Yan Meng 0001

dblp:43/1032-1 · DBLP profile ↗
← Back
43ranked-venue papers
8as first author
34since 2021 · last 2026
0000-0001-5445-0347ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 3 first-author · 18 since 2021Computer networks · 18 · 5 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 EXIA: Trusted Transitions for Enclaves via External-Input Attestation
Yidi Kao, Sanchuan Chen, Guoxing Chen, Yan Meng 0001, Haojin Zhu
NDSS5
2026 Vetting Privacy Policies in Virtual Reality Platforms With Longitudinal Analysis
abstract
With the help of advanced sensors, virtual reality (VR) apps provide users with an immersive experience, but they also have the potential to collect a wider range of user data compared to traditional web and mobile apps. As a result, increasing numbers of regulations are being introduced globally, emphasizing the need for app developers to provide privacy policies that inform users about data collection, usage, and sharing (CUS) process. Unfortunately, despite the significant efforts made by VR developers to improve app performance, it remains unclear how they ensure their privacy policies comply with regulations and meet user expectations. In this study, we proposeVPVetto automatically vet privacy policy issues for VR apps. We first summarize five vetting criteria based on a study of privacy policies from popular apps: availability, completeness, granularity, minimization, and consistency. We then dissect VR data and entity ontologies and manually generate VR-related CUS sentences to fine-tune privacy policy language models, overcoming performance degradation when handling VR domain-specific sentences. Finally, we construct the largest VR privacy policy dataset to date, namedVRPP, consisting of privacy policies from 11,923 VR apps across 10 mainstream platforms. These policies were crawled in late 2022 and early 2025 to investigate the evolution of the VR ecosystem. Our vetting process examines platform, app category, and longitudinal perspectives, revealing that VR privacy policies have shown severe privacy issues over the past few years, including limited availability, poor quality, coarse granularity, a lack of adaptation to VR-specific traits, and inconsistencies between CUS statements and actual app behaviors.
Yan Meng 0001, Yuxia Zhan, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu
IEEE Trans. Netw.1
2025 PipID: Light-Pupillary Response Based User Authentication for Virtual Reality
abstract
During the use of Virtual Reality (VR) applications such as gaming, education, and military training, sensitive information may be generated or collected by VR sensors, raising user concerns about potential data leakage. This highlights the critical need for effective user authentication to prevent unauthorized access. Existing authentication methods for VR are often either cumbersome (e.g., entering passwords via handheld controllers), reliant on specialized hardware (e.g., iris recognition), or vulnerable to credential replay attacks. In this study, we propose PipID, a lightweight VR authentication approach that leverages commercial off-the-shelf (COTS) eye trackers integrated into VR headsets. PipID is based on the fact that users' pupillary responses to visual stimuli vary uniquely. Thus, by displaying lights of randomly selected colors (i.e., wavelengths) on the VR screen, PipID can utilize pupil diameter responses to these wavelengths as the basis for authentication. For pupil data collected by precision-limited COTS eye trackers, PipID mitigates the impact of unrelated eye movements (e.g., blinks) and leverages pupillary response differences between the left and right eyes to further enhance the granularity of authentication features. Additionally, the randomized sequence of light colors helps prevent replay attacks. We implemented PipID on a COTS VR headset and tested it with 52 participants. Experimental results show that PipID achieves an accuracy of 98.65% and maintains robust performance under various conditions (e.g., keeping 98% and 91% accuracy after 7 and 14 days respectively).
Muchen Pan, Yan Meng 0001, Yuxia Zhan, Guoxing Chen, Haojin Zhu
CCS2
2025 Latte: Layered Attestation for Portable Enclaved Applications
abstract
Trusted Execution Environment (TEE) has become increasingly popular in privacy-protected cloud computing, and its rapid development has led to the availability of various heterogeneous TEE platforms on cloud servers. To facilitate portable TEE applications on heterogeneous TEE platforms, portable languages or intermediate representations (IRs) with platform-dependent TEE runtimes are adopted. However, existing remote attestation solutions for portable TEE applications follow a nested attestation pattern, i.e., attesting only the TEE runtime and relying on the TEE runtime to measure the loaded portable application, leading to potential security issues. On the other hand, directly packing the TEE runtime and the portable application into an enclave for secure attestation undermines the portability of the portable TEE applications.In this paper, we introduce the concept of portable identities to identify portable TEE applications, and propose a layered attestation framework, Latte, achieving both security and portability in attesting portable TEE applications. We provide a prototype implementation of Latte to validate its practicality, with WebAssembly as the portable IR, and Intel SGX and RISC-V Penglai as the exemplar heterogeneous TEEs. The evaluation demonstrates that Latte introduces minimal performance overhead compared with the nested attestation pattern.
Jia Xiang, Guoxing Chen, Yan Meng 0001, Haojin Zhu
EuroS&P5
2025 The Philosopher's Stone: Trojaning Plugins of Large Language Models
Tian Dong 0003, Minhui Xue 0001, Guoxing Chen, Rayne Holland, Yan Meng 0001, Shaofeng Li 0001, Zhen Liu 0008, Haojin Zhu
NDSS5
2025 Blind Points Between ASR and Intent Inferring: Vulnerability Discovering via Fuzzing in-Vehicle Voice Assistance
abstract
Currently, in-vehicle Voice Assistants (VAs) have been widely integrated into in-vehicle infotainment (IVI) systems to enhance driver safety when performing functions such as navigation and phone calls while driving. Although various studies have demonstrated the existence of vulnerabilities in general-purpose VAs, there is a lack of research specifically targeting in-vehicle VAs, which operate in a closed and black-box environment. In this paper, we utilize fuzzing testing to analyze how speech errors in voice commands affect the recognition performance of in-vehicle VAs. First, we simulate speech errors by applying linguistic knowledge to mutate voice commands. Then, we adopt a genetic algorithm to efficiently generate additional erroneous commands. To further improve the quality of these mutated commands, we assign a risk level to each original command and prioritize the mutation of those whose misrecognition by the in-vehicle VA results in an increased risk level. We conducted comprehensive fuzzing experiments on both local (Whisper–DistilBERT-based) and cloud-based (Amazon Lex) in-vehicle VA systems. Our approach generated 59112 speech-error commands in the local VA, achieving a 60.13% misrecognition rate, significantly outperforming Baseline-Fuzzing, which had an effectiveness of 40.26%. On the cloud-based VA, the effectiveness improved from 2.83% to 33.24%. These results confirm the superiority of our method in generating high-impact erroneous commands.
Peilin Luo, Wei Teng, Jiachun Li 0001, Yan Meng 0001, Haojin Zhu
TrustCom4
2025 Depth Gives a False Sense of Privacy: LLM Internal States Inversion
Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Zhen Liu 0008, Haojin Zhu
USENIX Security Symposium2
2025 A Magnetic Signal Based Device Fingerprinting Scheme in Wireless Charging
abstract
Wireless charging is widely used to charge smart devices with limited battery capacity. However, it is susceptible to the identity spoofing attack, where adversaries can impersonate malicious devices as legitimate ones to gain unauthorized access and potentially disrupt the wireless charging system (e.g., resulting in incorrect billing, overheating, or even explosions). Device fingerprinting is a classical method for defending against identity spoofing attacks. However, applying existing schemes in wireless charging scenarios has drawbacks such as inconvenience (e.g., requiring specialized devices or user participation) and ineffectiveness (e.g., vulnerability to spoofing). Thus, we design a novel passive, effective, and robust device fingerprinting scheme called MagID for wireless charging systems. The insight of MagID lies in the fact that during wireless charging, the magnetic signal around a device can reflect inherent hardware differences. These differences can be extracted as unique fingerprints for authentication purposes. MagID leverages a novel scheme, SUPER-ARRAY, to precisely measure magnetic data and generate effective fingerprints for authenticating a device's identity before starting charging progress. Experimental results demonstrate that MagID achieves an accuracy rate of 98.14% across various charging devices. We have also tested its performance under different impact factors and verified its compatibility with various wireless charging pads.
Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu
IEEE Trans. Dependable Secur. Comput.2
2025 Binary-Level Formal Verification Based Automatic Security Ensurement for PLC in Industrial IoT
abstract
Currently, the security of the control logic of Programmable Logic Controllers (PLCs) is facing a serious threat, significantly impacting industrial production. Consequently, ensuring the security of PLC control logic becomes imperative. Formal verification emerges as a promising methodology for verifing PLC security through behavioral modeling and security testing. However, existing formal verification approaches primarily focus on modeling the PLC source code, overlooking the identification of compile-time errors and real-time runtime logic checks. Therefore, it is essential to apply formal verification to PLC control logic at the binary level. In this study, we introduce VoICS, a system designed to facilitate binary-level formal verification. Using reverse engineering, VoICS automatically parses PLC programs written by various programming languages at the binary level and constructs control flow graphs (CFGs). Furthermore, we use an algorithm combining two model optimization methods (i.e., trim invalid states and unnecessary states compression) to convert the reversed PLC assembly program into nuXmv format model. Lastly, VoICS establishes the corresponding constraints and performs formal verification on the model using nuXmv. The evaluation results demonstrate the capability of VoICS in identifying instances of unreliable control logic within PLC control programs, thus reinforcing the dependability of the industrial automation system.
Xuankai Zhang, Jianhua Li 0001, Jun Wu 0001, Guoxing Chen, Yan Meng 0001, Haojin Zhu, Xiaosong Zhang 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Synergistic Multi-Modal Keystroke Eavesdropping in Virtual Reality With Vision and Wi-Fi
abstract
In panoramic and immersive virtual reality (VR) scenarios, users type on a floating and invisible keyboard, which cannot be observed by external adversaries, creating the illusion that their input is confidential. While recent studies have demonstrated the feasibility of leveraging side-channel information (e.g., vision, Wi-Fi) to eavesdrop on keystrokes in VR, they assume users typically type with fixed gestures, similar to using traditional physical keyboards. However, in real world scenarios, VR creates a 3D immersive environment, allowing users to type from varying orientations. This variation significantly degrades the quality of side-channel information (e.g., occlusion in vision, instability in Wi-Fi channels), leading to ineffective inference. In this study, we propose a multi-modal keystroke eavesdropping attack called WiViLeak, which combines Wi-Fi and vision information to complement each other. To address low-quality side-channel data caused by users’ varying orientations, we develop a theoretical model to explore the relationship between users’ hand movements in physical space (from the vision modality) and fluctuating Wi-Fi signals (from the wireless modality) as users change orientation. Based on this, we design a fully transformer based orientation calibration module to recover users’ vision data, aligning it as if they were facing the camera (i.e., in a front-facing view). Meanwhile, WiViLeak reconstructs Wi-Fi data to correspond to the front-facing view, utilizing the orientation angle derived from vision data. Finally, WiViLeak extracts effective features from reconstructed, high-quality vision and Wi-Fi data to predict keystrokes. We implement a WiViLeak prototype, achieving 89.2% accuracy in eavesdropping keystrokes and 93.6% top-100 password theft accuracy, while also demonstrating robustness across various real world VR scenarios, including payments, chatting, and meetings.
Jiachun Li 0001, Yan Meng 0001, Fazhong Liu, Tian Dong 0003, Suguo Du, Guoxing Chen, Yuling Chen 0002, Haojin Zhu
IEEE Trans. Inf. Forensics Secur.2
2025 A Redactable Blockchain-Based Anonymous Announcement Scheme for VANETs
abstract
Blockchain serves as a trust layer for data exchange in Vehicular Ad-hoc Networks (VANETs) due to its immutability and transparency. However, it can also be abused to spread false and inaccurate information. Additionally, the explosive growth of data in VANETs and the limited storage capacity of edge nodes make it challenging to maintain the entire blockchain. To address these challenges, we propose an anonymous vehicle announcement scheme based on redactable blockchain. Specifically, we propose a novel ephemeral trapdoor revocable chameleon hash scheme (ETRCH) that enables decentralized management and enforced revocation of redaction privileges. ETRCH deploys multiple regulators, each capable of creating multiple ephemeral trapdoors. These regulators enable${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$edge nodes associated with the same ephemeral trapdoor to collaboratively rewrite blockchain data, thereby addressing storage limitations. In addition,${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$regulators can cooperate to update the ephemeral trapdoor and revoke the redaction privileges of any malicious regulator discovered to be abusing their privileges. To facilitate the threshold authentication of announcement messages, we construct a redactable threshold ring signature scheme (RTRS) based on ETRCH, enabling anonymous signing of announcements in VANETs. Additionally, if a regulator detects a false or misleading message, the content can be promptly rewritten. Finally, we conducted rigorous security analysis and comprehensive experiments to evaluate the performance of the proposed scheme. The results demonstrate that compared to VANETs systems based on immutable blockchains, our scheme is both secure and efficient.
Yuxiang Yang 0006, Yuling Chen 0002, Zhiquan Liu 0001, Yan Meng 0001, Haiwei Sang
IEEE Trans. Intell. Transp. Syst.4
2025 Collaborative Ad Fraud Detection in Ad Networks
abstract
Mobile advertising has been significantly propelled by the advent of in-app programmatic advertising and Real-Time Bidding (RTB) technologies. However, it suffers from ad fraud incidents in ad networks, including click injection, covert background ad activities, and etc. While previous research has predominantly focused on ad fraud localized within individual apps or specific devices, this paper delineates a newly identified form of collusion-based ad fraud, termed ad attribution laundering fraud (ALF).ALFinvolves multiple apps conspiring to obfuscate the true origins of where advertisements are displayed, thereby allowing lower-quality apps to leverage the reputations of ostensibly legitimate ones. To detectALF, we developed the detection tool, AlfScan-X, which efficiently identifies potential collaborative apps among millions in the wild by heuristically prioritizing candidate apps likely to be involved inALFfor prompt analysis. AlfScan-Xmaintains an online APK crawler and an$\textsf {AppID}$database to enhance AlfScan-X’s responsiveness, adaptability, and reduce false negatives. Overcoming challenges of identity extraction from diverse and obfuscated apps, AlfScan-Xutilizes a combination of static and dynamic analysis techniques to cross-verify app identities, pinpointing instances ofALF. Our evaluation of AlfScan-Xon a 200-app ground truth dataset yielded high effectiveness with 92% precision and 92% recall. AlfScan-Xidentified$4,515$unique fraudulent apps and$1,483$fraudulent clusters, revealing significant patterns and implications of fraudulent apps and highlighting reliability issues in both third-party app development frameworks and advertising networks.
Guoxing Chen, Yan Meng 0001, Haojin Zhu
IEEE Trans. Netw.5
2024 VPVet: Vetting Privacy Policies of Virtual Reality Apps
abstract
Virtual reality (VR) apps can harvest a wider range of user data than web/mobile apps running on personal computers or smartphones. Existing law and privacy regulations emphasize that VR developers should inform users of what data are collected/used/shared (CUS) through privacy policies. However, privacy policies in the VR ecosystem are still in their early stages, and many developers fail to write appropriate privacy policies that comply with regulations and meet user expectations. In this paper, we propose VPVet to automatically vet privacy policy compliance issues for VR apps. VPVet first analyzes the availability and completeness of a VR privacy policy and then refines its analysis based on three key criteria: granularity, minimization, and consistency of CUS statements. Our study establishes the first and currently largest VR privacy policy dataset named VRPP, consisting of privacy policies of 11,923 different VR apps from 10 mainstream platforms. Our vetting results reveal severe privacy issues within the VR ecosystem, including the limited availability and poor quality of privacy policies, along with their coarse granularity, lack of adaptation to VR traits and the inconsistency between CUS statements in privacy policies and their actual behaviors. We open-source VPVet system along with our findings at repository https://github.com/kalamoo/PPAudit, aiming to raise awareness within the VR community and pave the way for further research in this field.
Yuxia Zhan, Yan Meng 0001, Yichang Xiong, Xiaokuan Zhang, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu
CCS2
2024 Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security Implications
abstract
In recent years, the growth of mobile advertising has been driven by in-app programmatic advertising and technologies like Real-Time Bidding (RTB). However, this growth has also led to an increase in ad fraud, such as click injection, background ad activity, etc. While existing studies have primarily concentrated on ad fraud within individual apps or devices, this paper introduces a new form of collusion-based ad fraud, named ad attribution laundering fraud (ALF). ALF involves multiple apps collaborating to deceive advertisers by misrepresenting the app where ads are displayed. The collusion-based approach allows lower-quality apps to exploit the reputable identities of seemingly legitimate apps. This deceives advertisers or ad networks into believing that the advertisements they place are reaching potentially valid end-users on the legitimate app. The seemingly legitimate ad events and ad attribution procedures employed by individual apps in such attacks can evade detection by existing tools.
Chaofan Shou, Guoxing Chen, Xiaokuan Zhang, Yan Meng 0001, Shuang Hao 0001, Haojin Zhu
CCS6
2024 Inferring Activities and Profiles of Users Based on Trajectory Leakage in Mobile Ad Network
abstract
With the widespread use of smartphones and the development of ad networks, mobile in-app targeted ads have become more and more prevalent, leveraging users' geolocation for targeting purposes. This service involves a large amount of user location data, which may not only expose sensitive locations closely associated with the users, but also reveal the users' activities and profiles. Previous studies have utilized various machine learning methods to infer users' activities or predict their future activities based on the location data from location-based social networks (LBSNs). These approaches, however, often require large datasets for training and are also resource-intensive. Unlike active behaviors, such as checking in, where users intentionally record their location, location data are passively recorded by mobile apps in the background, making inferring activities more challenging. Considering the rapid progress in the reasoning abilities of the large language models (LLMs) in recent years, we aim to evaluate user's activity and profile leakage through LLMs with the assistance of map APIs. We conduct the experiment on the location dataset, which is generated according to specified profiles. The results of the experiment show that the LLM can infer users' activities with an accuracy rate scoring up to 96.1 %, and there is also a high probability of predicting the users' profiles, such as the occupation.
Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Haojin Zhu
MSN4
2024 DevDet: Detecting IoT Device Impersonation Attacks via Traffic Based Identification
Hongliang Yong, Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Guoxing Chen, Haojin Zhu
WASA (2)4
2024 An HASM-Assisted Voice Disguise Scheme for Emotion Recognition of IoT-Enabled Voice Interface
abstract
Voice-enabled devices are becoming increasingly prevalent in the Internet of Things (IoT). Speech emotion recognition (SER), as a key technology in modern voice-assisted applications, holds tremendous potential for delivering convenient and intelligent services. Unfortunately, SER Service providers may not only analyze the emotions in users’ speech but also examine their speech content and voice characteristics, posing greater privacy risks. Existing real-time voice disguise methods, such as pitch scaling and VTLN, provide significant technical support for the protection of voiceprint privacy but significantly impact the accuracy of SER. In this paper, we propose a harmonic amplitude spectrum mapping (HASM) assisted voice disguise scheme, which disguises the voice for voiceprint privacy preservation while safeguarding the emotional information within the voice. Specifically, we first conduct an in-depth analysis of the features in the speech that can reflect emotions and find that restoring harmonic amplitude spectrum features after altering the speaker’s voice is crucial for recovering emotions in speech. Based on this discovery, we then preprocess the original speech signals with pitch scaling and design a HASM-assisted disguise scheme based on mathematical theory expression to restore the emotions. Our HASM-assisted voice disguise scheme is validated on the Berlin Emotional Speech Database, the LibriSpeech dataset and VCTK dataset. At voiceprint privacy protection levels of 81.86%, 85.42%, and 91.15% in the LibriSpeech dataset and 96.83%, 98.25%, and 98.41% in the VCTK dataset, respectively, the SER accuracy of acoustic feature-based disguised speech decreases by only 4.19%, 6.21%, and 9.87%, and the end-to-end SER accuracy decreases by only 3.69%, 7.37%, and 8.86%, which is superior to other voice disguise methods.
Wenjia Chen, Wenjuan Tang, Yan Meng 0001, Yaoxue Zhang
IEEE Internet Things J.3
2024 Privacy-Preserving Liveness Detection for Securing Smart Voice Interfaces
abstract
Smart speakers are widely used as the primary user interface in intelligent systems, including smart homes and industrial IoT. However, they are vulnerable to voice spoofing attacks which result in malicious command execution or privacy information leakage. Passive liveness detection, which thwarts voice spoofing via analyzing the collected audio rather than deploying sensors to distinguish between live-human and spoofing voices, has drawn increasing attention. But existing schemes either face performance degradation under environmental factor changes or require the user to keep fixed gestures, which limit their deployment in real-world scenarios. Besides, the space distributed property of smart speakers causes building a universal classifier for all involved users to be cumbersome and increases privacy leakage issues. To address the challenges mentioned above, we propose LIVEARRAY, an efficient, lightweight, and privacy-preserving passive liveness detection system. LIVEARRAY exploits a novel liveness feature, array fingerprint, which utilizes the microphone array inherently adopted by the smart speaker to improve the accuracy of liveness detection. LIVEARRAY's further employs the federated learning-based architecture to reduce the dataset collection overhead during classifier building and eliminate the potential privacy leakage during data transmission. Experimental results show that LIVEARRAY achieves an accuracy of 99.16%, which is superior to existing passive schemes
Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Yuan Tian 0001, Jiming Chen 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Dangers Behind Charging VR Devices: Hidden Side Channel Attacks via Charging Cables
abstract
Virtual reality (VR), offering 3D visuals and stereophonic sounds, significantly enhances users’ immersive experiences and has become a milestone in the era of the metaverse. However, due to the limited battery capacity of VR devices, it is common for users to rely on charging cables, which serve the dual purpose of power supply and audio output, to recharge their VR devices while in use. In this study, we propose an inconspicuous and stealthy side channel attack, coined as LineTalker, which can unveil visual-related and audio-related activities from VR devices during the charging process. The insight behind LineTalker is rooted in the observation that visual-related activities (e.g., 3D image rendering) are power-intensive and result in fluctuations in the current strength of the cable’s power supply line, which can be leveraged as side channel information. Similarly, audio-related activities (e.g., playing music) leave traces on the cable’s audio output line. Rather than providing a user with a compromised charging cable (i.e., embedding a current sensor) to measure the current strength, to make the attack less conspicuous, LineTalker employs the Hall effect to indirectly access side channel information. This is achieved by capturing magnetic signals using a Hall sensor placed near the target cable in a contactless manner. Experimental results demonstrate that LineTalker achieves an overall accuracy of 94.60% and 64.38% in inferring user activities in VR devices with intrusive and non-intrusive attack manners, respectively.
Jiachun Li 0001, Yan Meng 0001, Yuxia Zhan, Haojin Zhu
IEEE Trans. Inf. Forensics Secur.2
2024 De-Anonymizing Avatars in Virtual Reality: Attacks and Countermeasures
abstract
By providing users with an immersive visual and acoustic experience, virtual reality (VR) serves as a foundational technique for the emerging metaverse. One of the most promising aspects of VR is its ability to protect users’ identities by transforming their physical appearances into avatars with arbitrary appearances in the virtual world. However, the increasing threat of de-anonymization attacks that seek to reveal users’ identities poses significant privacy risks. We propose AvatarHunter, a non-intrusive and user-unaware de-anonymization attack leveraging victims’ inherent movement signatures. AvatarHunter discreetly collects the avatar's gait information by recording videos in the VR scenario without requiring any permissions. Notably, we designed a Unity-based feature extractor that maintains the avatar's movement signature while enabling AvatarHunter to be resistant to changes in the avatar's appearance. We conduct real-world experiments on VRChat to evaluate AvatarHunter's effectiveness. The results demonstrate that in commercial settings, AvatarHunter achieves attack success rates (ASR) of 92.1% and 66.9% in closed-world and open-world avatar scenarios, respectively, significantly surpassing existing benchmarks. Additionally, simulations using an open-source dataset confirm that AvatarHunter can attain over 78% ASR in full-body tracking scenarios. Finally, we discuss several countermeasures and implement an obfuscation mechanism during the avatar rendering phase, significantly reducing the ASR.
Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen
IEEE Trans. Mob. Comput.1
2024 Privacy-Preserving Location-Based Advertising via Longitudinal Geo-Indistinguishability
abstract
As location data have been increasingly adopted in location-based advertising (LBA), revealing locations to untrusted service providers has raised severe privacy concerns. Recent studies propose obfuscation mechanisms built upon geo-indistinguishability (geo-IND) to provide formal privacy guarantee. Unfortunately, due to the high degree of spatiotemporal regularity in human mobility pattern, the privacy cost will be unacceptably high in this situation, leading to accurate inference of user real locations. In this study, we identify this privacy risk in LBA scenarios under long-term and multi-platform assumption. We demonstrate an attacker can infer 75%∼90% of top-1 locations within a range of only 200 meters. To address it, we proposePrivLocAd, a novel system which can provide longitudinal privacy guarantee. The novelty of PrivLocAd stems from a novel surrogate-based obfuscation, which generates multiple surrogate locations to improve the privacy-utility trade-off. In addition, two novel obfuscation mechanisms, the two-stage Gaussian and multi-level surrogate generation mechanism in charge of surrogate generation can achieve the longitudinal privacy guarantee in intra- and inter-platform condition respectively. Our experimental results demonstrate PrivLocAd is able to defend against the attack, which reduces the inference rate to less than 1% of user top-1 locations in the 200 meter range.
Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Yuling Chen 0002, Yanli Ren, Haojin Zhu
IEEE Trans. Mob. Comput.3
2023 Privacy Computing with Right to Be Forgotten in Trusted Execution Environment
abstract
Sharing private data is at risk of potential data breaches, including the violation of the “right to be forgot-ten” principle, undermining people's willingness to share their data. A common solution is to involve the Trusted Execution Environment (TEE), which allows the data provider to verify the computation process without trusting others. However, previous works have either encountered incomplete computations or lacked scalability. In this paper, we propose TEERASE,a secure data-sharing framework that addresses these issues. TEERASEprotects every phase of the data lifecycle and enables individuals to share personal data with a predefined privacy budget. In particular, TEERASEapplies comprehensive privacy budgeting mechanisms to efficiently manage privacy budgets and employs an asynchronized execution approach that decouples budget consumption from data computation. TEERASErecords the predefined privacy budgets, verifies privacy consumption requests, updates the remaining budgets, and deletes data that have exhausted their budgets by preventing any attempts to access them. We implement a prototype of TEERASEand evaluate its effectiveness with a realistic case study on Genome-Wide Association Study.
Hongzhi Luo, Shaofeng Li 0001, Tian Dong 0003, Guoxing Chen, Yan Meng 0001, Haojin Zhu
GLOBECOM6
2023 Understanding and Identifying Cross-Platform UI Framework Based Potentially Unwanted Apps
abstract
Cross-platform UI frameworks may facilitate a new category of Potentially Unwanted Apps, dubbed XPUAs, which uses framework-specific language to implement its UI in the form of cross-platform payload. XPUAs are able to bypass the existing app vetting procedures leveraging their unique technical characteristics and make revenue on addicitive contents that are strictly prohibited by either local laws or app market regulations. In this paper, we first examined the profit chain of XPUAs and then proposed PUAXray, a novel detection system that utilized machine learning to identify XPUAs. PUAXray used a binary classifier that was trained on features extracted from cross-platform payloads, including semantics information and third-party library usage information. We evaluated PUAXray on a dataset that was created for the first time in the community with benign apps from reputable app markets and XPUAs from an industry collaborator. PUAXray achieved 95.4% F1-score in the XPUAs identification task, and proved capable to be extended to other cross-platform UI frameworks.
Guoxing Chen, Yan Meng 0001, Haojin Zhu
GLOBECOM3
2023 Data Poisoning Attack Against Anomaly Detectors in Digital Twin-Based Networks
abstract
In this paper, we study the abnormal behaviors detection and the corresponding data poisoning attacks in digital twin (DT)-based networks. We first analyze the abnormal behaviors existing in the DT-based networks, including environment anomalies, hardware and software faults, and network attacks. Specially, we design a machine learning (ML)-based anomaly detector to identify network attacks. Furthermore, due to the strong dependency of ML models on training data, in which the outputs of the trained ML models can be affected by the poisoned samples. We design a data poisoning attack scheme against the proposed ML-based anomaly detector, in which attackers can effectively compromise the output of anomaly detectors. Extensive experimental results adopting three commonly used ML-based models demonstrate that the attack can compromise these detectors with over 80% probability.
Shaofeng Li 0001, Wen Wu 0003, Yan Meng 0001, Jiachun Li 0001, Haojin Zhu, Xuemin Shen
ICC3
2023 MagFingerprint: A Magnetic Based Device Fingerprinting in Wireless Charging
Jiachun Li 0001, Yan Meng 0001, Guoxing Chen, Yuan Tian 0001, Haojin Zhu, Xuemin Shen
INFOCOM2
2023 De-anonymization Attacks on Metaverse
abstract
Virtual reality (VR) can provide users with an immersive experience in the metaverse. One of the most promising properties of VR is that users’ identities can be protected by changing their physical world appearances into arbitrary virtual avatars. However, recent proposed de-anonymization attacks demonstrate the feasibility of recognizing the user’s identity behind the VR avatar’s masking. In this paper, we propose AvatarHunter, a non-intrusive and user-unconscious de-anonymization attack based on victims’ inherent movement signatures. AvatarHunter imperceptibly collects the victim avatar’s gait information via recording videos from multiple views in the VR scenario without requiring any permission. A Unity-based feature extractor is designed that preserves the avatar’s movement signature while immune to the avatar’s appearance changes. Real-world experiments are conducted in VRChat, one of the most popular VR applications. The experimental results demonstrate that AvatarHunter can achieve attack success rates of 92.1% and 66.9% in closed-world and open-world avatar settings, respectively, which are much better than existing works.
Yan Meng 0001, Yuxia Zhan, Jiachun Li 0001, Suguo Du, Haojin Zhu, Xuemin Shen
INFOCOM1
2022 Thwarting Longitudinal Location Exposure Attacks in Advertising Ecosystem via Edge Computing
abstract
As geo-location data has been increasingly adopted as a high-profile feature in targeted advertising, exposing user real locations to untrusted cloud services or advertisers has raised severe privacy concerns. To protect location privacy with formal guarantee, a wide-stretched line of recent studies focuses on injecting controlled geo-indistinguishability (geo-IND) noise as per each location exposure. However, in advertising, over the course of 2 years, a single user can report and contribute near 1k location data points on average, which allows a longitudinal attacker to infer some statistics from the perturbed locations.In this study, we demonstrate the above-mentioned privacy risk via revealing an inference attack mechanism, coined as a longitudinal location exposure attack. This novel attack illustrates the possibility of recovering 75%∼90% of user top-1 locations (within only 200-meter range) among 37k users. In light of this deficiency, we propose a novel edge-assisted location privacy protection system, entitled Edge-PrivLocAd, that is adapted to location-based advertising. The novelty of Edge-PrivLocAd stems from our n-fold Gaussian mechanism, which adds permanent noise to the statistical user location profile and thus can defend against longitudinal attackers while balancing the privacy-utility trade-off. In addition, our system incorporates a posterior-based sampling technique into the location re-mapping process, that boosts location utility without privacy loss. We develop a fully-functioning prototype and empirically evaluate the proposed system. Our experimental results show that Edge-PrivLocAd is practical and scalable in real-world scenarios.
Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Haojin Zhu
ICDCS4
2022 Your Microphone Array Retains Your Identity: A Robust Voice Liveness Detection System for Smart Speakers
Yan Meng 0001, Jiachun Li 0001, Matthew Pillari, Arjun Deopujari, Liam Brennan, Hafsah Shamsie, Haojin Zhu, Yuan Tian 0001
USENIX Security Symposium1
2022 WiCapose: Multi-modal fusion based transparent authentication in mobile environments
Zhuo Chang, Yan Meng 0001, Haojin Zhu, Lin Wang 0023
J. Inf. Secur. Appl.2
2022 A Federated Learning Based Privacy-Preserving Smart Healthcare System
abstract
The rapid development of the smart healthcare system makes the early-stage detection of dementia disease more user-friendly and affordable. However, the main concern is the potential serious privacy leakage of the system. In this article, we take Alzheimer's disease (AD) as an example and design a convenient and privacy-preserving system namedADDetectorwith the assistance of Internet of Things (IoT) devices and security mechanisms. Particularly, to achieve effective AD detection,ADDetectoronly collects user's audio by IoT devices widely deployed in the smart home environment and utilizes novel topic-based linguistic features to improve the detection accuracy. For the privacy breach existing in data, feature, and model levels,ADDetectorachieves privacy-preserving by employing a unique three-layer (i.e., user, client, cloud, etc.) architecture. Moreover,ADDetectorexploitsfederated learning (FL) based schemeto ensure the user owns the integrity of raw data and secure the confidentiality of the classification model and implementdifferential privacy (DP) mechanismto enhance the privacy level of the feature. Furthermore, to secure the model aggregation process between clients and cloud in FL-based scheme, a novelasynchronous privacy-preserving aggregation frameworkis designed. We evaluateADDetectoron 1010 AD detection trials from 99 health and AD users. The experimental results show thatADDetectorachieves high accuracy of 81.9% and low time overhead of 0.7 s when implementing all privacy-preserving mechanisms (i.e., FL, DP, and cryptography-based aggregation).
Jiachun Li 0001, Yan Meng 0001, Lichuan Ma, Suguo Du, Haojin Zhu, Qingqi Pei, Xuemin Shen
IEEE Trans. Ind. Informatics2
2021 POSTER: ReAvatar: Virtual Reality De-anonymization Attack Through Correlating Movement Signatures
abstract
Virtual reality (VR) is on the precipice of entering mainstream entertainment with devices equipped with a multitude of sensing, tracking, and internet capabilities that can reshape the current infotainment industry such as online gaming or conferences with novel features. With VR techniques, the online gamer or conference attendances could choose to keep their identity anonymous by easily altering their appearances (i.e., avatars). However, in this study, we present ReAvatar, a novel de-anonymization attack that identifies users by their virtual avatar via a correlation in specific recorded movements. Using 3D pose estimation, we train a sophisticated machine learning model with user movement data recorded while performing a set of movements in real life and then again with their avatars. We then map correlations between these two sets of movement data using a bespoke agglomerative clustering algorithm and establish relationship between the user's virtual and real-life identity. ReAvatar achieves 89.60% accuracy in detecting a unique user among multiple avatars. The security and privacy implications of this paper will be foundational for users and researchers alike that explore the realm of virtual reality.
Brandon Falk, Yan Meng 0001, Yuxia Zhan, Haojin Zhu
CCS2
2021 Dissecting Click Fraud Autonomy in the Wild
abstract
Although the use of pay-per-click mechanisms stimulates the prosperity of the mobile advertisement network, fraudulent ad clicks result in huge financial losses for advertisers. Extensive studies identify click fraud according to click/traffic patterns based on dynamic analysis. However, in this study, we identify a novel click fraud, named humanoid attack, which can circumvent existing detection schemes by generating fraudulent clicks with similar patterns to normal clicks. We implement the first tool ClickScanner to detect humanoid attacks on Android apps based on static analysis and variational AutoEncoders (VAEs) with limited knowledge of fraudulent examples. We define novel features to characterize the patterns of humanoid attacks in the apps' bytecode level. ClickScanner builds a data dependency graph (DDG) based on static analysis to extract these key features and form a feature vector. We then propose a classification model only trained on benign datasets to overcome the limited knowledge of humanoid attacks.
Yan Meng 0001, Haotian Hu, Xiaokuan Zhang, Minhui Xue 0001, Haojin Zhu
CCS2
2021 Automatic Permission Optimization Framework for Privacy Enhancement of Mobile Applications
abstract
Mobile applications play a crucial role in the IoT system, which is experiencing unprecedented growth. However, users possessing little knowledge of permission configurations often accept app permission requests without reading them, which opens a backdoor for the potential adversaries to launch the future attacks. Proposing an automatic permission management scheme is an attractive solution to solve this issue, but since users have varying attitudes toward privacy, such a scheme would be neither straightforward nor user friendly. In this study, an automatic permission optimization framework, Permizer, is proposed to recommend different app permission configurations to users with different privacy preferences. Permizer estimates the permission risks and builds the permission-functionality mapping to each app, then regulates the relationship between permission and app functionality. Permizer is the first module to achieve a balance between privacy protection and app functionality under the personal privacy preference condition. Finally, we develop Permizer as a one-button service on the real-world Android OS with 58 apps. Case studies conducted on TikTok and Amazon Alexa also demonstrate its practicability and effectiveness.
Yiting Qu, Suguo Du, Shaofeng Li 0001, Yan Meng 0001, Haojin Zhu
IEEE Internet Things J.4
2021 Liveness Detection for Voice User Interface via Wireless Signals in IoT Environment
abstract
Voice interface has been a dominant User Interface (UI) channel in the popular smart home environment. Although Voice Control System (VCS) brings users conveniences, it is extremely vulnerable to spoofing attacks (e.g., hidden/inaudible command attack) due to its broadcast nature. In this study, to thwart spoofing attacks, we propose WSVA, a device-free voice liveness detection system based on the prevalent wireless signals generated by IoT devices without requiring user to carry any additional sensor or device. The basic insight of WSVA to distinguish the authentic voice command from a spoofed one is checking the consistency between the voice signal and its corresponding mouth motions, which can be captured by wireless signals. To achieve this goal, WSVA builds a theoretical model to describe the correlations among the wireless signal changes, the mouth motions, and the syllables in the voice command. Then, WSVA selects appropriate features from both voice and wireless signals, and calculates the consistency between these two types of signals to determine whether the VCS is suffering from the spoofing attack. To demonstrate the feasibility of WSVA, we conduct a case study on Samsung SmartThings platform and include WSVA as a new application, which is expected to significantly enhance the security of the existing VCS. We evaluate WSVA with various voice commands in different scenarios. Experimental results demonstrate that WSVA achieves the overall 99 percent true accept rate with 1 percent false accept rate with a good scalability and low latency.
Yan Meng 0001, Haojin Zhu, Jinlei Li, Jin Li 0002, Yao Liu 0007
IEEE Trans. Dependable Secur. Comput.1
2020 Securing App Behaviors in Smart Home: A Human-App Interaction Perspective
abstract
Smart home has become a mainstream lifestyle due to the maturity of the IoT platform and the popularity of smart devices. While offering great convenience and entertainment, smart home suffers from malicious attacks that inject improper commands and actions to home devices, which may breach the user's safety and privacy. Traditional solutions mainly focus on generating security policies relying on app analysis to constraint apps' behaviors. However, these policies lack flexibility to adapt to the highly dynamic smart home system. We need to consider not only the app behaviors but also the user behaviors for enforcing an appropriate security policy. In this study, we propose WiPolicy, a cross-layer security enforcement system for smart home by monitoring the behaviors of both apps and users. The key novelty of WiPolicy is incorporating user activity recognition via the physical-layer wireless signals into the definition and enforcement of security policies to constraint the app behavior. We implement WiPolicy on the Samsung SmartThings platform with 187 SmartApps, and 24 behavior policies are defined and enforced. The case study demonstrates the effectiveness of WiPolicy on thwarting app's misbehavior.
Jinlei Li, Yan Meng 0001, Haojin Zhu
ICPADS2
2020 Voiceprint Mimicry Attack Towards Speaker Verification System in Smart Home
abstract
The advancement of voice controllable systems (VC-Ses) has dramatically affected our daily lifestyle and catalyzed the smart home's deployment. Currently, most VCSes exploit automatic speaker verification (ASV) to prevent various voice attacks (e.g., replay attack). In this study, we present VMask, a novel and practical voiceprint mimicry attack that could fool ASV in smart home and inject the malicious voice command disguised as a legitimate user. The key observation behind VMask is that the deep learning models utilized by ASV are vulnerable to the subtle perturbations in the voice input space. To generate these subtle perturbations, VMask leverages the idea of adversarial examples. Then by adding the subtle perturbations to the recordings from an arbitrary speaker, VMask can mislead the ASV into classifying the crafted speech samples, which mirror the former speaker for human, as the targeted victim. Moreover, psychoacoustic masking is employed to manipulate the adversarial perturbations under human perception threshold, thus making victim unaware of ongoing attacks. We validate the effectiveness of VMask by performing comprehensive experiments on both grey box (VGGVox) and black box (Microsoft Azure Speaker Verification) ASVs. Additionally, a real-world case study on Apple HomeKit proves the VMask's practicability on smart home platforms.
Yan Meng 0001, Jiahao Yu 0001, Chong Xiang 0001, Brandon Falk, Haojin Zhu
INFOCOM2
2020 Revealing Your Mobile Password via WiFi Signals: Attacks and Countermeasures
abstract
In this study, we present WindTalker, a novel and practical keystroke inference framework that can be used to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from an observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). An attacker can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's password input. Compared with the previous keystroke inference approaches, WindTalker neither deploys external equipment physically close to the target device nor compromises the target device. Instead, it employs a more practical setting by deploying a free public WiFi hotspot and collects the CSI data from the target device as long as the device is connected to the hotspot. In addition, to improve inference accuracy and efficiency, it analyzes the WiFi traffic to selectively collect CSI only for the sensitive period where password entering occurs. WindTalker can be implemented without the requirement of visually seeing the target device, or installing any malware on the device. We tested Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. Furthermore, we proposed a novel CSI obfuscation countermeasure to thwart the inference attack. The evaluation results show that the performance of WindTalker can be dramatically reduced by adopting the proposed countermeasures.
Yan Meng 0001, Jinlei Li, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan
IEEE Trans. Mob. Comput.1
2019 An Ensemble Approach for Suspicious Traffic Detection from High Recall Network Alerts
abstract
Web services from large-scale systems are prevalent all over the world. However, these systems are naturally vulnerable and incline to be intruded by adversaries for illegal benefits. To detect anomalous events, previous works focus on inspecting raw system logs by identifying the outliers in workflows or relying on machine learning methods. Though those works successfully identify the anomalies, their models use large training set and process whole system logs. To reduce the quantity of logs that need to be processed, high recall suspicious network alert systems can be applied to preprocess system logs. Only the logs that trigger alerts are retrieved for further usage. Due to the universally usage of network traffic alerts among Security Operations Center, anomalies detection problems could be transformed to classify truly suspicious network traffic alerts from false alerts. In this work, we propose an ensemble model to distinguish truly suspicious alerts from false alerts. Our model consists of two sub-models with different feature extraction strategies to ensure the diversity and generalization. We use decision tree based boosters and deep neural networks to build ensemble models for classification. Finally, we evaluate our approach on suspicious network alerts dataset provided by 2019 IEEE BigData Cup: Suspicious Network Event Recognition. Under the metric of AUC scores, our model achieves 0.9068 on the whole testing set.
Jinlei Li, Yan Meng 0001, Haojin Zhu
IEEE BigData3
2019 Edge-Assisted Stream Scheduling Scheme for the Green-Communication-Based IoT
abstract
The consumer Internet of Things (IoT), which exploits wireless personal area network (WPAN) technology, is undergoing rapid growth. Although the consumer IoT enables users to control many devices and offers conveniences and benefits for daily life, its long-term operation capabilities are subject to a bottleneck related to power management. To save energy and prolong the lifetime of an IoT system, the basic idea is to allow idle devices to go to sleep. Because excessively frequent switching between the awake and asleep phases will consume a significant amount of power, it is essential to properly schedule the order of multiple communication streams among multiple devices such that the total number of wake-up events is as small as possible. Based on the typical communication protocols deployed in IoT systems, this problem can be divided into two cases: 1) the inter-superframe case and the 2) intrasuperframe case. The former case has been well studied in existing works, whereas research on the latter case is currently immature. In this paper, we propose an efficient scheme for addressing the stream order scheduling (SOS) problem in the intrasuperframe case. Mobile edge computing technology is utilized in the proposed scheme to reduce the network load, and three heuristic algorithms are proposed to improve the scheme's performance. We report various tests conducted on 4800 random original IoT topologies and 19000 random Hamiltonian edge-dual topologies, and the experimental results demonstrate that our scheme achieves optimal solutions with a very high success probability.
Licheng Wang 0004, Yan Meng 0001, Haojin Zhu, Minxing Tang, Kaoru Ota
IEEE Internet Things J.2
2018 HoMonit: Monitoring Smart Home Apps from Encrypted Traffic
abstract
Smart home is an emerging technology for intelligently connecting a large variety of smart sensors and devices to facilitate automation of home appliances, lighting, heating and cooling systems, and security and safety systems. Our research revolves around Samsung SmartThings, a smart home platform with the largest number of apps among currently available smart home platforms. The previous research has revealed several security flaws in the design of SmartThings, which allow malicious smart home apps (or SmartApps) to possess more privileges than they were designed and to eavesdrop or spoof events in the SmartThings platform. To address these problems, this paper leverages side-channel inference capabilities to design and develop a system, dubbed HoMonit, to monitor SmartApps from encrypted wireless traffic. To detect anomaly, HoMonit compares the SmartApps activities inferred from the encrypted traffic with their expected behaviors dictated in their source code or UI interfaces. To evaluate the effectiveness of HoMonit, we analyzed 181 official SmartApps and performed evaluation on 60 malicious SmartApps, which either performed over-privileged accesses to smart devices or conducted event-spoofing attacks. The evaluation results suggest that HoMonit can effectively validate the working logic of SmartApps and achieve a high accuracy in the detection of SmartApp misbehaviors.
Wei Zhang 0001, Yan Meng 0001, Yugeng Liu, Xiaokuan Zhang, Yinqian Zhang, Haojin Zhu
CCS2
2018 Detecting Vehicle Anomaly by Sensor Consistency: An Edge Computing Based Mechanism
abstract
Autonomous vehicles are expected to be a disruptive technology that has the potential to revolutionize the human mobility. However, the recent research progress on intra-vehicle network (e.g., the revealing of a series of security vulnerabilities of CAN design) has demonstrated that the security issue still represents one of the major challenges of future self-driving cars. In this study, we propose a novel edge based anomaly detection system, coined VeAnDe, which exploits edge based sensor data fusion to identify the anomaly events. VeAnDe analyzes pair-wise correlations between different intra-vehicle sensors, and utilizes these correlations to examine whether an anomaly has occurred within the vehicle. More specifically, the pair-wise correlations are organized as ring architecture to reduce the computation overhead. Furthermore, the major components of VeAnDe are embedded in edge computing devices, which enables VeAnDe to be more efficient and privacy-preserving. We evaluate the performance of VeAnDe under different scenarios, and our experimental results demonstrate its feasibility and efficiency.
Zichang Wang, Fei Guo 0003, Yan Meng 0001, Huaxin Li, Haojin Zhu, Zhenfu Cao
GLOBECOM3
2018 WiVo: Enhancing the Security of Voice Control System via Wireless Signal in IoT Environment
abstract
With the prevalent of smart devices and home automations, voice command has become a popular User Interface (UI) channel in the IoT environment. Although Voice Control System (VCS) has the advantages of great convenience, it is extremely vulnerable to the spoofing attack (e.g., replay attack, hidden/inaudible command attack) due to its broadcast nature. In this study, we present WiVo, a device-free voice liveness detection system based on the prevalent wireless signals generated by IoT devices without any additional devices or sensors carried by the users. The basic motivation of WiVo is to distinguish the authentic voice command from a spoofed one via its corresponding mouth motions, which can be captured and recognized by wireless signals. To achieve this goal, WiVo builds a theoretical model to characterize the correlation between wireless signal dynamics and the user's voice syllables. WiVo extracts the unique features from both voice and wireless signals, and then calculates the consistency between these different types of signals in order to determine whether the voice command is generated by the authentic user of VCS or an adversary. To evaluate the effectiveness of WiVo, we build a testbed based on Samsung SmartThings framework and include WiVo as a new application, which is expected to significantly enhance the security of the existing VCS. We have evaluated WiVo with 6 participants and different voice commands. Experimental evaluation results demonstrate that WiVo achieves the overall 99% detection rate with 1% false accept rate and has a low latency.
Yan Meng 0001, Zichang Wang, Wei Zhang 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007
MobiHoc1
2016 When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi Signals
abstract
In this study, we present WindTalker, a novel and practical keystroke inference framework that allows an attacker to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from the observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's number input. WindTalker presents a novel approach to collect the target's CSI data by deploying a public WiFi hotspot. Compared with the previous keystroke inference approach, WindTalker neither deploys external devices close to the target device nor compromises the target device. Instead, it utilizes the public WiFi to collect user's CSI data, which is easy-to-deploy and difficult-to-detect. In addition, it jointly analyzes the traffic and the CSI to launch the keystroke inference only for the sensitive period where password entering occurs. WindTalker can be launched without the requirement of visually seeing the smart phone user's input process, backside motion, or installing any malware on the tablet. We implemented Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. The evaluation results show that the attacker can recover the key with a high successful rate.
Mengyuan Li 0004, Yan Meng 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan
CCS2