VLDB 2026 Research / reviewers in the wild / expert
Chen Yan 0001
dblp:46/1162-1
· DBLP profile ↗
41ranked-venue papers
4as first author
36since 2021 · last 2026
0000-0003-4430-5263ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 4 first-author · 27 since 2021Computer networks · 8 · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities
Shilin Xiao, Kai Wang 0073, Peiwang Wang, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 6 |
| 2026 | PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal Fuzzing
Zhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 5 |
| 2026 | VoltSiren: Exploiting Power Supply Vulnerabilities to Control IoT DevicesabstractThis paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing, actuating, and communicating. Particularly, we discover a vulnerability in power supply modules and propose VoltSiren attacks. To launch a VoltSiren attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Consequently, VoltSiren attacks can cause sensor measurements irrelevant to reality, maneuver actuators in a way disregarding the desired command, or disrupt communications. To understand VoltSiren, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensors, actuators, or communication modules. Based on these findings, we implement and validate VoltSiren on off-the-shelf products: six sensors, three actuators, and two communication modules, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The root cause of this vulnerability lies in the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks. Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Ruochen Zhou, Kaixiang Zhang 0002, Wenyuan Xu 0001 |
IEEE Internet Things J. | 5 |
| 2026 | Critical Information Only: A Content Privacy-Preserving Framework for Detecting Audio DeepfakesabstractText-to-Speech (TTS) and Voice Conversion (VC) models have exhibited remarkable performance in generating realistic and natural audio. However, their dark side, audio deepfake poses a significant threat to both society and individuals. Existing countermeasures largely focus on determining the genuineness of speech based on complete original audio recordings, which however often contain private content. This oversight may refrain deepfake detection from many applications, particularly in scenarios involving sensitive information like business secrets. In this paper, we propose SafeEar, a novel framework that aims to detect deepfake audios without relying on accessing the speech content within. Our key idea is to devise a neural audio codec into a novel decoupling model that well separates the semantic and acoustic information from audio samples, and only use the acoustic information (e.g., prosody and timbre) for deepfake detection. In this way, no semantic content will be exposed to the detector. To overcome the challenge of identifying diverse deepfake audio without semantic clues, we enhance our deepfake detector with real-world augmentation, such as codecs and reverbs. Extensive experiments conducted on five benchmark datasets demonstrate SafeEar's effectiveness in detecting various deepfake techniques with an equal error rate (EER) down to 2.41%. Simultaneously, it shields f ive-language speech content from being deciphered by both machine and human auditory analysis, demonstrated by word error rates (WERs) all above 93.74% and our user study. Furthermore, our benchmark constructed for anti-deepfake and anti-content recovery evaluation helps provide a basis for future research in the realms of audio privacy preservation and deepfake detection. Xinfeng Li, Yifan Zheng 0001, Chen Yan 0001, Kai Li 0047, Chang Zeng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR
Zizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 4 |
| 2025 | GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference
Yanze Ren, Qinhong Jiang, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 3 |
| 2025 | LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference
Fengchen Yang, Wenze Cui, Xinfeng Li, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 4 |
| 2025 | ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters
Fengchen Yang, Zihao Dan, Kaikai Pan, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 4 |
| 2025 | Laser-Based LiDAR Spoofing: Effects Validation, Capability Quantification, and CountermeasuresabstractAutonomous vehicles (AVs) and robots increasingly exploit light detection and ranging (LiDAR)-based 3-D object detection systems to detect obstacles in the environment. Correct detection and classification are important to ensure safe driving. Although previous work has demonstrated the feasibility of manipulating point clouds to spoof 3-D object detectors, most of these attempts are performed digitally. In this article, we investigate the possibility of physically fooling LiDAR-based 3-D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We further analyze the impact of our attacks on four fusion-based detectors. This article concludes with experiments on defense methods and discussion on potential defense strategies at both the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 5 |
| 2024 | SafeEar: Content Privacy-Preserving Audio Deepfake Detection
Xinfeng Li, Kai Li 0047, Yifan Zheng 0001, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
CCS | 4 |
| 2024 | SafeGen: Mitigating Sexually Explicit Content Generation in Text-to-Image ModelsabstractText-to-image (T2I) models, such as Stable Diffusion, have exhibited remarkable performance in generating high-quality images from text descriptions in recent years. However, text-to-image models may be tricked into generating not-safe-for-work (NSFW) content, particularly in sexually explicit scenarios. Existing countermeasures mostly focus on filtering inappropriate inputs and outputs, or suppressing improper text embeddings, which can block sexually explicit content (e.g., naked) but may still be vulnerable to adversarial prompts -- inputs that appear innocent but are ill-intended. In this paper, we present SafeGen, a framework to mitigate sexual content generation by text-to-image models in a text-agnostic manner. The key idea is to eliminate explicit visual representations from the model regardless of the text input. In this way, the text-to-image model is resistant to adversarial prompts since such unsafe visual representations are obstructed from within. Extensive experiments conducted on four datasets and large-scale user studies demonstrate SafeGen's effectiveness in mitigating sexually explicit content generation while preserving the high-fidelity of benign images. SafeGen outperforms eight state-of-the-art baseline methods and achieves 99.4% sexual content removal performance. Furthermore, our constructed benchmark of adversarial prompts provides a basis for future development and evaluation of anti-NSFW-generation methods. Xinfeng Li, Jiangyi Deng, Chen Yan 0001, Yanjiao Chen, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
CCS | 4 |
| 2024 | Understanding Impacts of Electromagnetic Signal Injection Attacks on Object DetectionabstractObject detection can localize and identify objects in images, and it is extensively employed in critical multimedia applications such as security surveillance and autonomous driving. Despite the success of existing object detection models, they are often evaluated in ideal scenarios where captured images guarantee the accurate and complete representation of the detecting scenes. However, images captured by image sensors may be affected by different factors in real applications, including cyber-physical attacks. In particular, attackers can exploit hardware properties within the systems to inject electromagnetic interference so as to manipulate the images. Such attacks can cause noisy or incomplete information about the captured scene, leading to incorrect detection results, potentially granting attackers malicious control over critical functions of the systems. This paper presents a research work that comprehensively quantifies and analyzes the impacts of such attacks on state-of-the-art object detection models in practice. It also sheds light on the underlying reasons for the incorrect detection outcomes. Youqian Zhang, Eugene Yujun Fu, Qinhong Jiang, Chen Yan 0001, Sze-Yiu Chau, Grace Ngai, Hong Va Leong, Xiapu Luo, Wenyuan Xu 0001 |
ICME | 5 |
| 2024 | GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards
Qinhong Jiang, Yanze Ren, Yan Long 0002, Chen Yan 0001, Yumai Sun, Xiaoyu Ji 0001, Kevin Fu, Wenyuan Xu 0001 |
NDSS | 4 |
| 2024 | Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time
Xinfeng Li, Chen Yan 0001, Xuancun Lu, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 2 |
| 2024 | EM Eye: Characterizing Electromagnetic Side-channel Eavesdropping on Embedded Cameras
Yan Long 0002, Qinhong Jiang, Chen Yan 0001, Tobias Alam, Xiaoyu Ji 0001, Wenyuan Xu 0001, Kevin Fu |
NDSS | 3 |
| 2024 | Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack
Zizhi Jin, Xuancun Lu, Yushi Cheng, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
WWW | 5 |
| 2024 | Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial UltrasoundabstractAutomatic Speaker Recognition Systems (SRSs) have been widely used in voice applications for personal identification and access control. A typical SRS consists of three stages, i.e., training, enrollment, and recognition. Previous work has revealed that SRSs can be bypassed by backdoor attacks at the training stage or by adversarial example attacks at the recognition stage. In this paper, we propose TUNER, a new type of backdoor attack against the enrollment stage of SRS via adversarial ultrasound modulation, which is inaudible, synchronization-free, content-independent, and black-box. Our key idea is to first inject the backdoor into the SRS with modulated ultrasound when a legitimate user initiates the enrollment, and afterward, the polluted SRS will grant access to both the legitimate user and the adversary with high confidence. Our attack faces a major challenge of unpredictable user articulation at the enrollment stage. To overcome this challenge, we generate the ultrasonic backdoor by augmenting the optimization process with random speech content, vocalizing time, and volume of the user. Furthermore, to achieve real-world robustness, we improve the ultrasonic signal over traditional methods using sparse frequency points, pre-compensation, and single-sideband (SSB) modulation. We extensively evaluate TUNER on two common datasets and seven representative SRS models, as well as its robustness against seven kinds of defenses. Results show that our attack can successfully bypass speaker recognition systems while remaining effective to various speakers, speech content, etc. To mitigate this newly discovered threat, we also provide discussions on potential countermeasures, limitations, and future works of this new threat. Xinfeng Li, Junning Ze, Chen Yan 0001, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Toward Pitch-Insensitive Speaker Verification via SoundfieldabstractAutomatic speaker verification systems (ASVs) verify a person’s identity by his/her voice and have been widely deployed for user authentication. However, existing ASVs are based on traditional audio spectral features and hence, perform poorly in verifying pitch-changed utterances from speakers with cold or sore throat. In this article, we propose soundfield tracker(SOFTER), a soundfield-based speaker verification system that can verify speakers regardless of the pitch changes.SOFTERis based on the observation that soundfield features reflect the speaker’s vocal tract, mouth, head, torso, etc., which are less affected by the pitch changes in speech signals.SOFTERcan be integrated into off-the-shelf smartphones without any hardware modifications. One major challenge is that the soundfield is sensitive to the distance between the speaker and the phone. To solve this problem, we propose a two-stage mechanism combining distance sensing and soundfield reconstruction, which enables to reconstruct the soundfield to a setting similar to the one in the enrollment phase, thus, the speaker can be verified from any distance to the phone. We compareSOFTERwith six state-of-the-art academic and commercial ASVs on two data sets of 134 speakers and 31000 speech samples. Results show thatSOFTERhas an equal error rate (EER) of 2.18% and 1.61% on the two data sets, respectively. Moreover,SOFTERoutperforms other ASVs by at least 24.67% on average in verifying pitch-varying or pathological speech samples, denoting an evidence ofSOFTER’s effectiveness in both normal and unhealthy user conditions. Xinfeng Li, Zhicong Zheng, Chen Yan 0001, Chaohao Li, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Marionette: Manipulate Your Touchscreen via a Charging CableabstractThe security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. This paper presentsMarionette, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables and can manipulate the victim's devices with undesired consequences, e.g., establishing malicious Bluetooth connections. Our study provides a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various USB data blockers and power adapters. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affecting the touch measurement mechanism and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks, i.e., injection, alteration, and Denial-of-Service, and the evaluation of 12 commercial electronics, 6 power adapters, and 13 charging cables demonstrate the feasibility ofMarionette. Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Analyzing and Defending GhostTouch Attack Against Capacitive TouchscreensabstractCapacitive touchscreens have become the primary human-machine interface for personal devices such as smartphones and tablets. In this paper, we presentGhostTouch, the first active contactless attack against capacitive touchscreens.GhostTouchuses electromagnetic interference (EMI) to inject fake touch points into a touchscreen without the requirement to physically touch it. By tuning the parameters of the electromagnetic signal and adjusting the antenna, we can inject two types of basic touch events, taps and swipes, into targeted locations of the touchscreen and control them to manipulate the underlying device. We successfully launch theGhostTouchattacks on nine smartphone models. We can inject targeted taps continuously with a standard deviation of as low as$14.6 \times 19.2$pixels from the target area, and a distance of up to$40mm$. We show the real-world impact of theGhostTouchattacks in a few proof-of-concept scenarios, including pressing the button, answering an eavesdropping phone call, and swiping up to unlock. Finally, we propose touchscreen reinforcement and attack detection mechanisms to mitigate the threat ofGhostTouchattack. Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Detecting Hidden Voice Recorders via ADC Electromagnetic RadiationabstractUnauthorized covert voice recording presents a significant threat to privacy-sensitive scenarios, such as confidential meetings and private conversations. Due to their miniaturization and disguise characteristics, hidden voice recorders are difficult to notice. In this article, we present DeHiREC , the first proof-of-concept system capable of detecting offline hidden voice recorders from their electromagnetic radiations (EMR). We first characterize the unique patterns of the emanated EMR signals and then locate the EMR source, i.e., the analog-to-digital converter module embedded in the mixed signal system-on-chips. Since these unintentional EMR signals can be extremely noisy and weak, accurately detecting them can be challenging. To address this challenge, we design an EMR Catalyzing method to actively stimulate the EMR signals and then employ an adaptive-folding algorithm to improve the signal-to-noise ratio of the sensed EMRs. We evaluate the performance of DeHiREC on 18 commercial voice recorders under various impacts, including interference from other devices. Experimental results reveal that DeHiREC is effective in detecting all 18 voice recorders and achieves an overall success rate of 94.72% and a recall rate of 92.03% at a distance of 0.2 m. Ruochen Zhou, Xiaoyu Ji 0001, Chen Yan 0001, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 4 |
| 2023 | MicPro: Microphone-based Voice Privacy ProtectionabstractHundreds of hours of audios are recorded and transmitted over the Internet for voice interactions such as virtual calls or speech recognitions. As these recordings are uploaded, embedded biometric information, i.e., voiceprints, is unnecessarily exposed. This paper proposes the first privacy-enhanced microphone module (i.e., MicPro) that can produce anonymous audio recordings with biometric information suppressed while preserving speech quality for human perception or linguistic content for speech recognition. Limited by the hardware capabilities of microphone modules, previous works that modify recording at the software level are inapplicable. To achieve anonymity in this scenario, MicPro transforms formants, which are distinct for each person due to the unique physiological structure of the vocal organs, and formant transformations are done by modifying the linear spectrum frequencies (LSFs) provided by a popular codec (i.e., CELP) in low-latency communications. Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Zhicong Zheng, Wenyuan Xu 0001 |
CCS | 3 |
| 2023 | The Silent Manipulator: A Practical and Inaudible Backdoor Attack against Speech Recognition SystemsabstractBackdoor Attacks have been shown to pose significant threats to automatic speech recognition systems (ASRs). Existing success largely assumes backdoor triggering in the digital domain, or the victim will not notice the presence of triggering sounds in the physical domain. However, in practical victim-present scenarios, the over-the-air distortion of the backdoor trigger and the victim awareness raised by its audibility may invalidate such attacks. In this paper, we propose SMA, an inaudible grey-box backdoor attack that can be generalized to real-world scenarios where victims are present by exploiting both the vulnerability of microphones and neural networks. Specifically, we utilize the nonlinear effects of microphones to inject an inaudible ultrasonic trigger. To accurately characterize the microphone response to the crafted ultrasound, we construct a novel nonlinear transfer function for effective optimization. We also design optimization objectives to ensure triggers' robustness in the physical world and transferability on unseen ASR models. In practice, SMA can bypass the microphone's built-in filters and human perception, activating the implanted trigger in the ASRs inaudibly, regardless of whether the user is speaking. Extensive experiments show that the attack success rate of SMA can reach nearly 100% in the digital domain and over 85% against most microphones in the physical domains by only poisoning about 0.5% of the training audio dataset. Moreover, our attack can resist typical defense countermeasures to backdoor attacks. Zhicong Zheng, Xinfeng Li, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ACM Multimedia | 3 |
| 2023 | BitDance: Manipulating UART Serial Communication with IEMIabstractWired serial communication protocols such as UART are widely used in today’s IoT systems for their simple connection and good industry ecology. However, due to the simplicity of these protocols, they are vulnerable to attacks that falsify the communication. In this work, we propose the BitDance attack that can arbitrarily flip the bits of serial communication without any physical contact utilizing intentional electromagnetic interference (IEMI). We describe the physical process of how electromagnetic interference influences the voltage, build up a model to demonstrate the bit-level control principle of our work, and implement the attack on 6 different sensors with UART, a widely used serial communication protocol. The result shows we can inject bit-level information and disable legitimate communication from the system with a maximum success rate of 45.4 and 100. Finally, we propose countermeasures to mitigate the impact of this attack. Zhixin Xie, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
RAID | 2 |
| 2023 | PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous VehicleabstractAutonomous vehicles and robots increasingly exploit LiDAR-based 3D object detection systems to detect obstacles in environment. Correct detection and classification are important to ensure safe driving. Though existing work has demonstrated the feasibility of manipulating point clouds to spoof 3D object detectors, most of the attempts are conducted digitally. In this paper, we investigate the possibility of physically fooling LiDAR-based 3D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, which is 20 times more than prior work, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We also discuss defense strategies at the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
SP | 5 |
| 2023 | Private Eye: On the Limits of Textual Screen Peeking via Eyeglass Reflections in Video ConferencingabstractPersonal video conferencing has become a new norm after COVID-19 caused a seismic shift from in-person meetings and phone calls to video conferencing for daily communications and sensitive business. Video leaks participants’ on-screen information because eyeglasses and other reflective objects unwittingly expose partial screen contents. Using mathematical modeling and human subjects experiments, this research explores the extent to which emerging webcams might leak recognizable textual and graphical information gleaming from eyeglass reflections captured by webcams. The primary goal of our work is to measure, compute, and predict the factors, limits, and thresholds of recognizability as webcam technology evolves in the future. Our work explores and characterizes the viable threat models based on optical attacks using multi-frame super resolution techniques on sequences of video frames. Our models and experimental results in a controlled lab setting show it is possible to reconstruct and recognize with over 75% accuracy on-screen texts that have heights as small as 10 mm with a 720p webcam. We further apply this threat model to web textual contents with varying attacker capabilities to find thresholds at which text becomes recognizable. Our user study with 20 participants suggests present-day 720p webcams are sufficient for adversaries to reconstruct textual content on big-font websites. Our models further show that the evolution towards 4K cameras will tip the threshold of text leakage to reconstruction of most header texts on popular websites. Besides textual targets, a case study on recognizing a closed-world dataset of Alexa top 100 websites with 720p webcams shows a maximum recognition accuracy of 94% with 10 participants even without using machine-learning models. Our research proposes near-term mitigations including a software prototype that users can use to blur the eyeglass areas of their video streams. For possible long-term defenses, we advocate an individual reflection testing procedure to assess threats under various settings, and justify the importance of following the principle of least privilege for privacy-sensitive scenarios. Yan Long 0002, Chen Yan 0001, Shilin Xiao, Shivan Prasad, Wenyuan Xu 0001, Kevin Fu |
SP | 2 |
| 2023 | Volttack: Control IoT Devices by Manipulating Power Supply VoltageabstractThis paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing and actuating. Particularly, we discover a vulnerability in power supply modules and propose Volttack attacks. To launch a Volttack attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Eventually, Volttack attacks may cause the sensor measurement irrelevant to reality or maneuver the actuator in a way disregarding the desired command. To understand Volttack, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensor or actuator modules. Derived from these findings, we implement and validate Volttack on off-the-shelf products: 6 sensors and 3 actuators, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The consequences of manipulating the sensor measurement or actuation include doubled car braking distance and a natural gas leak. The root cause of such a vulnerability stems from the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks. Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Wenyuan Xu 0001 |
SP | 4 |
| 2023 | DeHiREC: Detecting Hidden Voice Recorders via ADC Electromagnetic RadiationabstractUnauthorized covert voice recording brings a remarkable threat to privacy-sensitive scenarios, such as confidential meetings and private conversations. Due to the miniaturization and disguise characteristics, hidden voice recorders are difficult to be noticed in their surroundings. In this paper, we present DeHiREC, the first proof-of-concept system that can detect offline hidden voice recorders from their electromagnetic radiations (EMR). We first characterize the unique patterns of the emanated EMR signals and then locate the EMR source, i.e., the analog-to-digital converter (ADC) module embedded in the mixed signal system-on-chips (MSoCs). Since these unintentional EMR signals can be extremely noisy and weak, accurately detecting them can be challenging. To address this challenge, we first design an EMR Catalyzing method to stimulate the EMR signals actively and then employ an adaptive-folding algorithm to improve the signal-to-noise ratio (SNR) of the sensed EMRs. Once the sensed EMR variation corresponds to our active stimulation, we can determine that there exists a hidden voice recorder. We evaluate the performance of DeHiREC on 13 commercial voice recorders under various impacts, including interference from other devices. Experimental results reveal that DeHiREC is effective in detecting all 13 voice recorders and achieves an overall success rate of 92.17% and a recall rate of 86.14% at a distance of 0.2 m. Ruochen Zhou, Xiaoyu Ji 0001, Chen Yan 0001, Yi-Chao Chen 0001, Wenyuan Xu 0001, Chaohao Li |
SP | 3 |
| 2023 | GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMI
Qinhong Jiang, Xiaoyu Ji 0001, Chen Yan 0001, Zhixin Xie, Haina Lou, Wenyuan Xu 0001 |
USENIX Security Symposium | 3 |
| 2023 | Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice Attacks
Xinfeng Li, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Zhenning Zhang, Wenyuan Xu 0001 |
USENIX Security Symposium | 3 |
| 2022 | WIGHT: Wired Ghost Touch Attack on Capacitive TouchscreensabstractThe security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. To the best of our knowledge, this paper presents WIGHT, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables, and can manipulate the victim devices with undesired consequences, e.g., allowing malicious Bluetooth connections, accepting files with viruses, etc. Our study calls for attention to a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various power adapters and even USB data blockers. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affect the touch measurement mechanism, and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks: injection attacks that create ghost touches without users touching the screen, alteration attacks that change the detected legitimate touch position, and Denial-of-Service attacks that prevent the device from identifying legitimate touches. Our evaluation on 6 smartphones, 1 tablet, 2 standalone touchscreen panels, 6 power adapters, and 13 charging cables demonstrates the feasibility of all three type attacks. Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001 |
SP | 4 |
| 2022 | GhostTouch: Targeted Attacks on Touchscreens without Physical Touch
Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001 |
USENIX Security Symposium | 3 |
| 2022 | Rolling Colors: Adversarial Laser Exploits against Traffic Light Recognition
Chen Yan 0001, Zhanyuan Yin, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
USENIX Security Symposium | 1 |
| 2022 | A Nonlinearity-Based Secure Face-to-Face Device Authentication for Mobile DevicesabstractWith the proliferation of mobile devices, face-to-face device-to-device (D2D) communication has been applied to a variety of daily scenarios such as mobile payment and short distance file transfer. In D2D communications, a critical security problem is to verify the device legitimacy when they share no secrets in advance. Previous research proposed device authentication schemes based on pre-built database or exploiting physical properties. However, a remaining challenge is to secure face-to-face D2D communication even in the middle of a crowd, within which an attacker may hide. In this paper, we presentNAuth, a nonlinearity-enhanced, location-sensitive authentication mechanism. Especially, we target at the secure authentication within a limited range such as 20 cm, which is typical for face-to-face scenarios.NAuthdesigns averification schemebased on the nonlinear distortion of speaker-microphone systems and a location-basedvalidation model. The verification scheme guarantees device authentication consistency by extracting acoustic nonlinearity patterns (ANP) while the validation model ensures device legitimacy by measuring the time difference of arrival (TDOA) at two microphones. We analyze the feasibility and security ofNAuththeoretically and evaluate its performance experimentally. Results demonstrate thatNAuthcan verify the device legitimacy in the presence of nearby attackers. Xiaoyu Ji 0001, Chen Yan 0001, Jiangyi Deng, Wenyuan Xu 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionabstractAutonomous vehicles increasingly exploit computer-vision-based object detection systems to perceive environments and make critical driving decisions. To increase the quality of images, image stabilizers with inertial sensors are added to alleviate image blurring caused by camera jitters. However, such a trend opens a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of the emerging image stabilizer hardware susceptible to acoustic manipulation and the object detection algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even if the camera is stable. The blurred images can then induce object misclassification affecting safety-critical decision making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks, i.e., hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against four academic object detectors (YOLO V3/V4/V5 and Fast R-CNN), and one commercial detector (Apollo). We further introduce the concept of AMpLe attacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware. Xiaoyu Ji 0001, Yushi Cheng, Kai Wang 0073, Chen Yan 0001, Wenyuan Xu 0001, Kevin Fu |
SP | 5 |
| 2021 | The Feasibility of Injecting Inaudible Voice Commands to Voice AssistantsabstractVoice assistants (VAs) such as Siri and Google Now have become an increasingly popular human-machine interaction method and have made various systems voice controllable. Prior work on attacking voice assistants shows that the hidden voice commands that are incomprehensible to people can control the VAs. Hidden voice commands, though `hidden', are nonetheless audible. In this work, we design a completely inaudible attack, DolphinAttack, that modulates voice commands on ultrasonic carriers to achieve inaudibility. By leveraging the nonlinearity of the microphone circuits, the modulated low-frequency audio commands can be successfully demodulated, recovered, and more importantly interpreted by the voice assistants. We validate DolphinAttack on popular voice assistants, including Siri, Google Now, S Voice, HiVoice, Cortana, Alexa, etc. By injecting a sequence of inaudible voice commands, we show a few proof-of-concept attacks, which include activating Siri to initiate a FaceTime call on iPhone, activating Google Now to turn on the airplane mode, and even manipulating the navigation system in an Audi automobile. We propose hardware and software defense solutions. We validate that it is feasible to detect DolphinAttack by classifying the audios using supported vector machine (SVM), and suggest to re-design voice assistants to be resilient to inaudible voice command attacks. Chen Yan 0001, Xiaoyu Ji 0001, Tianchen Zhang, Taimin Zhang, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | SoK: A Minimalist Approach to Formalizing Analog Sensor SecurityabstractOver the last six years, several papers demonstrated how intentional analog interference based on acoustics, RF, lasers, and other physical modalities could induce faults, influence, or even control the output of sensors. Damage to the availability and integrity of sensor output carries significant risks to safety-critical systems that make automated decisions based on trusted sensor measurement. Established signal processing models use transfer functions to express reliability and dependability characteristics of sensors, but existing models do not provide a deliberate way to express and capture security properties meaningfully.Our work begins to fill this gap by systematizing knowledge of analog attacks against sensor circuitry and defenses. Our primary contribution is a simple sensor security model such that sensor engineers can better express analog security properties of sensor circuitry without needing to learn significantly new notation. Our model introduces transfer functions and a vector of adversarial noise to represent adversarial capabilities at each stage of a sensor's signal conditioning chain. The primary goals of the systematization are (1) to enable more meaningful quantification of risk for the design and evaluation of past and future sensors, (2) to better predict new attack vectors, and (3) to establish defensive design patterns that make sensors more resistant to analog attacks. Chen Yan 0001, Hocheol Shin, Connor Bolton, Wenyuan Xu 0001, Yongdae Kim, Kevin Fu |
SP | 1 |
| 2019 | The Catcher in the Field: A Fieldprint based Spoofing Detection for Text-Independent Speaker VerificationabstractVerifying the identity of voice inputs is important as voices are increasingly used for sensitive operations. Traditional methods focus on differentiating individuals via the spectrographic features of voices (e.g., voiceprint), yet cannot cope with spoofing attacks, whereby a malicious attacker synthesizes the voice with almost the same voiceprint of a victim or simply replays it. This paper proposes CaField, a text-independent speaker verification method to detect loudspeaker-based voice spoofing attacks with the goal of achieving two seemingly conflicting requirements: usability and security. The key insight of CaField is to construct "fieldprint'' with the acoustic biometrics embedded in sound fields, i.e., a physical field of acoustic energy created as the sound propagates over the air, as analogous to "voiceprint''. We find that fieldprints can be distinctive between speakers (either humans or loudspeakers), and thus we may detect the speakers being used for spoofing attacks from the authentic users. Our evaluation on a dataset of 20 people and 8 loudspeakers shows that by relying on two on-board microphones to sample sound fields while users talk to the smartphones, CaField achieves a detection accuracy of 99.16% and an equal error rate (EER) of 0.85% across multiple sessions and various voice inputs. CaField supports low audio sample rates at 8~kHz and is robust to various factors including phone displacement, user posture, recording environment, etc. Chen Yan 0001, Yan Long 0002, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
CCS | 1 |
| 2019 | NAuth: Secure Face-to-Face Device Authentication via NonlinearityabstractWith the increasing prevalence of mobile devices, face-to-face device-to-device (D2D) communication has been applied to a variety of daily scenarios such as mobile payment and short distance file transfer. In D2D communications, a critical security problem is verifying the legitimacy of devices when they share no secrets in advance. Previous research addressed the problem with device authentication and pairing schemes based on user intervention or exploiting physical properties of the radio or acoustic channels. However, a remaining challenge is to secure face-to-face D2D communication even in the middle of a crowd, within which an attacker may hide. In this paper, we present Nhuth, a nonlinearity-enhanced, location-sensitive authentication mechanism for such communication. Especially, we target at the secure authentication within a limited range such as 20 cm, which is the common case for face-to-face scenarios. Nhuth contains averification scheme based on the nonlinear distortion of speaker-microphone systems and a location-based-validation model. The verification scheme guarantees device authentication consistency by extracting acoustic nonlinearity patterns (ANP) while the validation model ensures device legitimacy by measuring the time difference of arrival (TDOA) at two microphones. We analyze the security of Nhuth theoretically and evaluate its performance experimentally. Results show that Nhuth can verify the device legitimacy in the presence of nearby attackers. Xiaoyu Ji 0001, Chen Yan 0001, Jiangyi Deng, Wenyuan Xu 0001 |
INFOCOM | 3 |
| 2018 | Analyzing and Enhancing the Security of Ultrasonic Sensors for Autonomous VehiclesabstractAutonomous vehicles rely on sensors to measure road condition and make driving decisions, and their safety relies heavily on the reliability of these sensors. Out of all obstacle detection sensors, ultrasonic sensors have the largest market share and are expected to be increasingly installed on automobiles. Such sensors discover obstacles by emitting ultrasounds and analyzing their reflections. By exploiting the built-in vulnerabilities of sensors, we designed random spoofing, adaptive spoofing, and jamming attacks on ultrasonic sensors, and we managed to trick a vehicle to stop when it should keep moving, and let it fail to stop when it should. We validate our attacks on stand-alone sensors and moving vehicles, including a Tesla Model S with the “Autopilot” system. The results show that the attacks cause blindness and malfunction of not only sensors but also autonomous vehicles, which can lead to collisions. To enhance the security of ultrasonic sensors and autonomous vehicles, we propose two defense strategies, single-sensor-based physical shift authentication that verifies signals on the physical level, and multiple sensor consistency check that employs multiple sensors to verify signals on the system level. Our experiments on real sensors and MATLAB simulation reveal the validity of both schemes. Wenyuan Xu 0001, Chen Yan 0001, Weibin Jia, Xiaoyu Ji 0001, Jianhao Liu |
IEEE Internet Things J. | 2 |
| 2017 | DolphinAttack: Inaudible Voice CommandsabstractSpeech recognition (SR) systems such as Siri or Google Now have become an increasingly popular human-computer interaction method, and have turned various systems into voice controllable systems (VCS). Prior work on attacking VCS shows that the hidden voice commands that are incomprehensible to people can control the systems. Hidden voice commands, though "hidden", are nonetheless audible. In this work, we design a totally inaudible attack, DolphinAttack, that modulates voice commands on ultrasonic carriers (e.g., f > 20 kHz) to achieve inaudibility. By leveraging the nonlinearity of the microphone circuits, the modulated low-frequency audio commands can be successfully demodulated, recovered, and more importantly interpreted by the speech recognition systems. We validated DolphinAttack on popular speech recognition systems, including Siri, Google Now, Samsung S Voice, Huawei HiVoice, Cortana and Alexa. By injecting a sequence of inaudible voice commands, we show a few proof-of-concept attacks, which include activating Siri to initiate a FaceTime call on iPhone, activating Google Now to switch the phone to the airplane mode, and even manipulating the navigation system in an Audi automobile. We propose hardware and software defense solutions, and suggest to re-design voice controllable systems to be resilient to inaudible voice command attacks. Chen Yan 0001, Xiaoyu Ji 0001, Tianchen Zhang, Taimin Zhang, Wenyuan Xu 0001 |
CCS | 2 |