji 0001
MobiCom9
2022 MagDefender: Detecting Eavesdropping on Mobile Devices using the Built-in Magnetometer
abstract
This study reveals that on-board hardware modules leak electromagnetic (EM) emissions whenever audio or camera data is accessed, and proposes Magdefender scheme that explores the possibility of using the magnetometer built into mobile devices to detect eavesdropping instances by malicious apps and even the unscrupulous phone vendors. However, the target EM signals generated by accessing multimedia data is weak and tends to be buried beneath other noisy EM signals from apps running in the foreground. It is also subject to the external interference from geomagnetic signals generated by the device movement. To cope with the challenges, we adopt a generative adversarial networks (GAN) based model to facilitate the extraction of target EM signals indicating the occurrence of eavesdropping from the overall magnetometer readings. We also develop a neural network-based classifier with triplet loss embedding to identify the EM signals from the camera and/or microphones. Empirical results demonstrate the efficacy of MagDefenderin recognizing instances of eavesdropping on cameras/microphones data, with average accuracy of 97.3% when applied to the trained devices, and average 91.5% on unseen mobile devices.
Hao Pan 0003, Feitong Tan, Yi-Chao Chen 0001, Lanqing Yang, Guangtao Xue, Xiaoyu Ji 0001
SECON7
2022 WIGHT: Wired Ghost Touch Attack on Capacitive Touchscreens
abstract
The security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. To the best of our knowledge, this paper presents WIGHT, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables, and can manipulate the victim devices with undesired consequences, e.g., allowing malicious Bluetooth connections, accepting files with viruses, etc. Our study calls for attention to a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various power adapters and even USB data blockers. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affect the touch measurement mechanism, and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks: injection attacks that create ghost touches without users touching the screen, alteration attacks that change the detected legitimate touch position, and Denial-of-Service attacks that prevent the device from identifying legitimate touches. Our evaluation on 6 smartphones, 1 tablet, 2 standalone touchscreen panels, 6 power adapters, and 13 charging cables demonstrates the feasibility of all three type attacks.
Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
SP2
2022 "OK, Siri" or "Hey, Google": Evaluating Voiceprint Distinctiveness via Content-based PROLE Score
He Ruiwen, Xiaoyu Ji 0001, Xinfeng Li, Yushi Cheng, Wenyuan Xu 0001
USENIX Security Symposium2
2022 GhostTouch: Targeted Attacks on Touchscreens without Physical Touch
Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
USENIX Security Symposium4
2022 Rolling Colors: Adversarial Laser Exploits against Traffic Light Recognition
Chen Yan 0001, Zhanyuan Yin, Xiaoyu Ji 0001, Wenyuan Xu 0001
USENIX Security Symposium4
2022 Jamming-Resilient Backup Nodes Selection for RPL-based Routing in Smart Grid AMI Networks
Taimin Zhang, Xiaoyu Ji 0001, Wenyuan Xu 0001
Mob. Networks Appl.2
2022 Multi-User Beam Training and Transmission Design for Covert Millimeter-Wave Communication
abstract
Millimeter-wave (mmWave) communication has emerged as a promising means for supporting high-rate covert communication. However, the use of antenna arrays with beamforming at mmWave requires precise beam alignment between legitimate parties, and this procedure may entail large beam training overhead and create additional signal leakage to eavesdroppers. In this work, we consider a multi-user mmWave communication system and address the problem of designing proper covert beam training and data transmission between legitimate parties Alice and Bobs, while keeping the underlying communication undetectable from warden Willie. We first propose a novel Covert Multi-user Beam Training Strategy (CMBTS) that adopts multi-finger beam codebook to reduce the probability of communication being detected and to enable simultaneous training for multiple users. With the proposed CMBTS, a joint optimization framework for covert beam training and data transmission with a friendly jammer is developed to maximize the effective covert throughput while ensuring the covertness constraint at warden is met. We further propose an algorithm that combines successive convex approximation and inexact block coordinate descent methods to solve the problem efficiently. Numerical results validate the effectiveness of the CMBTS proposed and confirm its superior performance as compared to several beam training baselines (including exhaustive and hierarchical search) tailored to the covert communication setup considered. Among them, CMBTS achieves the best successful alignment probability and the largest effective covert throughput yet with the least training overhead.
Min Li 0008, Minjian Zhao, Xiaoyu Ji 0001, Wenyuan Xu 0001
IEEE Trans. Inf. Forensics Secur.4
2022 A Nonlinearity-Based Secure Face-to-Face Device Authentication for Mobile Devices
abstract
With the proliferation of mobile devices, face-to-face device-to-device (D2D) communication has been applied to a variety of daily scenarios such as mobile payment and short distance file transfer. In D2D communications, a critical security problem is to verify the device legitimacy when they share no secrets in advance. Previous research proposed device authentication schemes based on pre-built database or exploiting physical properties. However, a remaining challenge is to secure face-to-face D2D communication even in the middle of a crowd, within which an attacker may hide. In this paper, we presentNAuth, a nonlinearity-enhanced, location-sensitive authentication mechanism. Especially, we target at the secure authentication within a limited range such as 20 cm, which is typical for face-to-face scenarios.NAuthdesigns averification schemebased on the nonlinear distortion of speaker-microphone systems and a location-basedvalidation model. The verification scheme guarantees device authentication consistency by extracting acoustic nonlinearity patterns (ANP) while the validation model ensures device legitimacy by measuring the time difference of arrival (TDOA) at two microphones. We analyze the feasibility and security ofNAuththeoretically and evaluate its performance experimentally. Results demonstrate thatNAuthcan verify the device legitimacy in the presence of nearby attackers.
Xiaoyu Ji 0001, Chen Yan 0001, Jiangyi Deng, Wenyuan Xu 0001
IEEE Trans. Mob. Comput.1
2022 Device Fingerprinting with Magnetic Induction Signals Radiated by CPU Modules
abstract
With the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally measured device fingerprints, such as device ID, software or hardware-based characteristics. In this article, we propose DeMiCPU , a stimulation-response-based device fingerprinting technique that relies on externally measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power-supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.7% precision and recall on average, and 99.8% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6~s. The performance can be further improved to 99.9% with multi-round fingerprinting. In addition, we implement a prototype of DeMiCPU docker, which can effectively reduce the requirement of test points and enlarge the fingerprinting area.
Xiaoyu Ji 0001, Yushi Cheng, Juchuan Zhang, Yuehan Chi, Wenyuan Xu 0001, Yi-Chao Chen 0001
ACM Trans. Sens. Networks1
2021 CapSpeaker: Injecting Voices to Microphones via Capacitors
abstract
Voice assistants can be manipulated by various malicious voice commands, yet existing attacks require a nearby speaker to play the attack commands. In this paper, we show that even when no speakers are available, we can play malicious commands by utilizing the capacitors inside electronic devices, i.e., we convert capacitors into speakers and call it CapSpeaker. Essentially, capacitors can emit acoustic noises due to the inverse piezoelectric effect, i.e., varying the voltage across a capacitor can make it vibrate and thus emit acoustic noises. Forcing capacitors to play malicious voice commands is challenging because (1) the frequency responses of capacitors as speakers have poor performance in the range of audible voices, and (2) we have no direct control over the voltage across capacitors to manipulate their emitting sounds. To overcome the challenges, we use a PWM-based modulation scheme to embed the malicious audio onto a high-frequency carrier, e.g., above 20 kHz, and we create malware that can induce the right voltage across the capacitors such that CapSpeaker plays the chosen malicious commands. We conducted extensive experiments with 2 LED lamps (a modified one and a commercial one) and 5 victim devices (iPhone 4s, iPad mini 5, Huawei Nova 5i, etc.). Evaluation results demonstrate that CapSpeaker is feasible at a distance up to 10.5 cm, triggering a smartphone to receive voice commands, e.g., "open the door''.
Xiaoyu Ji 0001, Juchuan Zhang, Shui Jiang, Jishen Li, Wenyuan Xu 0001
CCS1
2021 Anti-Replay: A Fast and Lightweight Voice Replay Attack Detection System
abstract
Due to the open nature of voice and voice interface, attackers can easily record the user's voice commands and spoof the voice recognition systems by replaying them. Existing voice replay attack detection methods mainly rely on extra hardware to determine the sound source or require excessively computing resources for training the classifier with a large number of acoustic features. Hence, we propose Anti-Replay, a fast and lightweight detection system for voice replay attacks. To overcome the challenge of redundant classification feature vectors and complex calculation, we first investigate the spectrum difference between live-human voice and the replayed audio caused by the non-linear distortion of the attacker's microphones and speakers and then extract 72-dimensional feature vectors. Then we employ a single deep convolutional neural network classifier (SE-ResNet50) to enhance the robustness of our classification model. Finally, we evaluate the performance of Anti-Replay on the datasets of ASVspoof2017 and ASVspoof2019. Results show that Anti-Replay can achieve an equal error rate (EER) of 2.38% and 0.82% on two datasets, respectively. Meanwhile, the training time and the model size of Anti-Replay have decreased by 56% and 84% compared with the baseline model (i.e., CQCC-GMM).
Zhuoyang Shi, Chaohao Li, Zizhi Jin, Weinong Sun, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICPADS5
2021 ScreenID: Enhancing QRCode Security by Fingerprinting Screens
abstract
Quick response (QR) codes have been widely used in mobile applications due to its convenience and the pervasive built-in cameras on smartphones. Recently, however, attacks against QR codes have been reported that attackers can capture a QR code of the victim and replay it to achieve a fraudulent transaction or intercept private information, just before the original QR code is scanned. In this study, we enhance the security of a QR code by identifying its authenticity. We propose SCREENID, which embeds a QR code with information of the screen which displays it, thereby the QR code can reveal whether it is reproduced by an adversary or not. In SCREENID, PWM frequency of screens is exploited as the unique screen fingerprint. To improve the estimation accuracy of PWM frequency, SCREENID incorporates a model for the interaction between the camera and screen in the temporal and spatial domains. Extensive experiments demonstrate that SCREENID can differentiate screens of different models, types, and manufacturers, thus improve the security of QR codes.
Yijie Li 0002, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Hao Pan 0003, Lanqing Yang, Guangtao Xue, Jiadi Yu
INFOCOM3
2021 EarArray: Defending against DolphinAttack via Acoustic Attenuation
Xiaoyu Ji 0001, Xinfeng Li, Gang Qu 0001, Wenyuan Xu 0001
NDSS2
2021 MagThief: Stealing Private App Usage Data on Mobile Devices via Built-in Magnetometer
abstract
Various characteristics of mobile applications (apps) and associated in-app services have been used reveal potentially-sensitive user information; however, privacy concerns have prompted third-party apps to rigorously restrict access to data related to mobile app usage. This paper outlines a novel approach to the extraction of detailed app usage information based on analysis of the electromagnetic (EM) signals emitted from mobile devices when executing app-related tasks. Note that this type of EM leakage becomes high-complex when multiple apps are used simultaneously and is subject to interference from geomagnetic signals generated by device movement. This paper proposes a deep learning-based multi-label classification system to identify apps and in-app services based on magnetometer readings. The proposed MAGTHIEF system uses accelerometer and gyroscope data to cancel out the offset in geomagnetic signals followed by an elaborate deep region convolution neural network (DRCNN) to differentiate among multiple apps and the corresponding inapp services. Experiments on 50 apps demonstrated the efficacy of MAGTHIEF in identifying multiple apps and in-app services, achieving high average macro F1 scores of 0.87 and 0.95, respectively. MAGTHIEF also achieved time duration accuracy of 89.5% in recognizing app trajectory in the real-world scene.
Hao Pan 0003, Lanqing Yang, Honglu Li, Chuang-Wen You, Xiaoyu Ji 0001, Yi-Chao Chen 0001, Zhenxian Hu, Guangtao Xue
SECON5
2021 Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer Vision
abstract
Autonomous vehicles increasingly exploit computer-vision-based object detection systems to perceive environments and make critical driving decisions. To increase the quality of images, image stabilizers with inertial sensors are added to alleviate image blurring caused by camera jitters. However, such a trend opens a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of the emerging image stabilizer hardware susceptible to acoustic manipulation and the object detection algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even if the camera is stable. The blurred images can then induce object misclassification affecting safety-critical decision making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks, i.e., hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against four academic object detectors (YOLO V3/V4/V5 and Fast R-CNN), and one commercial detector (Apollo). We further introduce the concept of AMpLe attacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware.
Xiaoyu Ji 0001, Yushi Cheng, Kai Wang 0073, Chen Yan 0001, Wenyuan Xu 0001, Kevin Fu
SP1
2021 mID: Tracing Screen Photos via Moiré Patterns
Yushi Cheng, Xiaoyu Ji 0001, Lixu Wang, Qi Pang, Yi-Chao Chen 0001, Wenyuan Xu 0001
USENIX Security Symposium2
2021 OutletSpy: cross-outlet application inference via power factor correction signal
abstract
Trade secrets such as intellectual properties are the inherent values for firms. Although companies have exploited strict access management policies and isolated their networks from the public Internet, trade secrets are still vulnerable to side-channel attacks. Side-channels can reveal the computing processes of computers in forms of various physical signals such as light, electromagnetism, and even heat. Such side-channels can bypass the isolation mechanism and therefore bring about severe threats. However, existing side-channels can only perform well within a short-distance (e.g., less than 1 meter) due to the high attenuation of signals. In this paper, we seek to utilize the built-in power lines in a building and construct a power side-channel that enables remote, i.e., cross-outlet attack against trade secrets. To this end, we investigate the power factor correction (PFC) module inside the power supply units of commodity computers and find that the PFC signals observed from an outlet can precisely reveal the power consumption information of all the connected devices, even from the outlets in adjacent rooms. Based upon this insight, we design and implement OutletSpy, a power side-channel attack that can infer application launching from a remote outlet and therefore enjoys the stealthiness property. We validate and evaluate OutletSpy with a dataset under different background APPs, time variations and different locations. The experiment results show OutletSpy can infer the application launching with 98.25% accuracy.
Juchuan Zhang, Xiaoyu Ji 0001, Yuehan Chi, Yi-Chao Chen 0001, Bin Wang 0062, Wenyuan Xu 0001
WISEC2
2021 Who is Charging My Phone? Identifying Wireless Chargers via Fingerprinting
abstract
With the increasing popularity of the Internet-of-Things (IoT) devices, the demand for fast and convenient battery charging services grows rapidly. Wireless charging is a promising technology for such a purpose and its usage has become ubiquitous. However, the close distance between the charger and the device being charged not only makes proximity-based and near-field communication attacks possible but also introduces a new type of vulnerabilities. In this article, we propose to create fingerprints for wireless chargers based on the intrinsic nonlinear distortion effects of the underlying charging circuit. Using such fingerprints, we design the WirelessID system to detect potential short-range malicious wireless charging attacks. WirelessID collects signals in the standby state of the charging process and sends them to a trusted server, which can extract the fingerprint and then identify the charger. We conduct experiments on eight commercial chargers over a period of five months and collect 8000 traces of signal. We use 10% of the traces as the training data set and the rest for testing. The results show that on the standard performance metrics, we have achieved 99.0% precision, 98.9% recall, and 98.9% F1 -score.
Zhiyun Wang, Xiaoyu Ji 0001, Wenyuan Xu 0001, Gang Qu 0001, Minjian Zhao
IEEE Internet Things J.3
2021 The Feasibility of Injecting Inaudible Voice Commands to Voice Assistants
abstract
Voice assistants (VAs) such as Siri and Google Now have become an increasingly popular human-machine interaction method and have made various systems voice controllable. Prior work on attacking voice assistants shows that the hidden voice commands that are incomprehensible to people can control the VAs. Hidden voice commands, though `hidden', are nonetheless audible. In this work, we design a completely inaudible attack, DolphinAttack, that modulates voice commands on ultrasonic carriers to achieve inaudibility. By leveraging the nonlinearity of the microphone circuits, the modulated low-frequency audio commands can be successfully demodulated, recovered, and more importantly interpreted by the voice assistants. We validate DolphinAttack on popular voice assistants, including Siri, Google Now, S Voice, HiVoice, Cortana, Alexa, etc. By injecting a sequence of inaudible voice commands, we show a few proof-of-concept attacks, which include activating Siri to initiate a FaceTime call on iPhone, activating Google Now to turn on the airplane mode, and even manipulating the navigation system in an Audi automobile. We propose hardware and software defense solutions. We validate that it is feasible to detect DolphinAttack by classifying the audios using supported vector machine (SVM), and suggest to re-design voice assistants to be resilient to inaudible voice command attacks.
Chen Yan 0001, Xiaoyu Ji 0001, Tianchen Zhang, Taimin Zhang, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.3
2021 SenCS: Enabling Real-time Indoor Proximity Verification via Contextual Similarity
abstract
Indoor proximity verification has become an increasingly useful primitive for the scenarios where access is granted to the previously unknown users when they enter a given area (e.g., a hotel room). Existing solutions either rely on homogeneous sensing modalities shared by two parties or require additional human interactions. In this article, we propose a context-based indoor proximity verification scheme, called SenCS, to enable real-time autonomous access for mobile devices, utilizing the available heterogeneous sensors at the user side and at the room side. The intuition is that only when the user is within a room can sensors from both sides observe the same events in the room. Yet such a solution is challenging, because the events may not provide enough entropy within the required time and the heterogeneity in sensing modalities may not always agree on the sensed events. To overcome the challenges, we exploit the time intervals between successively human actions to create heterogeneous contextual fingerprints (HCF) at a millisecond level. By comparing the contextual similarity between the HCF s from both the room and user sides, SenCS accomplishes the indoor proximity verification. Through proof-of-concept implementation and evaluations on 30 participants, SenCS achieves an accuracy of 99.77% and an equal error rate (EER) of 0.23% across various hardware configurations.
Chaohao Li, Xiaoyu Ji 0001, Bin Wang 0062, Kai Wang 0073, Wenyuan Xu 0001
ACM Trans. Sens. Networks2
2020 MagView: A Distributed Magnetic Covert Channel via Video Encoding and Decoding
abstract
Air-gapped networks achieve security by using the physical isolation to keep the computers and network from the Internet. However, magnetic covert channels based on CPU utilization have been proposed to help secret data to escape the Faraday-cage and the air-gap. Despite the success of such cover channels, they suffer from the high risk of being detected by the transmitter computer and the challenge of installing malware into such a computer. In this paper, we propose MagView, a distributed magnetic cover channel, where sensitive information is embedded in other data such as video and can be transmitted over the air-gapped internal network. When any computer uses the data such as playing the video, the sensitive information will leak through the magnetic covert channel. The "separation" of information embedding and leaking, combined with the fact that the covert channel can be created on any computer, overcomes these limitations. We demonstrate that CPU utilization for video decoding can be effectively controlled by changing the video frame type and reducing the quantization parameter without video quality degradation. We prototype MagView and achieve up to 8.9 bps throughput with BER as low as 0.0057. Experiments under different environment are conducted to show the robustness of MagView. Limitations and possible countermeasures are also discussed.
Juchuan Zhang, Xiaoyu Ji 0001, Wenyuan Xu 0001, Yi-Chao Chen 0001, Yuting Tang, Gang Qu 0001
INFOCOM2
2020 Toward a secure QR code system by fingerprinting screens
abstract
Quick response (QR) codes have been widely used in mobile applications, due to its convenience and the pervasive built-in cameras on smartphones. Recently, however, QR codes have been reported suffering attacks for being sniffed just before the QR code is scanned, which lead to financial loss. In this study, we propose ScreenID, for enhancing the QR code security by identifying its authenticity, which embeds a QR code with information of unique screen fingerprint - PWM frequency. PWM frequencies are adjusted to different values by screen manufacturers, therefore can successfully differentiate screens. To improve the estimation accuracy of PWM frequency, ScreenID incorporates a model for the interaction between the camera and screen in the temporal and spatial domains. Extensive experiments demonstrate that ScreenID can differentiate screens of different models, types and manufacturers and thus improve the security of QR codes.
Yijie Li 0002, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Hao Pan 0003, Lanqing Yang, Guangtao Xue, Jiadi Yu
MobiCom3
2020 Authenticating Smart Home Devices via Home Limited Channels
abstract
Nowadays, most Internet of Things devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks such as spoofing and eavesdropping attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this article, we design a key-free communication method for such devices in a smart home. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for outside-house attackers. Utilizing HLCs, we propose HlcAuth, a challenge-response mechanism to authenticate the communications between smart devices without keys. The advantages of HlcAuth are low cost, lightweight as well as key-free, and requiring no human intervention. According to the security analysis, HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. We further evaluate HlcAuth in four different physical scenarios, and results show that HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers, i.e., guaranteeing a high-level usability and security for in-house communications. Finally, we implement HlcAuth in both single-room and multi-room scenarios.
Xiaoyu Ji 0001, Chaohao Li, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001
ACM Trans. Internet Things1
2020 On Detecting Hidden Wireless Cameras: A Traffic Pattern-based Approach
abstract
Wireless cameras are widely deployed in surveillance systems for security guarding. However, the privacy concerns associated with unauthorized videotaping, are drawing increasing attention recently. Existing detection methods for unauthorized wireless cameras are either limited by their detection accuracy or requiring dedicated devices. In this paper, we propose DeWiCam, a lightweight and effective detection mechanism using smartphones. The basic idea of DeWiCam is to utilize the intrinsic traffic patterns of flows from wireless cameras. Compared with traditional traffic pattern analysis, DeWiCam is more challenging because it cannot access the encrypted information in the data packets. Yet, DeWiCam overcomes the difficulty and can detect nearby wireless cameras reliably. To further identify whether a camera is in an interested room, we propose a human-assisted identification model. Extension functions of DeWiCam further enable the video resolution and audio channel inference to provide extra protection. We implemented DeWiCam on the Android platform and evaluated it with extensive experiments on 20 cameras. The evaluation results show that DeWiCam can detect cameras with an accuracy of 99 percent within 2:7 s.
Yushi Cheng, Xiaoyu Ji 0001, Tianyang Lu, Wenyuan Xu 0001
IEEE Trans. Mob. Comput.2
2020 Identifying Child Users via Touchscreen Interactions
abstract
With the proliferation of smart devices, children can be easily exposed to violent or adult-only content on the Internet. Without any precaution, the premature and unsupervised use of smart devices can be harmful to both children and their parents. Thus, it is critical to employ parent patrol mechanisms such that children are restricted to child-friendly content only. A successful parent patrol strategy has to be user friendly and privacy aware. The apps that require explicit actions from parents are not effective because a parent may forget to enable them, and the ones that use built-in cameras or microphones to detect child users may impose privacy violations. In this article, we propose iCare, a system that can identify child users automatically and seamlessly when users operate smartphones. In particular, iCare investigates the intrinsic differences of screen-touch patterns between child and adult users from the aspect of physiological maturity. We discover that one’s touch behaviors are related to his or her age. Thus, iCare records the touch behaviors and extracts hand geometry, finger dexterity, and hand stability features that capture the age information. We conduct experiments on 100 people including 62 children (3 to 17 years old) and 38 adults (18 to 59 years old). Results show that iCare can achieve 96.6% accuracy for child identification using only a single swipe on the screen, and the accuracy becomes 98.3% with three consecutive swipes.
Yushi Cheng, Xiaoyu Ji 0001, Xiaopeng Li 0001, Tianchen Zhang, Sharaf Jameel Malebary, Xianshan Qu, Wenyuan Xu 0001
ACM Trans. Sens. Networks2
2020 OPCIO: Optimizing Power Consumption for Embedded Devices via GPIO Configuration
abstract
Battery lifetime is one of the main challenges that impedes the deployment of energy-constrained wireless networks, such as unattended Internet-of-Things (IoT) systems. To prolong battery lifetime, the duty-cycle mode is utilized in many IoT systems, especially in environment monitoring Wireless Sensor Networks (WSN) and Low-Power Wide-Area Networks (LPWAN). In duty-cycle mode, devices transmit packets during the active phase, which lasts for a short time, and sleeps the rest of the time. Prior research mainly focuses on energy efficiency in the active phase; energy consumption during the sleep phase, however, is always ignored, as it is assumed to have little margin to be optimized. In this work, we reveal that sleep phase can become a significant battery consumer due to the misconfiguration of General-Purpose Input/Output (GPIO) pins of micro-controllers. We propose OPCIO, which incorporates a genetic algorithm to obtain energy-efficient GPIO configurations automatically to squeeze the energy waste during the sleep phase. We prototype OPCIO on off-the-shelf devices and evaluate it on two ARM devices. Experiment results show that OPCIO can effectively find multiple low-power configurations that prolong the lifespans up to 10×.
Xiaoyu Ji 0001, Wenyuan Xu 0001, Yabo Dong
ACM Trans. Sens. Networks1
2019 MagAttack: Guessing Application Launching and Operation via Smartphone
abstract
Mobile devices have emerged as the most popular platforms to access information. However, they have also become a major concern of privacy violation and previous researches have demonstrated various approaches to infer user privacy based on mobile devices. In this paper, we study a new side channel of a laptop that could be harvested by a commercial-off-the-shelf (COTS) mobile device, eg, a smartphone. We propose MagAttack, which exploits the electromagnetic (EM) side channel of a laptop to infer user activities, i.e., application launching and application operation. The key insight of MagAttack is that applications are discrepant in essence due to the different compositions of instructions, which can be reflected on the CPU power consumption, and thus the corresponding EM emissions. MagAttack is challenging since that EM signals are noisy due to the dynamics of applications and the limited sampling rate of the built-in magnetometers in COTS mobile devices. We overcome these challenges and convert noisy coarse-grained EM signals to robust fine-grained features. We implement MagAttack on both an iOS and an Android smartphone without any hardware modification, and evaluate its performance with 13 popular applications and 50 top websites in China. The results demonstrate that MagAttack can recognize aforementioned 13 applications with an average accuracy of 98.6%, and figure out the visiting operation among 50 websites with an average accuracy of 84.7%.
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001, Hao Pan 0003, Zhuangdi Zhu, Chuang-Wen You, Yi-Chao Chen 0001, Lili Qiu
AsiaCCS2
2019 DeMiCPU: Device Fingerprinting with Magnetic Signals Radiated by CPU
abstract
With the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally-measured device fingerprints, such as device ID, software or hardware-based characteristics. In this paper, we propose DeMiCPU, a stimulation-response-based device fingerprinting technique that relies on externally-measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.1% precision and recall on average, and 98.6% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6 s. In addition, the performance can be further improved to 99.9% with multi-round fingerprinting.
Yushi Cheng, Xiaoyu Ji 0001, Juchuan Zhang, Wenyuan Xu 0001, Yi-Chao Chen 0001
CCS2
2019 The Catcher in the Field: A Fieldprint based Spoofing Detection for Text-Independent Speaker Verification
abstract
Verifying the identity of voice inputs is important as voices are increasingly used for sensitive operations. Traditional methods focus on differentiating individuals via the spectrographic features of voices (e.g., voiceprint), yet cannot cope with spoofing attacks, whereby a malicious attacker synthesizes the voice with almost the same voiceprint of a victim or simply replays it. This paper proposes CaField, a text-independent speaker verification method to detect loudspeaker-based voice spoofing attacks with the goal of achieving two seemingly conflicting requirements: usability and security. The key insight of CaField is to construct "fieldprint'' with the acoustic biometrics embedded in sound fields, i.e., a physical field of acoustic energy created as the sound propagates over the air, as analogous to "voiceprint''. We find that fieldprints can be distinctive between speakers (either humans or loudspeakers), and thus we may detect the speakers being used for spoofing attacks from the authentic users. Our evaluation on a dataset of 20 people and 8 loudspeakers shows that by relying on two on-board microphones to sample sound fields while users talk to the smartphones, CaField achieves a detection accuracy of 99.16% and an equal error rate (EER) of 0.85% across multiple sessions and various voice inputs. CaField supports low audio sample rates at 8~kHz and is robust to various factors including phone displacement, user posture, recording environment, etc.
Chen Yan 0001, Yan Long 0002, Xiaoyu Ji 0001, Wenyuan Xu 0001
CCS3
2019 NAuth: Secure Face-to-Face Device Authentication via Nonlinearity
abstract
With the increasing prevalence of mobile devices, face-to-face device-to-device (D2D) communication has been applied to a variety of daily scenarios such as mobile payment and short distance file transfer. In D2D communications, a critical security problem is verifying the legitimacy of devices when they share no secrets in advance. Previous research addressed the problem with device authentication and pairing schemes based on user intervention or exploiting physical properties of the radio or acoustic channels. However, a remaining challenge is to secure face-to-face D2D communication even in the middle of a crowd, within which an attacker may hide. In this paper, we present Nhuth, a nonlinearity-enhanced, location-sensitive authentication mechanism for such communication. Especially, we target at the secure authentication within a limited range such as 20 cm, which is the common case for face-to-face scenarios. Nhuth contains averification scheme based on the nonlinear distortion of speaker-microphone systems and a location-based-validation model. The verification scheme guarantees device authentication consistency by extracting acoustic nonlinearity patterns (ANP) while the validation model ensures device legitimacy by measuring the time difference of arrival (TDOA) at two microphones. We analyze the security of Nhuth theoretically and evaluate its performance experimentally. Results show that Nhuth can verify the device legitimacy in the presence of nearby attackers.
Xiaoyu Ji 0001, Chen Yan 0001, Jiangyi Deng, Wenyuan Xu 0001
INFOCOM2
2019 mQRCode: Secure QR Code Using Nonlinearity of Spatial Frequency in Light
abstract
Quick response (QR) codes are becoming pervasive due to their rapid readability and the popularity of smartphones with built-in cameras. QR codes are also gaining importance in the retail sector as a convenient mobile payment method. However, researchers have concerns regarding the security of QR codes, which leave users susceptible to financial loss or private information leakage. In this study, we addressed this issue by developing a novel QR code (called mQRCode), which exploits patterns presenting a specific spatial frequency as a form of camouflage. When the targeted receiver holds a camera in a designated position (e.g., directly in front at a distance of 30 cm from the camouflaged QR code), the original QR code is revealed in form of a Moire pattern. From any other position, only the camouflaged QR code can be seen. In experiments, the decryption rate of mQRCode was > 98.6% within 10.2 frames via a multi-frame decryption method. The decryption rate for cameras positioned 20° off axis or > 10cm away from the designated location dropped to 0%, indicating that mQRCode is robust against attacks.
Hao Pan 0003, Yi-Chao Chen 0001, Lanqing Yang, Guangtao Xue, Chuang-Wen You, Xiaoyu Ji 0001
MobiCom6
2019 Poster: Secure Visible Light Communication based on Nonlinearity of Spatial Frequency in Light
abstract
Quick response (QR) codes are becoming pervasive due to their rapid readability and the popularity of smartphones with built-in cameras. QR codes are also gaining importance in the retail sector as a convenient mobile payment method. However, researchers have concerns regarding the security of QR codes, which leave users susceptible to financial loss or private information leakage. In this study, we address this issue by developing a novel QR code (called mQR code), which exploits patterns presenting a specific spatial frequency as a form of camouflage. When the targeted receiver holds a camera in a designated position (e.g., directly in front at a distance of 30 cm from the camouflaged QR code), the original QR code is revealed in form of a Moiré pattern. From any other position, only the camouflaged QR code can be seen. In experiments, the decryption rate of mQR codes is $> 98%$. The decryption rate for cameras positioned $20\degree$ off axis or $> 10cm$ from the designated location drops to $0%$, indicating that any attackers will be unable to steal a usable image.
Hao Pan 0003, Lanqing Yang, Yi-Chao Chen 0001, Guangtao Xue, Chuang-Wen You, Xiaoyu Ji 0001, Pai-Yen Chen
MobiCom6
2019 AHV-RPL: Jamming-Resilient Backup Nodes Selection for RPL-Based Routing in Smart Grid AMI Networks
Taimin Zhang, Xiaoyu Ji 0001, Wenyuan Xu 0001
QSHINE2
2019 UltraComm: High-Speed and Inaudible Acoustic Communication
Xiaoyu Ji 0001, Donglian Qi, Wenyuan Xu 0001
QSHINE2
2019 Exploiting Concurrency for Opportunistic Forwarding in Duty-Cycled IoT Networks
abstract
Due to limited energy supply of Internet of Things (Zhao et al. 2018) (IoT) devices, asynchronous duty cycle radio management is widely adopted to save energy. Since the sleep schedules of nodes are unsynchronized, a sender has to repeatedly send frames to coordinate with its receiver or keep sleeping until the receiver’s wake-up time will come according to receiver’s sleep-wake schedule. In such contexts, opportunistic forwarding, which takes the earliest forwarding opportunity instead of a deterministic forwarder, shows great advantage in utilizing channel resource for duty-cycled IoT networks. The multiple forwarding choices with temporal and spatial diversity increase the chance of collision tolerance in opportunistic forwarding, potentially enhancing the overall performance of duty-cycled multi-hop networks. However, since the current channel contention mechanisms mainly focus on collision avoidance, it is too conservative to exploit concurrency. To address this problem, in this article, we propose COF to fully exploit the potential Concurrency for Opportunistic Forwarding in duty-cycled IoT networks. COF achieves concurrent transmission by: (i) measuring conditional link quality under the interference of on-going transmissions, and then (ii) further modeling the benefit of potential concurrency opportunities. According to the expected benefit of concurrency, COF decides whether or not to transmit in concurrent way. COF also adopts concurrency flag and signal features to avoid data collision caused by disordered concurrent transmissions and enhance the accuracy of conditional link quality estimation. COF can be easily integrated into the conventional unsynchronized and duty-cycled protocols. We have implemented COF and evaluated its performance on a 40-node testbed. The results show that COF can effectively exploit potential concurrency in opportunistic forwarding and COF outperforms the state-of-art protocols under diverse traffic load and network density.
Daibo Liu, Zhichao Cao 0001, Yuan He 0004, Xiaoyu Ji 0001, Mengshu Hou, Hongbo Jiang 0001
ACM Trans. Sens. Networks4
2018 DeWiCam: Detecting Hidden Wireless Cameras via Smartphones
abstract
Wireless cameras are widely deployed in surveillance systems for security guarding. However, the privacy concerns associated with unauthorized videotaping, are drawing an increasing attention recently. Existing detection methods for unauthorized wireless cameras are either limited by their detection accuracy or requiring dedicated devices. In this paper, we propose DeWiCam, a lightweight and effective detection mechanism using smartphones. The basic idea of DeWiCam is to utilize the intrinsic traffic patterns of flows from wireless cameras. Compared with traditional traffic pattern analysis, DeWiCam is more challenging because it cannot access the encrypted information in the data packets. Yet, DeWiCam overcomes the difficulty and can detect nearby wireless cameras reliably. To further identify whether a camera is in an interested room, we propose a human-assisted identification model. We implement DeWiCam on the Android platform and evaluate it with extensive experiments on 20 cameras. The evaluation results show that DeWiCam can detect cameras with an accuracy of 99% within 2.7 s.
Yushi Cheng, Xiaoyu Ji 0001, Tianyang Lu, Wenyuan Xu 0001
AsiaCCS2
2018 HlcAuth: Key-free and Secure Communications via Home-Limited Channel
abstract
Nowadays most IoT devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this paper we design a key-free communication method for such devices. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for an outside-house attacker. Utilizing HLCs, we propose a challenge-response mechanism to authenticate the communications inside a house. The advantages of the HlcAuth protocol are low cost, lightweight as well as key-free, and requiring no human intervention. We show that HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers.
Chaohao Li, Xiaoyu Ji 0001, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001
AsiaCCS2
2018 FBSleuth: Fake Base Station Forensics via Radio Frequency Fingerprinting
abstract
Fake base station (FBS) crime is a type of wireless communication crime that has appeared recently. The key to enforcing the laws on regulating FBS based crime is not only to arrest but also to convict criminals effectively. Much work on FBS discovering, localization, and tracking can assist the arresting, but the problem of collecting evidence accurately to support a proper conviction has not been addressed yet.
Zhou Zhuang, Xiaoyu Ji 0001, Taimin Zhang, Juchuan Zhang, Wenyuan Xu 0001, Zhenhua Li 0001, Yunhao Liu 0001
AsiaCCS2
2018 Analyzing and Enhancing the Security of Ultrasonic Sensors for Autonomous Vehicles
abstract
Autonomous vehicles rely on sensors to measure road condition and make driving decisions, and their safety relies heavily on the reliability of these sensors. Out of all obstacle detection sensors, ultrasonic sensors have the largest market share and are expected to be increasingly installed on automobiles. Such sensors discover obstacles by emitting ultrasounds and analyzing their reflections. By exploiting the built-in vulnerabilities of sensors, we designed random spoofing, adaptive spoofing, and jamming attacks on ultrasonic sensors, and we managed to trick a vehicle to stop when it should keep moving, and let it fail to stop when it should. We validate our attacks on stand-alone sensors and moving vehicles, including a Tesla Model S with the “Autopilot” system. The results show that the attacks cause blindness and malfunction of not only sensors but also autonomous vehicles, which can lead to collisions. To enhance the security of ultrasonic sensors and autonomous vehicles, we propose two defense strategies, single-sensor-based physical shift authentication that verifies signals on the physical level, and multiple sensor consistency check that employs multiple sensors to verify signals on the system level. Our experiments on real sensors and MATLAB simulation reveal the validity of both schemes.
Wenyuan Xu 0001, Chen Yan 0001, Weibin Jia, Xiaoyu Ji 0001, Jianhao Liu
IEEE Internet Things J.4
2018 User Presence Inference via Encrypted Traffic of Wireless Camera in Smart Homes
abstract
Wireless cameras are widely deployed in smart homes for security guarding, baby monitoring, fall detection, and so on. Those security cameras, which are supposed to protect users, however, may in turn leak a user’s personal privacy. In this paper, we reveal that attackers are able to infer whether users are at home or not, that is, the user presence, by eavesdropping the traffic of wireless cameras from distance. We propose HomeSpy, a system that infers user presence by inspecting the intrinsic pattern of the wireless camera traffic. To infer the user presence, HomeSpy first eavesdrops the wireless traffic around the target house and detects the existence of wireless cameras with a Long Short-Term Memory (LSTM) network. Then, HomeSpy infers the user presence using the bitrate variation of the wireless camera traffic based on a cumulative sum control chart (CUSUM) algorithm. We implement HomeSpy on the Android platform and validate it on 20 cameras. The evaluation results show that HomeSpy can achieve a successful attack rate of 97.2%.
Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001
Secur. Commun. Networks1
2018 Channel-Aware Rate Adaptation for Backscatter Networks
Wei Gong 0001, Haoxiang Liu, Jiangchuan Liu, Xiaoyi Fan 0001, Kebin Liu 0001, Qiang Ma 0007, Xiaoyu Ji 0001
IEEE/ACM Trans. Netw.7
2017 DolphinAttack: Inaudible Voice Commands
abstract
Speech recognition (SR) systems such as Siri or Google Now have become an increasingly popular human-computer interaction method, and have turned various systems into voice controllable systems (VCS). Prior work on attacking VCS shows that the hidden voice commands that are incomprehensible to people can control the systems. Hidden voice commands, though "hidden", are nonetheless audible. In this work, we design a totally inaudible attack, DolphinAttack, that modulates voice commands on ultrasonic carriers (e.g., f > 20 kHz) to achieve inaudibility. By leveraging the nonlinearity of the microphone circuits, the modulated low-frequency audio commands can be successfully demodulated, recovered, and more importantly interpreted by the speech recognition systems. We validated DolphinAttack on popular speech recognition systems, including Siri, Google Now, Samsung S Voice, Huawei HiVoice, Cortana and Alexa. By injecting a sequence of inaudible voice commands, we show a few proof-of-concept attacks, which include activating Siri to initiate a FaceTime call on iPhone, activating Google Now to switch the phone to the airplane mode, and even manipulating the navigation system in an Audi automobile. We propose hardware and software defense solutions, and suggest to re-design voice controllable systems to be resilient to inaudible voice command attacks.
Chen Yan 0001, Xiaoyu Ji 0001, Tianchen Zhang, Taimin Zhang, Wenyuan Xu 0001
CCS3
2017 HomeSpy: Inferring User Presence via Encrypted Traffic of Home Surveillance Camera
abstract
Wireless cameras are widely deployed in homes and offices for security guarding, and play as an important part of smart home devices. Those security cameras, which are supposed to provide protection services, however, may in turn leak personal privacy that can result in security issues. In this paper, we reveal that attackers are able to eavesdrop the traffic of wireless cameras and analyze whether you are at home or not without entering the house. We propose HomeSpy, an attack tool that infers the house status by inspecting the bitrate variation of the wireless camera traffic. We implement HomeSpy on the Android platform and validate it on 3 cameras. The evaluation results show that HomeSpy can achieve a successful attack rate of 97.2%.
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICPADS2
2017 MagneComm: Magnetometer-based Near-Field Communication
abstract
Near-field communication (NFC) plays a crucial role in the operation of mobile devices to enhance applications such as payment, social networks, private communication, gaming, and etc. Despite of the convenience, existing NFC standards like ISO-13157 require additional hardware (e.g., loop antenna and dedicated chip) and thereby hindering their wide-scale applications. In this work, we seek to propose a novel near-field communication protocol, MagneComm, which utilizes Magnetic Induction (MI) signals emitted from CPUs and captured by magnetometers on mobile devices for communication. Since CPUs and magnetometers are readily available components in mobile devices, MagneComm eliminates the requirement for special hardware and complements existing near-field communication protocols by providing additional bandwidth. We systematically analyze the characteristics of magnetic signals of CPUs and facilitate MagneComm with one-way communication, full-duplex communication, and multi-transmitter schemes in accordance with the hardware availability on devices. We prototype MagneComm on both laptops and smartphones. Extensive evaluation results show that MagneComm achieves up to 110bps within 10cm.
Hao Pan 0003, Yi-Chao Chen 0001, Guangtao Xue, Xiaoyu Ji 0001
MobiCom4
2017 On Improving Wireless Channel Utilization: A Collision Tolerance-Based Approach
abstract
Packet corruption caused by collision is a critical problem that hurts the performance of wireless networks. Conventional medium access control (MAC) protocols resort to collision avoidance to maintain acceptable efficiency of channel utilization. According to our investigation and observation, however, collision avoidance comes at the cost of miscellaneous overhead, which oppositely hurts channel utilization, not to mention the poor resiliency and performance of those protocols in face of dense networks or intensive traffic. Discovering the ability to tolerate collisions at the physical layer implementations of wireless networks, we in this paper propose Coco, a protocol that advocates simultaneous accesses from multiple senders to a shared channel, i.e., optimistically allowing collisions instead of simply avoiding them. With a simple but effective design, Coco addresses the key challenges in achieving collision tolerance, such as precise sender alignment and the control of transmission concurrency. We implement Coco in 802.15.4 networks and evaluate its performance through extensive experiments with 21 TelosB nodes. The results demonstrate that Coco is light-weight and enhances channel utilization by at least 20 percent in general cases, compared with state-of-the-arts protocols.
Xiaoyu Ji 0001, Yuan He 0004, Jiliang Wang, Kaishun Wu, Daibo Liu, Ke Yi 0001, Yunhao Liu 0001
IEEE Trans. Mob. Comput.1
2016 Furion: Towards Energy-Efficient WiFi Offloading under Link Dynamics
abstract
Offloading network traffic from cellular to WiFi is widely used to reduce energy consumption since WiFi is assumed to have lower power consumption than cellular. However, we find that WiFi link quality may vary significantly under user mobility. Consequently, the energy efficiency of WiFi varies and sometimes becomes even worse than that of cellular. Therefore, widely used WiFi offloading may not be beneficial or even incurs more energy consumption. To address this issue, we propose Furion, an energy efficient WiFi offloading scheme that exploits beneficial WiFi links on smartphones. Towards such a goal, we investigate the relationship between energy efficiency and link quality. Accordingly, we propose a practical probabilistic model to predict WiFi energy efficiency based on the dynamics of link quality. We further extend the method to different environments by exploiting contextual factors in the prediction model to improve the accuracy. Based on the model, we design an adaptive offloading scheme to optimize the energy efficiency of WiFi offloading, while also guaranteeing user experience. We have implemented Furion on the Android platform and conduct extensive real-world experiments. The results demonstrate that Furion achieves 34.13% improvement in energy efficiency compared with the state-of-the- arts.
Yi Zhang 0017, Jiliang Wang, Yuan He 0004, Xiaoyu Ji 0001, Yanrong Kang, Daibo Liu, Bo Li 0001
SECON4
2016 Privacy-Aware High-Quality Map Generation with Participatory Sensing
abstract
Accurate maps are increasingly important with the growth of smart phones and the development of location-based services. Several crowdsourcing based map generation protocols that rely on users to provide their traces have been proposed. Being creative, however, those methods pose a significant threat to user privacy as the traces can easily imply user behavior patterns. On the flip side, crowdsourcing-based map generation method does need individual locations. To address the issue, we present a systematic participatory-sensing-based high-quality map generation scheme, PMG, that meets the privacy demand of individual users. To be specific, the individual users merely need to upload unorganized sparse location points to reduce the risk of exposing users’ traces and utilize theCrust, a technique from computational geometry for curve reconstruction, to estimate the unobserved map as well as evaluate the degree of privacy leakage. Experiments show that our solution is able to generate high-quality maps for a real environment that is robust to noisy data. The difference between the ground-truth map and the produced map is less than 10 m, even when the collected locations are about 32 m apart after clustering for the purpose of removing noise.
Xiaopei Wu, Xiang-Yang Li 0001, Xiaoyu Ji 0001, Yuan He 0004, Yunhao Liu 0001
IEEE Trans. Mob. Comput.4
2016 Hitchhike: A Preamble-Based Control Plane for SNR-Sensitive Wireless Networks
abstract
Recently, carrying control signals on passing data packets has emerged as a promising direction for efficient control information transmission. With control messages carried on data payload, the extra air time needed for control packets like RTS/CTS is eliminated and thus channel utilization is improved. However, carrying control signals on the data payload of a packet requires the data packet to have a sufficiently large SNR, otherwise both the data packet and the control messages are lost. In this paper, we propose Hitchhike, a technique that utilizes the preamble field to carry control messages. Hitchhike completely decouples the control messages from the payload and therefore the superposition of (multiple) control messages has little adverse effect on the operation of the payload decoding. We implement and evaluate Hitchhike in the USRP2 platform with five nodes. Evaluation results demonstrate the feasibility and effectiveness of Hitchhike. Compared with the state-of-the-art, e.g., side-channel in 802.15.4, Hitchhike improves the detection accuracy of control messages by 40% and reduces the data loss caused by control messages by 15%.
Xiaoyu Ji 0001, Jiliang Wang, Mingyan Liu, Yubo Yan, Panlong Yang, Yunhao Liu 0001
IEEE Trans. Wirel. Commun.1
2015 Tele Adjusting: Using Path Coding and Opportunistic Forwarding for Remote Control in WSNs
abstract
On-air access of individual sensor node (called remote control) is an indispensable function in operational wireless sensor networks, for purposes like network management and real-time information delivery. To realize reliable and efficient remote control in a wireless sensor network (WSN), however, is extremely challenging, due to the stringent resource constraints and intrinsically unrealizable wireless communication. In this paper, we propose TeleAdjusting, a ready-to-use protocol to remotely control any individual node in a WSN. We develop a coding scheme for addressing on the cost-optimal reverse routing tree. In the address of each node, all its upstream relaying nodes are implicitly encoded. Then through a distributed prefix matching process between the local address and the destination address, a packet used for remote control is forwarded along a cost-optimal path. Moreover, TeleAdjusting incorporates opportunistic forwarding into the addressing process, so as to improve the network performance in terms of reliability and energy efficiency. We implement TeleAdjusting with TinyOS and evaluate its performance through extensive simulations and experiments. The results demonstrate that compared to the existing protocols, TeleAdjusting can provide high performance of remote control, which is as reliable as network-wide flooding and much more efficient than remote control through a pre-determined path.
Daibo Liu, Zhichao Cao 0001, Xiaopei Wu, Yuan He 0004, Xiaoyu Ji 0001, Mengshu Hou
ICDCS5
2015 COF: Exploiting Concurrency for Low Power Opportunistic Forwarding
abstract
Due to the constraint of energy resource, the radio of sensor nodes usually works in a duty-cycled mode. Since the sleep schedules of nodes are unsynchronized, a sender has to send preambles to coordinate with its receiver(s). In such contexts, opportunistic forwarding, which takes the earliest forwarding opportunity instead of a deterministic forwarder, shows great advantage in utilizing channel resource. The multiple forwarding choices with temporal and spatial diversity increase the chance of collision tolerance in concurrent transmissions, potentially enhancing end-to-end network performance. However, the current channel contention mechanism based on collision avoidance is too conservative to exploit concurrency. To address this problem, we propose COF, a practical protocol to exploit the potential Concurrency for low power Opportunistic Forwarding. COF determines whether a node should concurrently transmit or not, by incorporating: (1) a distributed and light-weight link quality measurement scheme for concurrent transmission and (2) a synthetic method to estimate the benefit of potential concurrency opportunity. COF can be easily integrated into the conventional unsynchronized sender-initiated protocols. We evaluate COF on a 40-node testbed. The results show that COF can reduce the end-to-end delay by up to 41% and energy consumption by 18.9%, compared with the state-of-the-art opportunistic forwarding protocol.
Daibo Liu, Mengshu Hou, Zhichao Cao 0001, Yuan He 0004, Xiaoyu Ji 0001, Xiaolong Zheng 0002
ICNP5
2014 Walking down the STAIRS: Efficient collision resolution for wireless sensor networks
abstract
Collision resolution is a crucial issue in wireless sensor networks. The existing approaches of collision resolution have drawbacks with respect to energy efficiency and processing latency. In this paper, we propose ST AIRS, a time and energy efficient collision resolution mechanism for wireless sensor networks. STAIRS incorporates the constructive interference technique in its design and explicitly forms superimposed colliding signals. Through extensive observations and theoretical analysis, we show that the RSSI of the superimposed signals exhibit stairs-like phenomenon with different number of contenders. That principle offers an attractive feature to efficiently distinguish multiple contenders and in turn makes collision-free schedules for channel access. In the design and implementation of STAIRS, we address practical challenges such as contenders alignment, online detection of RSSI change points, and fast channel assignment. The experiments on real testbed show that STARIS realizes fast and effective collision resolution, which significantly improves the network performance in terms of both latency and throughput.
Xiaoyu Ji 0001, Yuan He 0004, Jiliang Wang, Wei Dong 0001, Xiaopei Wu, Yunhao Liu 0001
INFOCOM1
2014 Hitchhike: Riding control on preambles
abstract
Recently, carrying control signals on passing data packets has emerged as a promising direction for efficient control information transmission. With control messages carried on data payload, the extra air time needed for control packets like RTS/CTS is eliminated and thus channel utilization is improved. However, carrying control signals on the data payload of a packet requires the data packet to have a sufficiently large SNR, otherwise both the data packet and the control messages are lost. In this paper, we proposeHitchhike, a technique that utilizes the preamble field to carry control messages. Hitchhike completely decouples the control messages from the payload and therefore the superposition of (multiple) control messages has little adverse effect on the operation of the payload decoding. We implement and evaluate Hitchhike in the USRP2 platform with 5 nodes. Evaluation results demonstrate the feasibility and effectiveness of Hitchhike. Compared with the state-of-the-art, e.g., Side-channel in 802.15.4, Hitchhike improves the detection accuracy of control messages by 40% and reduces the data loss caused by control messages by 15%.
Xiaoyu Ji 0001, Jiliang Wang, Mingyan Liu, Yubo Yan, Panlong Yang, Yunhao Liu 0001
INFOCOM1
2013 Voice over the dins: Improving wireless channel utilization with collision tolerance
abstract
Packet corruption caused by collision is a critical problem that hurts the performance of wireless networks. Conventional medium access control (MAC) protocols resort to collision avoidance to maintain acceptable efficiency of channel utilization. According to our investigation and observation, however, collision avoidance comes at the cost of miscellaneous overhead, which oppositely hurts channel utilization, not to mention the poor resiliency and performance of those protocols in face of dense networks or intensive traffic. Discovering the ability to tolerate collisions at the physical layer implementations of wireless networks, we in this paper propose Coco, a MAC protocol that advocates simultaneous accesses from multiple senders to a shared channel, i.e., optimistically allowing collisions instead of simply avoiding them. With a simple but effective design, Coco addresses the key challenges in achieving collision tolerance, such as precise sender alignment and fine control of the transmission concurrency. We implement Coco in 802.15.4 networks and evaluate its performance through extensive experiments with 21 TelosB nodes. The results demonstrate that Coco is light-weight and enhances channel utilization by at least 20% in general cases, compared with state-of-the-arts protocols.
Xiaoyu Ji 0001, Yuan He 0004, Jiliang Wang, Kaishun Wu, Ke Yi 0001, Yunhao Liu 0001
ICNP1
2010 Integrating old chinese shadow play-piying into tangible interaction (abstract only)
abstract
Piying is an old Chinese art form and one of the origins of the modern movie. In Piying, the shadow of fur made characters with delicate carving could be seen by audience in front of the curtain. The artists behind the curtain control the actions of shadows using sticks fastened to the characters.
Lining Yao, Xiaoyu Ji 0001, Fangtian Ying
TEI3
2010 Music-touch shoes: vibrotactile interface for hearing impaired dancers
abstract
The hearing handicapped children show a penchant for dancing and dance plays an essential part in education of deaf children. This paper introduces the Music-touch Shoes, a pair of shoes particularly designed for hearing handicapped dancers: The rhythm and tempo of music can be communicated and perceived through the vibrotactile interaction. The vibrotactile interface is applied to shoes because feet are among the body parts which are most directly involved in performing dancing rhythm. The different sequences, intensity and frequency of vibrations reflect different rhythm and tempo of music. This project sought to explore a way of making up for the shortage of hearing ability through interaction with other senses, such as vibrotactile sense, to fulfill the same dancing entertainment demand of the hearing handicapped people.
Lining Yao, Hengfeng Chi, Xiaoyu Ji 0001, Fangtian Ying
TEI4