Luis Vargas

dblp:68/5101 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
3since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Real-Time Myoelectric-Based Neural-Drive Decoding for Concurrent and Continuous Control of Robotic Finger Forces
abstract
Neural or muscular injuries, such as due to amputation, spinal cord injury, and stroke, can affect hand functions, profoundly impacting independent living. This has motivated the advancement of cutting-edge assistive robotic hands. However, unintuitive myoelectric control of these devices remains challenging, which limits the clinical translation of these devices. Accordingly, we developed a robust motor-intent decoding approach to continuously predict the intended fingertip forces of single and multiple fingers in real time. We used population motor neuron discharge activities (i.e., neural drive from brain to spinal cord) decoded from a high-density surface electromyogram (HD-sEMG) signals as the control signals instead of the conventional global sEMG features. To enable real-time neural-drive prediction, we employed a convolutional neural network model to establish the mapping from global HD-sEMG features to finger-specific neural-drive signals, which were then employed for continuous and real-time control of three prosthetic fingers (index, middle, and ring). As a result, the neural-drive-based approach can decode the motor intent of single-finger and multifinger forces with significantly lower force estimation errors than that obtained using the global HD-sEMG-amplitude approach. Besides, the force prediction accuracy was consistent over time and demonstrated strong robustness to signal interference. Our network-based decoder can also achieve better finger isolation with minimal forces predicted in unintended fingers. Our work demonstrates that the accurate and robust finger force control could be achieved through this new decoding approach. The outcomes offer an efficient intent prediction approach that allows users to have intuitive control of prosthetic fingertip forces in a dexterous way.
Long Meng, Luis Vargas, Derek G. Kamper, Xiaogang Hu
IEEE Trans. Hum. Mach. Syst.2
2022 Who Are You (I Really Wanna Know)? Detecting Audio DeepFakes Through Vocal Tract Reconstruction
Logan Blue, Kevin Warren, Hadi Abdullah, Cassidy Gibson, Luis Vargas, Jessica O'Dell, Kevin R. B. Butler, Patrick Traynor
USENIX Security Symposium5
2022 Analyzing the Monetization Ecosystem of Stalkerware
abstract
Stalkerware is a form of malware that allows for the abusive monitoring of intimate partners. Primarily deployed on information-rich mobile platforms, these malicious applications allow for collecting information about a victim’s actions and behaviors, including location data, call audio, text messages, photos, and other personal details. While stalkerware has received increased attention from the security community, the ways in which stalkerware authors monetize their efforts have not been explored in depth. This paper represents the first large-scale technical analysis of monetization within the stalkerware ecosystem. We analyze the code base of 6,432 applications collected by the Coalition Against Stalkerware to determine their monetization strategies. We find that while far fewer stalkerware apps use ad libraries than normal apps, 99% of those that do use Google AdMob. We also find that payment services range from traditional in-app billing to cryptocurrency. Finally, we demonstrate that Google’s recent change to their Terms of Service (ToS) did not eliminate these applications, but instead caused a shift to other payment processors, while the apps can still be found on the Play Store; we verify through emulation that these apps often operate in blatant contravention of the ToS. Through this analysis, we find that the heterogeneity of markets and payment processors means that while point solutions can have impact on monetization, a multi-pronged solution involving multiple stakeholders is necessary to mitigate the financial incentive for developing stalkerware.
Cassidy Gibson, Vanessa Frost, Katie Platt, Washington Garcia, Luis Vargas, Sara Rampazzi, Vincent Bindschaedler, Patrick Traynor, Kevin R. B. Butler
Proc. Priv. Enhancing Technol.5
2019 Digital Healthcare-Associated Infection: A Case Study on the Security of a Major Multi-Campus Hospital System
Luis Vargas, Logan Blue, Vanessa Frost, Christopher Patton, Nolen Scaife, Kevin R. B. Butler, Patrick Traynor
NDSS1
2019 Characterizing the Security of the SMS Ecosystem with Public Gateways
abstract
Recent years have seen the Short Message Service (SMS) become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this article, we provide a comprehensive longitudinal study to answer these questions, analyzing over 900,000 text messages sent to public online SMS gateways over the course of 28 months. From this data, we uncover the geographical distribution of spam messages, study SMS as a transmission medium of malicious content, and find that changes in benign and malicious behaviors in the SMS ecosystem have been minimal during our collection period. The key takeaways of this research show many services sending sensitive security-based messages through an unencrypted medium, implementing low entropy solutions for one-use codes, and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for combating phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent.
Bradley Reaves, Luis Vargas, Nolen Scaife, Jing (Dave) Tian, Logan Blue, Patrick Traynor, Kevin R. B. Butler
ACM Trans. Priv. Secur.2
2018 2MA: Verifying Voice Commands via Two Microphone Authentication
abstract
Voice controlled interfaces have vastly improved the usability of many devices (e.g., headless IoT systems). Unfortunately, the lack of authentication for these interfaces has also introduced command injection vulnerabilities - whether via compromised IoT devices, television ads or simply malicious nearby neighbors, causing such devices to perform unauthenticated sensitive commands is relatively easy. We address these weaknesses with Two Microphone Authentication (2MA), which takes advantage of the presence of multiple ambient and personal devices operating in the same area. We develop an embodiment of 2MA that combines approximate localization through Direction of Arrival (DOA) techniques with Robust Audio Hashes (RSHs). Our results show that our 2MA system can localize a source to within a narrow physical cone ($<30^\circ $) with zero false positives, eliminate replay attacks and prevent the injection of inaudible/hidden commands. As such, we dramatically increase the difficulty for an adversary to carry out such attacks and demonstrate that 2MA is an effective means of authenticating and localizing voice commands.
Logan Blue, Hadi Abdullah, Luis Vargas, Patrick Traynor
AsiaCCS3
2018 Mitigating Risk while Complying with Data Retention Laws
abstract
Data breaches represent a significant threat to organizations. While the general problem of protecting data has received much attention, one large (and growing) class has not - data that must be kept due to mandatory retention laws. Such data is often of little use to an organization, is rarely accessed, and represents a significant potential liability, yet cannot be discarded. Protecting such data entails an unusual combination of practical constraints (such as providing verification to a party that may be unknown) and thus requires functionality that is not well addressed by traditional cryptographic primitives. We propose to mitigate the risk to such data through a new system called Dragchute, which creates a time window during which locked data cannot be accessed by anyone. Based on a verifiable non-interactive, non-parallelizable, time-delay key escrow mechanism, Dragchute is novel in that it requires that no cryptographic material capable of providing early access to the data be retained, yet provides verification for multiple properties. We define a base construction for Dragchute, show possible extensions that help meet additional verification requirements, and characterize its performance. Our results show that Dragchute systems offer verifiable, customizable, computational protection against data exposure for encryption costs similar to traditional methods (e.g., less than 6% overhead compared to AEAD). We thus show that Dragchute systems provide a critical new means for protecting data that must be retained long term due to mandatory retention laws.
Luis Vargas, Gyan Hazarika, Rachel Culpepper, Kevin R. B. Butler, Thomas Shrimpton, Doug Szajda, Patrick Traynor
CCS1
2018 Hello, Is It Me You're Looking For?: Differentiating Between Human and Electronic Speakers for Voice Interface Security
abstract
Voice interfaces are increasingly becoming integrated into a variety of Internet of Things (IoT) devices. Such systems can dramatically simplify interactions between users and devices with limited displays. Unfortunately voice interfaces also create new opportunities for exploitation. Specifically any sound-emitting device within range of the system implementing the voice interface (e.g., a smart television, an Internet-connected appliance, etc) can potentially cause these systems to perform operations against the desires of their owners (e.g., unlock doors, make unauthorized purchases, etc). We address this problem by developing a technique to recognize fundamental differences in audio created by humans and electronic speakers. We identify sub-bass over-excitation, or the presence of significant low frequency signals that are outside of the range of human voices but inherent to the design of modern speakers, as a strong differentiator between these two sources. After identifying this phenomenon, we demonstrate its use in preventing adversarial requests, replayed audio, and hidden commands with a 100%/1.72% TPR/FPR in quiet environments. In so doing, we demonstrate that commands injected via nearby audio devices can be effectively removed by voice interfaces.
Logan Blue, Luis Vargas, Patrick Traynor
WISEC2
2017 AuthentiCall: Efficient Identity and Content Authentication for Phone Calls
Bradley Reaves, Logan Blue, Hadi Abdullah, Luis Vargas, Patrick Traynor, Thomas Shrimpton
USENIX Security Symposium4
2007 An Evolutionary Approach for the Greenfield Planning Problem in Distribution Networks
abstract
Distribution network Greenfield planning is recognized as an important task of the planning studies. This importance lies in its use as a regulatory tool to determine the distribution charges applied to final users. However, the Greenfield planning requires solving a combinatorial optimization problem classified as a NP-hard. Because of its complexity, different models based on heuristic strategies have been proposed to solve this problem. In this work, an evolutionary strategy -as a global search methodology-is proposed. The corresponding Greenfield problem is formulated considering the network capacity constraints and the voltage drop. The proposed algorithm assumes that the system elements costs and its optimal assignment are provided beforehand. Next, the individuals' generation is based on a heuristic biased construction of random spanning trees. Then, the fitness function penalizes the unfeasible solutions with a dynamic function. Finally, four crossover methodologies are proposed and evaluated on a test case. A comparison of the solutions and the algorithm performance is performed on a test case system.
Guillermo Jimenez-Estevez, Luis Vargas, Rodrigo Palma-Behnke
IJCNN2