VLDB 2026 Research / reviewers in the wild / expert
Yifan Zhang 0042
dblp:57/4707-42
· DBLP profile ↗
10ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-9314-7532ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 3 first-author · 6 since 2021Security and privacy · 4 · 3 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Physical Layer Challenge-Response Authentication Between Ambient Backscatter DevicesabstractAmbient backscatter communication (AmBC) has become an integral part of ubiquitous Internet of Things (IoT) applications due to its energy-harvesting capabilities and ultra-low- power consumption. However, the open wireless environment exposes AmBC systems to various attacks, and existing authentication methods cannot be implemented between resource-constrained backscatter devices (BDs) due to their high computational demands. To this end, this paper proposes PLCRA-BD, a novel physical layer challenge-response authentication scheme between BDs in AmBC that overcomes BDs’ limitations, supports high mobility, and performs robustly against impersonation and wireless attacks. It constructs embedded keys as physical layer fingerprints for lightweight identification and designs a joint transceiver that integrates BDs’ backscatter waveform with receiver functionality to mitigate interference from ambient RF signals by exploiting repeated patterns in orthogonal frequency division multiplexing (OFDM) symbols. Based on this, a challenge-response authentication procedure is introduced to enable low-complexity fingerprint exchange between two paired BDs leveraging channel coherence, while securing the exchange process using a random number and unpredictable channel fading. Additionally, we optimize the authentication procedure for high-mobility scenarios, completing exchanges within the channel coherence time to minimize the impact of dynamic channel fluctuations. Security analysis confirms its resistance against impersonation, eavesdropping, replay, and counterfeiting attacks. Extensive simulations validate its effectiveness in resource-constrained BDs, demonstrating high authentication accuracy across diverse channel conditions, robustness against multiple wireless attacks, and superior efficiency compared to traditional authentication schemes. Yifan Zhang 0042, Yongchao Dang, Masoud Kaveh, Zheng Yan 0002, Riku Jäntti, Zhu Han 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | AmbShield: Enhancing Physical Layer Security With Ambient Backscatter Devices Against EavesdroppersabstractPassive eavesdropping compromises confidentiality in wireless networks, especially in resource-constrained environments where heavyweight cryptography is impractical. Physical layer security (PLS) exploits channel randomness and spatial selectivity to confine information to an intended receiver with modest overhead. However, typical PLS techniques, such as beamforming, artificial noise, and reconfigurable intelligent surfaces, often require additional active power or specialized deployment and rely on precise time synchronization and perfect CSI estimation, which limits their practicality. Meanwhile, the role of ambient backscatter devices (AmBDs) in potentially strengthening the legitimate channel while limiting eavesdroppers in generalized wireless network settings has not been fully investigated. To this end, we propose AmbShield, an AmBD-assisted PLS scheme that leverages naturally distributed AmBDs to simultaneously strengthen the legitimate channel and degrade eavesdroppers' reception without requiring extra transmit power and with minimal deployment overhead. In AmbShield, AmBDs are exploited as friendly jammers that randomly backscatter to create interference at eavesdroppers, and as passive relays that backscatter the desired signal to enhance the capacity of legitimate devices. We further develop a unified analytical framework that analyzes the exact probability density function (PDF) and cumulative distribution function (CDF) of legitimate and eavesdropper signal-to-interference-noise ratio (SINR), a closed-form secrecy outage probability (SOP), its high-SNR asymptote, and a secrecy diversity order (SDO). The analysis provides clear design guidelines on various practical system parameters to minimize SOP. Extensive experiments that include Monte Carlo simulations, theoretical derivations, and high-SNR asymptotic analysis demonstrate the security gains of AmbShield across diverse system parameters under imperfect synchronization and CSI estimation. Yifan Zhang 0042, Yishan Yang, Masoud Kaveh, Riku Jäntti, Zheng Yan 0002, Dusit Niyato, Zhu Han 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Backscatter Device-Aided Integrated Sensing and Communication: A Pareto Optimization FrameworkabstractIntegrated sensing and communication (ISAC) systems potentially encounter significant performance degradation in densely obstructed urban and non-line-of-sight scenarios, thus limiting their effectiveness in practical deployments. To deal with these challenges, this paper proposes a backscatter device (BD)-assisted ISAC system, which leverages passive BDs naturally distributed in underlying environments for performance enhancement. Specifically, the additional reflective signal paths provided by these ambient devices are exploited to enhance sensing accuracy and communication reliability, respectively. In this system, we define the Pareto boundary characterizing the trade-off between sensing mutual information (SMI) and communication rates to provide fundamental insights for its design. To derive the boundary, we formulate a performance optimization problem within an orthogonal frequency division multiplexing (OFDM) framework, by jointly optimizing time-frequency resource element (RE) allocation, transmit power management, and BD modulation decisions. To tackle the non-convexity of the problem, we decompose it into three subproblems, solved iteratively through a block coordinate descent (BCD) algorithm. Specifically, the RE subproblem is addressed using the successive convex approximation (SCA) method, the power subproblem is solved using an augmented Lagrangian combined water-filling method, and the BD modulation subproblem is tackled using semidefinite relaxation (SDR) methods. Additionally, we demonstrate the generality of the proposed system by showing its adaptability to bistatic ISAC scenarios and MIMO settings. Finally, extensive simulation results validate the effectiveness of the proposed system and its superior performance compared to existing state-of-the-art ISAC schemes. Yifan Zhang 0042, Shuhao Zeng, Riku Jäntti, Zheng Yan 0002, Christos Masouros, Zhu Han 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2025 | Joint Time-Frequency-Power Resource Optimization in Backscatter Device-Assisted ISAC SystemsabstractIntegrated sensing and communication (ISAC) has emerged as a key enabling technology for next-generation wireless networks, seamlessly combining communication and radar sensing functionalities by utilizing shared wireless resources. However, ISAC systems suffer from diminished sensing accuracy and compromised communication reliability in complex propagation environments, particularly in densely obstructed urban or non-line-of-sight scenarios. To cope with these issues, this paper proposes a novel backscatter device (BD)-assisted ISAC system where passive BDs are utilized to concurrently enhance sensing accuracy and communication reliability by providing additional signal-reflecting paths. Furthermore, a joint time-frequency-power resource optimization problem is formulated between sensing mutual information and communication capacity in an orthogonal frequency division multiplexing (OFDM) setting. Then, a Pareto boundary is characterized by solving this dual problem, providing clear insights into fundamental tradeoffs involved between sensing and communication. Specifically, we decompose the formulated optimization problem into two manageable subproblems and iteratively solve them through successive convex approximation (SCA) techniques with a block coordinate descent (BCD) algorithm to address the inherent non-convexity of the problem. Simulation results demonstrate the superior performance of the proposed BD-assisted ISAC system, showing substantial improvements in both sensing and communication metrics compared to state-of-the-art ISAC methods. Yifan Zhang 0042, Shuhao Zeng, Zheng Yan 0002, Riku Jäntti, Zhu Han 0001 |
GLOBECOM | 1 |
| 2025 | AmbAu: Accurate and Robust Physical Layer Authentication for Ambient Backscatter DevicesabstractAmbient backscatter communication (AmBC) has become increasingly popular for facilitating ubiquitous Internet of Things (IoT) due to its ultra-low-power consumption and energy-harvesting capabilities. However, the open nature of wireless channels and the resource-limited devices in AmBC systems expose them to threats such as identity impersonation and wireless spoofing attacks. Recently, physical layer authentication (PLA) offered a lightweight solution to address the above security challenges by utilizing inherent wireless properties, like channel fading and signal patterns, as unique fingerprints to identify legitimate devices and distinguish them from attackers. Despite its promise, current research still lacks an effective PLA mechanism that can accurately authenticate backscatter devices (BDs) and defend against spoofing attacks in AmBC systems. This paper presents AmbAu, a two-stage PLA scheme designed to authenticate BDs by leveraging the signal correlation between an ambient source and the BD. In the initialization stage, the verifier extracts a complex covariance matrix from the downlink signals between the ambient source and the BD. This matrix is later used during the authentication stage to verify the BD's identity and detect spoofing attempts. Through security analysis, we demonstrate AmbAu's resilience against replay, relay, and counterfeiting attacks. Simulations under various conditions demonstrate AmbAu's accuracy, efficiency, and superior performance when compared to traditional PLA schemes. Yifan Zhang 0042, Yongchao Dang, Yishan Yang, Masoud Kaveh, Zheng Yan 0002, Riku Jäntti |
ICC | 1 |
| 2025 | Voltage Profile-Driven Physical Layer Authentication for RIS-Aided Backscattering Tag-to-Tag NetworksabstractThis paper proposes a novel physical layer authentication (PLA) scheme for backscattering tag-to-tag networks (BTTNs), where aTalker Tag(TT) communicates passively with a Listener Tag (LT) in the presence of a potential adversary. Designed for ultra-low power tags without cryptographic capability, the proposed PLA leverages the unique voltage profiles generated by the tags’ energy harvesting and demodulation circuits to form physical-layer signatures for authentication. In addition, to enhance the reliability of voltage measurements, especially under weak signal conditions inherent within BTTNs, an indoor reconfigurable intelligent surface (RIS) is integrated to improve the received signal quality at LT. The proposed approach maintains a high authentication success rate even as the distance between TT and LT increases. A detailed security analysis demonstrates strong resilience against impersonation, man-in-the-middle, relay, and replay attacks, as long as the RIS controller remains secure. This robustness stems from the adversary’s inability to recreate the exact voltage profiles at LT, due to the inherent location-specific channel characteristics and the RIS-assisted signal shaping that the attacker cannot replicate. Furthermore, the simulation results confirm the effectiveness of the proposed RIS-assisted PLA, showing significant gains in authentication performance and secrecy capacity across diverse deployment scenarios. Masoud Kaveh, Farshad Rostami Ghadi, Yifan Zhang 0042, Zheng Yan 0002, Riku Jäntti |
IEEE Internet Things J. | 3 |
| 2025 | AuthScatter: Accurate, Robust, and Scalable Mutual Authentication in Physical Layer for Backscatter CommunicationsabstractBackscatter communication (BC) enables resource-constrained backscatter devices (BDs) to communicate by reflecting signals from external radio frequency sources (RFSs), thereby avoiding active RF components, making it a cutting-edge technology for the ubiquitous Internet of Things (IoT). However, the open nature of BC makes it vulnerable to passive and active attacks, and existing methods fail to offer robust mutual authentication suitable for mobile BC systems while keeping a low computational overhead. To address this issue, we propose AuthScatter, an accurate, robust, and scalable physical-layer mutual authentication scheme between the RFS and multiple BDs by leveraging channel fading and random numbers as a one-time pad to protect the identity key exchange procedure during the authentication. Specifically, AuthScatter constructs shared identity keys as physical-layer fingerprints for efficient identification and employs a challenge-response authentication mechanism to enable secure key exchange between the RFS and the BD. In the authentication, the one-time pad effectively prevents eavesdropping, spoofing, replay, and counterfeiting attacks, while legitimate devices leverage channel reciprocity and random number knowledge to authenticate efficiently without channel estimation or complex processing. It is tailored for high-mobility scenarios by completing the exchange within the channel coherence time while incorporating a key-update mechanism to ensure sustained security in the long term. Additionally, it includes a re-authentication mechanism to enhance resistance against wireless attacks and a batch authentication framework leveraging time-division duplexing (TDD) to enable scalability in large-scale BC deployments. Comprehensive security analysis demonstrates the resistance of AuthScatter to various threats, including eavesdropping, identity spoofing, replay, and counterfeiting attacks. Extensive simulations further validate its high authentication accuracy across diverse channel conditions, robustness against various attack vectors, and scalability with a large number of BDs, highlighting its superiority over state-of-the-art schemes. Yifan Zhang 0042, Boxuan Xie, Yishan Yang, Zheng Yan 0002, Riku Jäntti, Zhu Han 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | APAuth: Authenticate an Access Point by Backscatter DevicesabstractBackscatter communication (BC) represents a wireless communication technology that facilitates the transmission of data by low-power devices, referred to as backscatter devices (BDs), through the modulation or reflection of pre-existing wireless signals, typically sourced from an access point (AP). The advent of the Internet of Things (IoT) has garnered significant attention and witnessed the widespread adoption of BC, primarily due to its exceptional energy- efficiency characteristics. Nevertheless, the security of BC systems faces substantial threats when deployed in practical scenarios due to their inherent openness. Specifically, wireless BDs, which directly engage with users, are susceptible to detrimental consequences in the event of interactions with counterfeit wireless APs. Owing to their non-authenticated and unconditional reflection properties, BDs are vulnerable to spoofing attacks orchestrated by malicious APs. Moreover, their limited computing capabilities make it challenging to employ intricate cryptographic algorithms. To tackle these challenges, we introduce APAuth, a lightweight authentication scheme that leverages the power value of BD to establish AP authentication. In this scheme, BDs and APs share a confidential key and engage in negotiations to determine a key generation algorithm. Subsequently, the current stored power value of BD is utilized to calculate the power value that must be delivered to BD from AP. If the computed charging power value aligns with the value determined by the key generation algorithm, the AP successfully passes the authentication of BD. We perform a thorough theoretical analysis of the security aspects inherent in our proposed scheme. We further conduct numerical simulations to validate the practical viability and desired performance of APAuth in diverse real-world scenarios. Jingdong Chang, Yishan Yang, Yifan Zhang 0042, Masoud Kaveh, Zheng Yan 0002 |
ICC | 4 |
| 2024 | BatchAuth: A Physical Layer Batch Authentication Scheme for Multiple Backscatter DevicesabstractBackscatter communication (BC) offers a promising power-efficient communication paradigm for wireless devices with constrained energy resources. However, the innate openness and broadcast characteristics of BC raise considerable security concerns. To address this, physical layer authentication has emerged as a primary solution to enable secure BC. To facilitate efficient authentication on multiple backscatter devices (BDs), batch authentication becomes essential. Nevertheless, existing schemes have not yet bridged the research gap regarding effective batch authentication on mobile BDs with high scalability support. This paper proposes BatchAuth, a physical layer batch authentication scheme designed to authenticate multiple BDs simultaneously by leveraging orthogonal frequency-division multiple access (OFDMA) technology. BatchAuth utilizes two factors, received signal strength (RSS) and multiple channel impulse responses (CIRs), to authenticate a group of BDs and leverages a channel correlation coefficient to offset performance loss and support BD dynamicity. What’s more, a backscatter waveform design facilitates an access point (AP) in estimating the CIRs from backscattered signals. Additionally, BatchAuth possesses the capability to detect and trace potential attackers by analyzing the specific characteristics of orthogonal subcarriers to facilitate countermeasure. In particular, BatchAuth demonstrates significant potential on scalability in large-scale BC systems and multiple-input multiple-output (MIMO) systems. Theoretical analysis on BatchAuth security and extensive simulations under various settings by comparing with cutting-edge schemes further validate its commendable performance with regard to accuracy, robustness, efficiency, and scalability. Yishan Yang, Niya Luo, Zheng Yan 0002, Yifan Zhang 0042, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | BatAu: A Batch Authentication Scheme for Backscatter Devices in a Smart Home NetworkabstractWith the maturity of the Internet of Things (IoT), many IoT applications have been popularized and promoted. As one of the IoT technology, backscatter communication (BC) has aroused research interest due to its low-cost and ultra-low power consumption characteristics. Due to their simple design and battery-less functionalities, backscatter devices (BDs) have been introduced as the main candidates for deploying in smart home networks (SHN). Although batch authentication in BC systems is crucial and efficient for SHN security, existing schemes have only focused on radio frequency identification (RFID) devices and no literature has given a general solution for BD batch authentication. In this paper, we propose a scheme named BatAu for authenticating batch BDs applied in SHN by extracting physical layer features in multiplexing signals. We conduct numerical simulations with various settings to show its desirable performance. Yishan Yang, Masoud Kaveh, Yifan Zhang 0042, Zheng Yan 0002, Kai Zeng 0001 |
ICC | 4 |