VLDB 2026 Research / reviewers in the wild / expert
Yao Wang 0005
dblp:72/628-5
· DBLP profile ↗
15ranked-venue papers
11as first author
11since 2021 · last 2026
0000-0002-4578-4932ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 7 first-author · 10 since 2021Security and privacy · 3 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A bone conduction-based approach for secure device pairing
Yao Wang 0005, Yue Li 0035 |
Comput. Networks | 2 |
| 2026 | Separating Individual Respiration From Entangled WiFi Signals for Multi-User AuthenticationabstractUser authentication is a critical component of IoT environments, serving as the security bridge between users and devices to safeguard data transmission and prevent unauthorized access. While WiFi-based authentication via motion recognition has shown potential in single-user scenarios, its effectiveness diminishes significantly in multi-user environments. Detecting subtle movements, such as breathing, from multiple users simultaneously poses a significant challenge, pushing the capabilities of current WiFi authentication systems to their limits. In this paper, we presentBreathEye, a multi-user authentication system that leverages only a pair of commercial WiFi devices to detect and authenticate the subtle respiratory patterns of multiple individuals simultaneously. The core insight of our approach lies in exploiting the inherent variability in individual breathing patterns, which manifest in short-term energy fluctuations and long-term dependencies within the breathing signals. To this end, we propose a dual-attention fusion mechanism that captures these subtle differences, enabling the effective disentanglement of individual breathing signals from overlapping multi-user data. To further enhance practicality,BreathEyeincorporates a few-shot learning framework to minimize user registration time and reduce system training overhead by analyzing independent breathing signals for authentication. Extensive experiments demonstrate thatBreathEyeachieves authentication accuracies of over 99%, 92%, and 87% in single-, two-, and three-user scenarios, respectively, highlighting the system's effectiveness. Yao Wang 0005, An He, Tao Gu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | BoneAuth: A Bone-Conduction-Based Voice Liveness Authentication for Voice AssistantsabstractAs voice assistants (VAs) become increasingly popular, concerns about their privacy and security have garnered significant attention. VAs nowadays rely on voiceprint authentication to enhance their security. However, this method is susceptible to spoofing attacks, where attackers may use recording or synthesis techniques to mimic the user's voice, thereby bypassing the authentication mechanism. To address this, we introduce “BoneAuth,” a novel liveness detection system in this article. It offers continuous voice authentication for users, enhancing the security of VAs. BoneAuth is designed to be used in wearable devices with built-in microphones, such as Bluetooth earphones. Our basic idea is continuously matching the user's voice signals with the vibration signals produced by their vocal cords during speech. Specifically, our system uses the device's built-in microphone to concurrently capture vibrations from bone conduction (BC) and voices from air conduction (AC). We introduce a signal separation algorithm that, by measuring the unique threshold range of the user, can separate the AC and BC signals from the mixed microphone signals. By continuously comparing the consistency of the two signals, our system can determine whether the user's voice is a real live voice or artificially generated voice. Our system does not require user-specific passphrases for authentication, making it easy to deploy and use without the need for additional user actions or hardware. We demonstrate the feasibility of our method using commercial off-the-shelf Bluetooth earphones. Extensive experiments show an accuracy rate close to 98.15%, proving the effectiveness of our approach. Yue Li 0035, Xueru Gao, Qipeng Song, Yao Wang 0005 |
IEEE Internet Things J. | 4 |
| 2024 | Cyber Sentinel: Fortifying Voice Assistant Security with Biometric Template Integration in Neural Networks
Yao Wang 0005, Zhipeng Si |
WASA (1) | 2 |
| 2024 | Simultaneous Authentication of Multiple Users Using a Single mmWave RadarabstractUser authentication is crucial for maintaining privacy. However, most existing methods are designed for single-user scenarios and may not be efficient for multiple users. To address this issue, we propose M-Auth, a Multiuser Authentication system that utilizes a commercial mmWave radar to detect the unique breathing pattern. We exploit the phenomenon that chest movements due to breathing can alter radio frequency signals. To make M-Auth more effective in capturing signals from multiple users, we design an auxiliary rotating gadget to adjust the radar orientation dynamically. By using mmWave’s high directivity, we can isolate individual components from blended RF signals and focus on reflections from different positions. We propose an energy comparison method to filter out irrelevant body movements and retain fine-grained respiration traits. Subsequently, we develop a feature selection pipeline to extract the most informative features and train a machine learning-based classifier to identify each user. M-Auth is practical because it is non-contact and passive, and it is secure because respiration is unique and challenging to forge. Extensive experiments with 37 participants demonstrate that M-Auth is effective in verifying legitimate users and thwarting spoofing attacks, with an authentication accuracy of over 96% and an attack detection rate of over 95%. Yao Wang 0005, Tao Gu 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Exploring a Secure Device Pairing Using Human Body as a ConductorabstractRecent research has been exploring ways to streamline device pairing by introducingtouch-to-accessthat minimizes user interaction. It generates pairing keys by extracting features from a shared information source to ascertain if two devices are being held by the same person. While these solutions focus on verifying the authenticity of the device, they do not consider the legitimacy and pairing intent of the device holder. Moreover, the pairing keys exchanged over an open wireless link may be susceptible to eavesdropping attacks. In this paper, we propose a secure device pairing mechanism that utilizes the unique electrical responses of the human body to generate and transmit user-specific pairing keys, ensuring both the user's legitimacy and pairing intent while also improving key transmission reliability. We accomplish this by using the device's built-in microphone to capture ambient sound as entropy and converting it into an electrical signal transmitted by the body for device pairing. We have built a prototype and conducted extensive experiments with 31 participants to evaluate its security and usability. The results demonstrate that our proposed mechanism offers a more secure and reliable option for user-specific pairing keys, contributing to the field of device pairing. Yao Wang 0005, Tao Gu 0001, Yu Zhang 0093, Minjie Lyu, Hui Li 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Collusive attack that exploits biometric similarity difference and basic countermeasures
Wandong Cai, Yao Wang 0005 |
Wirel. Networks | 3 |
| 2022 | Enabling secure touch-to-access device pairing based on human body's electrical responseabstractRecent efforts in reducing user involvement during device pairing have successfully introduced touch-to-access. To detect whether two devices are being held by the same person, existing touch-to-access solutions extract features from a shared information source to generate pairing keys. They focus on validating the device's authenticity by only requiring the user's simple touching of the device, however, ignore the device holder's legitimacy and pairing intent. Moreover, the pairing keys may be vulnerable to eavesdropping attacks since they are exchanged over an open wireless link (e.g., WiFi or Bluetooth). In this paper, we develop a secure device pairing mechanism that essentially uses the human body to generate and transmit user-specific pairing keys, ensuring the user's legitimacy and pairing intent, as well as improving key transmission reliability. Our work is based on the observation that the human body produces a unique response to the electrical signal flowing through it, and different bodies induce distinct responses to the signal. The built-in microphone on devices captures ambient sound as an entropy source and converts it into an electrical signal, which is subsequently processed and transmitted by the human body for device pairing. We build a prototype using off-the-shelf microphones and conduct extensive experiments with 31 participants to evaluate its security performance and usability. The results show that our system achieves a pairing success rate of 97.74% and an equal error rate of 2.28%. Yao Wang 0005, Tao Gu 0001, Yu Zhang 0093, Minjie Lyu, Tom H. Luan, Hui Li 0006 |
MobiCom | 1 |
| 2022 | BiTouch: enabling secure touch-to-access device pairing based on human body's electrical responseabstractWe present a secure device pairing approach, called BiTouch, using the human body as a conductor to generate and transmit user-specific pairing keys for advancing touch-to-access policy. BiTouch is designed based on the observation that the human body responds uniquely to electrical signals flowing through it. Built-in microphones on devices are essentially used to capture ambient sound as entropy and convert it into an electrical signal, which is subsequently transmitted by the body for device pairing. We implement BiTouch using off-the-shelf microphones and evaluate it with 31 participants. The results demonstrate that BiTouch ensures the user's legitimacy and key transmission reliability, and achieves a pairing success rate of 97.74% and an equal error rate of 2.28%. Yao Wang 0005, Tao Gu 0001, Yu Zhang 0093, Minjie Lyu, Tom H. Luan, Hui Li 0006 |
MobiCom | 1 |
| 2022 | Your Breath Doesn't Lie: Multi-user Authentication by Sensing Respiration Using mmWave RadarabstractUser authentication is critical to privacy preservation. Most of the existing works focus on single-user authentication, which may not work efficiently and practically in multi-user scenarios. To this end, we present a Multi-user Authentication system (M-Auth) that employs a single COTS mmWave radar to capture the user's unique breathing pattern. It exploits the phenomenon that radio frequency (RF) signals are affected by chest displacements due to breathing. We specifically design an auxiliary rotating gadget to dynamically adjust radar orientation, making it more effective in capturing respiration signals from multiple users. To profile individual components from the entangled RF signals, we leverage mmWave's high directivity to locate each user and separately focus on reflections from different positions. We propose a signal energy comparison method to eliminate the irrelevant body movements for preserving fine-grained respiration traits. Afterward, we develop a feature selection pipeline to elicit the most informative features and train a machine learning-based classifier to identify each user. M-Auth is practical due to its non-contact and passive nature, and it is secure as respiration is unique and difficult-to-forge. Extensive experiments involving 37 participants demonstrate that M-Auth is effective in verifying legitimate users and thwarting spoofing attacks, with an authentication accuracy of over 96 % and an attack detection rate of over 95%. Yao Wang 0005, Tao Gu 0001, Tom H. Luan, Yong Yu 0002 |
SECON | 1 |
| 2022 | HeartPrint: Exploring a Heartbeat-Based Multiuser Authentication With Single mmWave RadarabstractContinuous authentication is crucial for protecting user’s privacy throughout their login session. Existing studies employ wireless sensing technologies to provide device-free and unobtrusive authentication; the user’s behavior is continually assessed without their direct involvement until it deviates from their normal pattern. However, these works primarily concentrate on single-user authentication, which poses challenges in multiuser scenarios, such as smart homes and offices, where more than one user usually exists. In this article, we propose HeartPrint, a continuous multiuser authentication system, that employs a single commodity mmWave radar to capture the unique self-driving heartbeat motions from multiple users. Specifically, HeartPrint leverages the effect of skin surface vibrations caused by heartbeat on radio frequency (RF) transmissions. To profile individual heartbeat signals from the entangled components that are induced by multiple users, we first use a clustering method to position each user in the environment, then focus on the signal reflected from each position separately. The irrelevant body movements are eliminated from the RF signal by using a proposed signal energy comparison method for preserving fine-grained heartbeat traits. We then develop a pipeline to extract the most informative features for characterizing each user and feed them to an elaborated classifier for user authentication. We evaluate HeartPrint with 54 participants and demonstrate that it achieves an average authentication accuracy of over 95%. Additionally, we show that it is resilient against spoofing attacks, with an average attack success rate of less than 3%. Yao Wang 0005, Tao Gu 0001, Tom H. Luan, Minjie Lyu, Yue Li 0035 |
IEEE Internet Things J. | 1 |
| 2020 | Your Eyes Reveal Your Secrets: An Eye Movement Based Password Inference on SmartphoneabstractThe widespread use of smartphones has brought great convenience to our daily lives, while at the same time we have been increasingly exposed to security threats. Keystroke security is essential to user privacy protection. In this paper, we present GazeRevealer, a novel side-channel based keystroke inference framework to infer sensitive inputs on smartphone from video recordings of victim's eye patterns captured from smartphone front camera. We observe that eye movements typically follow the keystrokes typing on the number-only soft keyboard during password input. By exploiting eye movement patterns, we are able to infer the passwords being entered. We propose a novel algorithm to extract sensitive eye images from video streams, and classify these images with Support Vector Classification. We also propose a novel classification enhancement algorithm to further improve classification accuracy. Compared with prior keystroke detection approaches, GazeRevealer does not require any external auxiliary devices, and it only relies on smartphone front camera. We evaluate the performance of GazeRevealer on several smartphones under different real-life usage scenarios. The results show that GazeRevealer achieves an inference rate of 77.89 percent for single key number and an inference rate of 84.38 percent for 6-digit password in the ideal case. Yao Wang 0005, Wandong Cai, Tao Gu 0001, Wei Shao 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2018 | GazeRevealer: Inferring Password Using Smartphone Front CameraabstractThe widespread use of smartphones has brought great convenience to our daily lives, while at the same time we have been increasingly exposed to security threats. Keystroke security is an essential element in user privacy protection. In this paper, we present GazeRevealer, a novel side-channel based keystroke inference framework to infer sensitive inputs on smartphone from video recordings of victim's eye patterns captured from smartphone front camera. We observe that eye movements typically follow the keystrokes typing on the number-only soft keyboard during password input. By exploiting eye patterns, we are able to infer the passwords being entered. We propose a novel algorithm to extract sensitive eye pattern images from video streams, and classify different eye patterns with Support Vector Classification. We also propose a novel enhanced method to boost the inference accuracy. Compared with prior keystroke detection approaches, GazeRevealer does not require any external auxiliary devices, and it relies only on smartphone front camera. We evaluate the performance of GazeRevealer with three different types of smartphones, and the result shows that GazeRevealer achieves 77.43% detection accuracy for a single key number and 83.33% inference rate for the 6-digit password in the ideal case. Yao Wang 0005, Wandong Cai, Tao Gu 0001, Wei Shao 0006, Ibrahim Khalil 0001, Xianghua Xu |
MobiQuitous | 1 |
| 2018 | A Combined Static and Dynamic Analysis Approach to Detect Malicious Browser ExtensionsabstractIll-intentioned browser extensions pose an emergent security risk and have become one of the most common attack vectors on the Internet due to their wide popularity and high privilege. Once installed, malicious extensions are executed and attempt to compromise a victim’s browser. To detect malicious browser extensions, security researchers have put forward several techniques. These techniques primarily concentrate on the usage of API calls by malicious extensions, imposing restricted policies for extensions, and monitoring extension’s activities. In this paper, we propose a machine-learning-based approach to detect malicious extensions. We apply static and dynamic techniques to analyse an extension for extracting features. The analysis process extracts features from the source codes including JavaScript codes, HTML pages, and CSS files and the execution activities of an extension. To guarantee the robustness of the features, a feature selection method is then applied to retain the most relevant features while discarding low-correlated features. The detection models based on machine-learning techniques are subsequently constructed by leveraging these features. As can be seen from evaluation results, our detection model, containing over 4,600 labelled extension samples, is able to detect malicious extensions with an accuracy of 96.52% in validation set and 95.18% in test set, with a false positive rate of 2.38% in validation set and 3.66% in test set. Yao Wang 0005, Wandong Cai, Wei Shao 0006 |
Secur. Commun. Networks | 1 |
| 2016 | A deep learning approach for detecting malicious JavaScript codeabstractAbstract Malicious JavaScript code in webpages on the Internet is an emergent security issue because of its universality and potentially severe impact. Because of its obfuscation and complexities, detecting it has a considerable cost. Over the last few years, several machine learning‐based detection approaches have been proposed; most of them use shallow discriminating models with features that are constructed with artificial rules. However, with the advent of the big data era for information transmission, these existing methods already cannot satisfy actual needs. In this paper, we present a new deep learning framework for detection of malicious JavaScript code, from which we obtained the highest detection accuracy compared with the control group. The architecture is composed of a sparse random projection, deep learning model, and logistic regression. Stacked denoising auto‐encoders were used to extract high‐level features from JavaScript code; logistic regression as a classifier was used to distinguish between malicious and benign JavaScript code. Experimental results indicated that our architecture, with over 27 000 labeled samples, can achieve an accuracy of up to 95%, with a false positive rate less than 4.2% in the best case. Copyright © 2016 John Wiley & Sons, Ltd. Yao Wang 0005, Wandong Cai, Pengcheng Wei |
Secur. Commun. Networks | 1 |