E. Paul Ratazzi

dblp:46/1398 · also Paul Ratazzi · DBLP profile ↗
← Back
10ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0002-9817-6025ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Advanced Security for NextG Mobile Networks: A Hybrid Fuzzing Approach
abstract
This paper presents HyFuzz, a hybrid intelligent fuzz testing platform designed to enhance the security validation of next generation (NextG) mobile networks. HyFuzz integrates symbolic formal analysis with adaptive fuzzing to enable the discovery of vulnerabilities that emerge from subtle state inconsistencies and session level command manipulations. Specifically, HyFuzz demonstrates support for multi step intra session fuzzing, where carefully crafted command sequences cause persistent state desynchronization between User Equipment (UE) and the network. Complementing this, HyFuzz employs formal guided deep fuzzing, directing fuzzing efforts to high risk protocol states identified by symbolic analysis. Through a dual mode architecture supporting both virtual (ZMQ) and over the air (OTA) fuzzing, HyFuzz provides an extensible testbed for low level and behavioral vulnerability discovery. Experimental results across 1,281 test cases reveal 1,105 failure instances, including stealthy failures that manifest only under extended interaction contexts. Our findings suggest HyFuzz provides a foundational capability toward more realistic and semantically rich vulnerability detection in modern mobile infrastructure.
Jingda Yang, E. Paul Ratazzi, Ying Wang 0113
IEEE Trans. Mob. Comput.2
2024 A Lightweight Hardware-Assisted Security Method for eFPGA Edge Devices
abstract
Security has been a concern for all connected devices. Attackers continually search for vulnerabilities from software, firmware, and all the way down to hardware level. At the same time, cybersecurity has also been pushed to the hardware platform to keep invaders out. In this paper, the main objective is to provide a cost effective solution to FPGA configuration bitstream confidentiality/authentication. A lightweight hardware assisted chaos-based stream cipher for FPGA bitstream protection is proposed and integrated into a system-level security architecture. This enhances cyber resilience at the platform level and strengthens the platform’s ability to prevent attacks. The design targets hardware environments where gate count and power consumption are limited. The proposed security approach is integrated into the FPGA system’s boot process to assure a secure booting process, secure key management, and secure remote updating. As chaotic dynamics can be controlled by a low power signal, and require fewer resources to implement the cipher, lower power consumption and hardware utilization are expected. A Physical Unclonable Function (PUF) is applied to provide secrecy to the proposed security approach, making key management feasible for remotely placed devices. A protocol for remote system updating is also proposed. Performance and security analysis show that the proposed approach can be used for securing FPGA-based edge devices.
E. Paul Ratazzi
IEEE Internet Things J.2
2023 VoiceGuard: An Effective and Practical Approach for Detecting and Blocking Unauthorized Voice Commands to Smart Speakers
abstract
Smart speakers bring convenience to people's daily lives. However, various attacks can be launched against smart speakers to execute malicious commands, which may cause serious safety or security issues. The existing solutions against sophisticated attacks such as voice replay attacks and voice synthesis attacks require intrusive modifications of the smart speaker hardware and/or software, which are impractical for general users. In this work, we present a novel security scheme- VoiceGuard that can effectively detect and block unauthorized voice commands to smart speakers. VoiceGuard does not require any modification to smart speakers' hardware or software. We implement a prototype of VoiceGuard on two popular smart speakers: Amazon Echo Dot and Google Home Mini, and evaluate the scheme in three real-world testbeds, which include both single-user and multi-user scenarios. The experimental results show that VoiceGuard achieves an accuracy of 97% in blocking malicious voice commands issued by illegitimate sources while having a negligible impact on the user experience.
Xuening Xu, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi
DSN4
2023 Discovering Complex Correlations Among Multiple IoT Devices in Smart Environments
abstract
The ubiquity of the Internet of Things (IoT) in a vast range of consumer applications is unparalleled. Unfortunately, despite the benefits of IoT, its widespread integration comes with significant security challenges. Considering IoT devices' capability to interact with the physical environment, there is an urgent need for effective anomaly detection. The state-of-the-art anomaly detection method, HAWatcher, models the normal behaviors of smart homes with inter-device correlations and demonstrates great results. Nonetheless, it is limited to capturing only simple one-to-one correlations between two events or states, which undermines its capability to detect anomalies in more complicated environments. To address this issue, we present a novel correlation discovering method to mine complex two-to-one correlations in such complicated IoT-enabled environments. We conduct experiments over two weeks on four smart home testbeds and obtain 70 two-to-one correlations. The correlations are applied to 9 anomaly scenarios, which show significant improvements in detecting anomalies over one-to-one correlations.
Andrew D'Angelo, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi
GLOBECOM4
2022 DICE-Enabled Distributed Security Schemes for the Air Force Internet of Things
abstract
Security for Internet of Things requires balancing power consumption and memory usage in devices. In this work, we propose symmetric DICE-based schemes for distributed IoT systems, which aims to have effective security and recovery procedures through symmetric keys while achieving energy efficiency. Our security schemes utilize an efficient security primitive for IoT Device Identifier Composition Engine (DICE). Our schemes enhance security and flexibility in distributed IoT systems, allowing for a secure dynamic bootstrapping and a node recovery mechanism in IoT system.
Haotian Chi, Luke Jakielaszek, Xiaojiang Du, E. Paul Ratazzi
ICC4
2019 Effective UAV and Ground Sensor Authentication
abstract
Nowadays, The Internet of Things (IoT) has been widely used in various fields due to its smart sensing and communication capabilities. IoT devices serve as bridges for the cyber system to interact with the physical environment by providing various useful sensing capabilities such as battlefield surveillance, home monitoring, traffic control, etc. These capabilities also make IoT an important role in tactical missions in the military, including Reconnaissance, Intelligence, Surveillance, and Target Acquisition (RISTA). Nevertheless, IoT devices are known to have critical issues on security due to constraints on cost and resources. Most existing researches are based on smart sensors that have comparatively more computing and communication resources, while security solutions for dumb sensors are still lacking. Some IoT sensors that are deployed in a hostile environment are dumb due to limitations on cost and power supply, making them more vulnerable to attacks. In this work, we try to tackle this problem by proposing effective authentication solutions between a UAV and dumb IoT devices (also referred to as dumb sensors) within an example application of a UAV-sensor collaborative RISTA mission. We present two different schemes for two-way mutual authentication between the UAV and dumb sensors which utilize non-cryptographic physical layer cover channel and neighboring devices' signal sensing correlations respectively. We demonstrate the feasibility and effectiveness of our schemes with extensive real-world experiments on our prototype deployment.
Xuening Xu, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi
GLOBECOM4
2019 A Light-Weight Authentication Scheme for Air Force Internet of Things
abstract
Internet of Things (IoT) is ubiquitous because of its broad applications and the advance in communication technologies. The capabilities of IoT also enable its important role in homeland security and tactical missions, including Reconnaissance, Intelligence, Surveillance, and Target Acquisition (RISTA). IoT security becomes the most critical issue before its extensive use in military operations. While the majority of research focuses on smart IoT devices, treatments for legacy dumb network-ready devices are lacking; moreover, IoT devices deployed in a hostile environment are often required to be dumb due to the strict hardware constraints, making them highly vulnerable to cyber attacks. To mitigate the problem, we propose a light-weight authentication scheme for dumb IoT devices, in a case study of the UAV-sensor collaborative RISTA missions. Our scheme utilizes the covert channels in the physical layer for authentications and does not request conventional key deployments, key generations which may cause security risks and large overhead that a dumb sensor cannot afford. Our scheme operates on the physical layer, and thus it is highly portable and generalizable to most commercial and military communication protocols. We demonstrate the viability of our scheme by building a prototype system and conducting experiments to emulate the behaviors of UAVs and sensors in real scenarios.
Xi Hang Cao, Xiaojiang Du, E. Paul Ratazzi
ICC3
2018 An Efficient Privacy-Preserving Incentive Scheme without TTP in Participatory Sensing Network
abstract
Along with the development of wireless communication technology, a mass of mobile devices are gaining stronger sensing capability, which brings a novel paradigm to light: participatory sensing networks (PSNs). PSNs can greatly reduce the cost of wireless sensor networks, and hence are becoming an efficient way to obtain abundant sensing data from surrounding environment. Therefore, PSNs would lead to significant improvement in various fields, including cognitive communication. However, the large-scale deployment of participatory sensing applications is hindered by the lack of incentive mechanism, security and privacy concerns. It is still an ongoing issue to address all three aspects simultaneously in PSNs. In this paper, we construct an efficient privacy-preserving incentive scheme without trusted third party (TTP) for PSNs to motivate user-participation. This scheme allows each participant to earn credits by contributing data privately. Using blind and partially blind signatures, the proposed scheme is proved to be secure for privacy and incentive. Additionally, the performance evaluation in terms of computation and storage indicates that the proposed scheme has higher efficiency.
Xiaojiang Du, E. Paul Ratazzi
ICC5
2006 Array Redundancy and Diversity for Wireless Transmissions with Low Probability of Interception
abstract
In contrast to the classical spread spectrum or data encryption methods, we propose an array redundancy-based approach for wireless transmissions with inherent low probability of interception (LPI). The redundancy of transmit antenna arrays introduces some degrees of freedom for deliberate signal randomization, based on which, diversity is exploited to randomize the eavesdropper's signal. LPI is analyzed by proving the indeterminacy of eavesdroppers' blind deconvolution. Extensive simulations and preliminary experiments are conducted to demonstrate the proposed method.
Xiaohua Li 0003, Juite Hwu, E. Paul Ratazzi
ICASSP (4)3
2002 Securing Wireless and Mobile Networks - Is It Possible?
William D. Ivancic, David A. Wagner 0001, Aviel D. Rubin, E. Paul Ratazzi, James P. G. Sterbenz
INFOCOM4