VLDB 2026 Research / reviewers in the wild / expert
Tao Li 0042
dblp:75/4601-42
· DBLP profile ↗
29ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0002-5333-0586ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 3 first-author · 12 since 2021Security and privacy · 8 · 1 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TagStroke: Stealthy Keystroke Inference via Passive RFID Arrays Beneath Keyboards
Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042 |
INFOCOM | 5 |
| 2026 | EarlyShield: Early-Stage Screening for Robust Personalized Federated Learning
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
PAKDD (2) | 4 |
| 2026 | BadAMC: A Model-Agnostic Digital Backdoor Attack for Automatic Modulation Classification in Crowdsourced Platforms
Yan Zhang 0091, Ang Li 0013, Tao Li 0042 |
IEEE Trans. Netw. | 4 |
| 2025 | Physical Backdoor Attacks against mmWave-based Human Activity RecognitionabstractHuman Activity Recognition (HAR) using wireless signals like mmWave technology has promising applications in numerous scenarios, including monitoring and surveillance, healthcare, and smart home. Wireless HAR is non-intrusive and can operate in situations where traditional sensors or cameras may fail. However, these systems also introduce new attack surfaces alongside their benefits. Existing security research on wireless HAR primarily focuses on the vulnerabilities of the AI models used by these systems, without addressing the challenges of physically implementing these attacks in real-world scenarios. In this paper, we present the first physical backdoor attack for mmWave-based HAR systems, manipulating physical signals to deceive the systems into producing targeted outputs. Utilizing passive metal reflectors and optimized attacking strategies, our attack is efficient, stealthy, and easy to implement. Tailored experiments on a mmWave HAR prototype demonstrate the high effectiveness of the proposed attack. Ziqian Bi, Amit Singha, Hongfei Xue, Tao Li 0042, Yimin Chen 0004 |
ICDCS | 4 |
| 2025 | Beyond Uniformity: Robust Backdoor Attacks on Deep Neural Networks with Trigger Selection
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
PAKDD (6) | 4 |
| 2025 | Buffer is All You Need: Defending Federated Learning against Backdoor Attacks under Non-iids via BufferingabstractFederated Learning (FL) is a popular paradigm enabling clients to jointly train a global model without sharing raw data. However, FL is known to be vulnerable towards backdoor attacks due to its distributed nature. As participants, attackers can upload model updates that effectively compromise FL. More critically, existing defenses are mostly designed under independent-and-identically-distributed (iid) settings, hence neglecting the fundamental non-iid characteristic of FL. Here we propose FLBuff for tackling backdoor attacks even under non-iids. The main challenge for such defenses is that non-iids shorten the distance between benign and malicious updates, rendering them harder to separate. FLBuff is inspired by our insight that non-iids can be modeled as omni-directional expansion in representation space while backdoor attacks as uni-directional. This leads to the key design of FLBuff, i.e., a supervised-contrastive-learning model extracting penultimate-layer representations to create a large in-between buffer layer. Comprehensive evaluations demonstrate that FLBuff consistently outperforms state-of-the-art defenses. Code is at https://github.com/xingyushu/FLBuff. Xingyu Lyu, Ning Wang 0022, Yang Xiao 0010, Shixiong Li, Tao Li 0042, Danjue Chen, Yimin Chen 0004 |
TrustCom | 5 |
| 2024 | WaveKey: Secure Mobile Ad Hoc Access to RFID-Protected SystemsabstractThis paper presents the design and evaluation of WaveKey, a cross-modal deep learning-based method to enable mobile ad hoc in-situ access to RFID- protected cyber systems. Built upon the ever-growing popularity of user-carried mobile devices and RFID technologies, WaveKey is motivated by the need for secure and user-friendly data access in various application contexts. WaveKey explores a random gesture performed by the mobile user to induce correlated IMU data and RFID signals at the involved mobile device and RFID server, adopts deep learning techniques to extract the complex cross-modal correlation, and devises an Oblivious Transfer-based key-agreement protocol to-ward secure and efficient key establishment. Theoretical analysis and experimental human-based evaluation confirmed the high security and efficiency of WaveKey. In particular, WaveKey shows very high key-establishment success rates consistently exceeding 98 % across all evaluated settings and renders extremely low success rates below 0.5 % for all evaluated common attacks. Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042 |
ICDCS | 5 |
| 2024 | Securing Contrastive mmWave-based Human Activity Recognition against Adversarial Label FlippingabstractWireless Human Activity Recognition (HAR), leveraging their non-intrusive nature, has the potential to revolutionize various sectors, including healthcare, virtual reality, and surveillance. The advent of millimeter wave (mmWave) technology has significantly enhanced the capabilities of wireless HAR systems. This paper presents the first systematic study on the vulnerabilities of mmWave-based HAR to label flipping poisoning attacks in the context of supervised contrastive learning. We identify three label poisoning attacks on the contrastive mmWave-based HAR and propose corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other wireless HAR systems, thereby promoting security considerations in system design and deployment. Amit Singha, Ziqian Bi, Tao Li 0042, Yimin Chen 0004 |
WISEC | 3 |
| 2023 | mmLock: User Leaving Detection Against Data Theft via High-Quality mmWave Radar ImagingabstractThe use of smart devices such as smartphones, tablets, and laptops skyrocketed in the last decade. These devices enable ubiquitous applications for entertainment, communication, productivity, and healthcare but also introduce big concern about user privacy and data security. In addition to various authentication techniques, automatic and immediate device locking based on user leaving detection is an indispensable way to secure the devices. Current user leaving detection techniques mainly rely on acoustic ranging and do not work well in environments with multiple moving objects. In this paper, we present mmLock, a system that enables faster and more accurate user leaving detection in dynamic environments. mmLock uses a mmWave FMCW radar to capture the user's 3D mesh and detects the leaving gesture from the 3D human mesh data with a hybrid PointNet-LSTM model. Based on explainable user point clouds, mmLock is more robust than existing gesture recognition systems which can only identify the raw signal patterns. We implement and evaluate mmLock with a commercial off-the-shelf (COTS) TI mmWave radar in multiple environments and scenarios. We train the PointNet-LSTM model out of over 1 TB mmWave signal data and achieve 100% true-positive rate in most scenarios. Ziqian Bi, Amit Singha, Tao Li 0042, Yimin Chen 0004 |
ICCCN | 4 |
| 2023 | Evaluating the Impact of Noisy Point Clouds on Wireless Gesture Recognition SystemsabstractPoint cloud data gathered through wireless sensors has garnered increasing attention for its critical applications, including automotive radars, security systems, and notably, gesture recognition. It provides a non-intrusive and robust approach towards humancomputer interactions. However, its reliance on real-time data makes resilience of paramount concern and attacks on or imperfections with these sensors can have catastrophic effects. From real-time spoofing to data poisoning attacks or even just faulty data, systems based on 2D and 3D point cloud machine learning models can be extremely vulnerable. Despite this, there exist few studies prioritizing evaluations on the robustness of these systems over noisy time-sensitive point clouds. This study presents an in-depth examination on the effects of noisy data being used in training various millimeter wave based gesture recognition systems. Noisy point clouds can be introduced during the training stage where imperfect data is fed to a model, causing the model to misclassify test-time samples and lowering its overall accuracy. We stage and evaluate the impact of four different, simple data noising scenarios to observe potential vulnerabilities within these systems. Our findings reveal the respective susceptibilities and resiliencies of transformer, long-short term memory, and convolutional models, highlighting the importance to not only dedicate time and research towards innovations in wireless gesture recognition, but also towards optimizing these systems in order to proactively prevent undesirable effects. Paul Jiang, Ellie Fassman, Amit Singha, Yimin Chen 0004, Tao Li 0042 |
MobiHoc | 5 |
| 2023 | PhyAuth: Physical-Layer Message Authentication for ZigBee Networks
Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042, Ting Zhu 0001 |
USENIX Security Symposium | 5 |
| 2023 | SmartMagnet: Proximity-Based Access Control for IoT Devices With Smartphones and MagnetsabstractUbiquitous smartphones can be powerful tools to access IoT devices. Proximity-based access control (PBAC) is needed such that IoT devices only allow data access by legitimate users in close proximity. Traditional smartphone-based authentication techniques do not satisfy the PBAC requirements. This paper presents SmartMagnet, a novel scheme that combines smartphones and cheap magnets to achieve PBAC for IoT devices. SmartMagnet explores a few cheap, tiny commodity magnets which we propose to attach to or embed into IoT devices, as well as the magnetometer and attitude sensor on commodity smartphones. Each legitimate user performs a self-chosen 3D password gesture near the target IoT device with the enrolled smartphone. Then the system server uses the IoT device’s confidential magnet configuration parameters to reconstruct the user gesture from the magnetometer and attitude sensor data submitted by the smartphone. If the reconstructed gesture matches the stored template of the purported user, the smartphone user is deemed legitimate and allowed access to the IoT device. Extensive experiments confirm the high usability of SmartMagnet and its strong resilience to lost/stolen smartphones and also remote attacks via signal relaying. Yan Zhang 0091, Dianqi Han, Ang Li 0013, Jiawei Li 0010, Tao Li 0042 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | MagAuth: Secure and Usable Two-Factor Authentication With Magnetic Wrist WearablesabstractSecure and usable user authentication is the first line of defense against cyber attacks on smart end-user devices. Advanced hacking techniques pose severe threats to the traditional authentication systems based on the password/PIN/fingerprint. We propose MagAuth, a secure and usable two-factor authentication scheme with commercial off-the-shelf (COTS) wrist wearables with magnetic strap bands to enhance the security and usability of password-based authentication for mobile touchscreen devices. In MagAuth, a user enrolls a self-chosen unlock pattern or touch gesture into his touchscreen device by performing it with the same hand the magnetic wrist wearable is on. The chosen unlock pattern or touch gesture serves as the first authentication factor, and the user’s behavioral features manifested in the magnetic field changes during his finger movement correspond to the second factor. The user can unlock his touchscreen device only when both authentication factors can be validated. Comprehensive user experiments confirm the high security and usability of MagAuth. In particular, MagAuth achieves an average true-positive rate up to 96.3 percent and a false-positive rate no larger than 8.4 percent. Moreover, we show that MagAuth is highly resilient to various attacks. Yan Zhang 0091, Dianqi Han, Ang Li 0013, Tao Li 0042 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | Secure UHF RFID Authentication With Smart DevicesabstractCommodity ultra-high-frequency (UHF) RFID authentication systems only provide weak user authentication, as RFID tags can be easily stolen, lost, or cloned by attackers. This paper presents the design and evaluation of SmartRFID, a novel UHF RFID authentication system to promote commodity crypto-less UHF RFID tags for security-sensitive applications. SmartRFID explores extremely popular smart devices and requires a legitimate user to enroll his smart device along with his RFID tag. Besides authenticating the RFID tag as usual, SmartRFID verifies whether the user simultaneously possesses the associated smart device with both feature-based machine learning and deep learning techniques. The user is considered authentic if and only if passing the dual verifications. Comprehensive user experiments on commodity smartwatches and RFID devices confirmed the high security and usability of SmartRFID. In particular, SmartRFID achieves a true acceptance rate of above 97.5% and a false acceptance rate of less than 0.7% based on deep learning. In addition, SmartRFID can achieve an average authentication latency of less than 2.21 s, which is comparable to inputting a PIN on a door keypad or smartphone. Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Dianqi Han, Tao Li 0042 |
IEEE Trans. Wirel. Commun. | 5 |
| 2022 | WearRF-CLA: Continuous Location Authentication with Wrist Wearables and UHF RFIDabstractContinuous location authentication (CLA) seeks to continuously and automatically verify the physical presence of legitimate users in a protected indoor area. CLA can play an important role in contexts where access to electrical or physical resources must be limited to physically present legitimate users. In this paper, we present WearRF-CLA, a novel CLA scheme built upon increasingly popular wrist wearables and UHF RFID systems. WearRF-CLA explores the observation that human daily routines in a protected indoor area comprise a sequence of human-states (e.g., walking and sitting) that follow predictable state transitions. Each legitimate WearRF-CLA user registers his/her RFID tag and also wrist wearable during system enrollment. After the user enters a protected area, WearRF-CLA continuously collects and processes the gyroscope data of the wrist wearable and the phase data of the RFID tag signals to verify three factors to determine the user's physical presence/absence without explicit user involvement: (1) the tag ID as in a traditional RFID authentication system, (2) the validity of the human-state chain, and (3) the continuous coexistence of the paired wrist wearable and RFID tag with the user. The user passes CLA if and only if all three factors can be validated. Extensive user experiments on commodity smartwatches and UHF RFID devices confirm the very high security and low authentication latency of WearRF-CLA. Ang Li 0013, Jiawei Li 0010, Dianqi Han, Yan Zhang 0091, Tao Li 0042 |
AsiaCCS | 5 |
| 2022 | RCID: Fingerprinting Passive RFID Tags via Wideband BackscatterabstractTag cloning and spoofing pose great challenges to RFID applications. This paper presents the design and evaluation of RCID, a novel system to fingerprint RFID tags based on the unique reflection coefficient of each tag circuit. Based on a novel OFDM-based fingerprint collector, our system can quickly acquire and verify each tag’s RCID fingerprint which are independent of the RFID reader and measurement environment. Our system applies to COTS RFID tags and readers after a firmware update at the reader. Extensive prototyped experiments on 600 tags confirm that RCID is highly secure with the authentication accuracy up to 97.15% and the median authentication error rate equal to 1.49%. RCID is also highly usable because it only takes about 8 s to enroll a tag and 2 ms to verify an RCID fingerprint with a fully connected multi-class neural network. Finally, empirical studies demonstrate that the entropy of an RCID fingerprint is about 202 bits over a bandwidth of 20 MHz in contrast to the best prior result of 17 bits, thus offering strong theoretical resilience to RFID cloning and spoofing. Jiawei Li 0010, Ang Li 0013, Dianqi Han, Yan Zhang 0091, Tao Li 0042 |
INFOCOM | 5 |
| 2022 | (In)secure Acoustic Mobile AuthenticationabstractAcoustic fingerprinting aims to identify a mobile device based on its internal microphone(s) and speaker(s) which are unique due to manufacturing imperfection. This paper seeks a thorough understanding of the (in)security of exploring acoustic fingerprints for achieving distributed mobile authentication. Our contributions are threefold. First, we present a new acoustic fingerprint-emulation attack and demonstrate that it is a common vulnerability of acoustic mobile authentication systems. Second, we propose a dynamic challenge-response defense to secure acoustic mobile authentication systems against the acoustic fingerprint-emulation attack. Finally, we thoroughly investigate existing acoustic fingerprinting schemes and identify the best option for accurate, secure, and deployable acoustic mobile authentication systems. Dianqi Han, Ang Li 0013, Tao Li 0042, Yan Zhang 0091, Jiawei Li 0010, Rui Zhang 0007 |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | SpecKriging: GNN-Based Secure Cooperative Spectrum SensingabstractCooperative spectrum sensing (CSS) adopted by spectrum-sensing providers (SSPs) plays a key role for dynamic spectrum access and is essential for avoiding interference with licensed primary users (PUs). A typical SSP system consists of geographically distributed spectrum sensors which can be compromised to submit fake spectrum-sensing reports. In this paper, we propose SpecKriging, a new spatial-interpolation technique based on Inductive Graph Neural Network Kriging (IGNNK) for secure CSS. In SpecKriging, we first pretrain a graphical neural network (GNN) model with the historical sensing records of a few trusted anchor sensors. During system runtime, we use the trained model to evaluate the trustworthiness of non-anchor sensors’ data and also use them along with anchor sensors’ new data to retrain the model. SpecKriging outputs trustworthy sensor reports for spectrum-occupancy detection. To the best of our knowledge, SpecKriging is the first work that explores GNNs for trustworthy CSS and also incorporates the hardware heterogeneity of spectrum sensors. Extensive experiments confirm the high efficacy and efficiency of SpecKriging for trustworthy spectrum-occupancy detection even when malicious spectrum sensors constitute the majority. Yan Zhang 0091, Ang Li 0013, Jiawei Li 0010, Dianqi Han, Tao Li 0042, Rui Zhang 0007 |
IEEE Trans. Wirel. Commun. | 5 |
| 2021 | DroneKey: A Drone-Aided Group-Key Generation Scheme for Large-Scale IoT NetworksabstractThe Internet of Things (IoT) networks are finding massive applications in mission-critical contexts. A group key is needed to encrypt and authenticate broadcast/multicast messages commonly seen in large-scale wireless networks. In this paper, we propose DroneKey, a novel drone-aided PHY-based Group-Key Generation (GKG) scheme for large-scale IoT networks. In DroneKey, a drone is dispatched to fly along random 3D trajectories and keep broadcasting standard wireless signals to refresh the group keys in the whole network. Every IoT device receives the broadcast signals from which to extract the Channel State Information (CSI) stream which captures the dynamic variations of the individual wireless channel between the IoT device and the drone. DroneKey explores a deep-learning approach to extract the hidden correlation among the CSI streams to establish a common group key. We thoroughly evaluate DroneKey with a prototype in both indoor and outdoor environments. We show that DroneKey can achieve a high key-generation rate of 89.5 bit/sec for 10 devices in contrast to 40 bit/sec in the state-of-art prior work. In addition, DroneKey is much more scalable and can support 100 devices in contrast to 10 nodes in the state-of-art prior work with comparable key-generate rates. Dianqi Han, Ang Li 0013, Jiawei Li 0010, Yan Zhang 0091, Tao Li 0042 |
CCS | 5 |
| 2021 | Your Home is Insecure: Practical Attacks on Wireless Home Alarm SystemsabstractWireless home alarm systems are being widely deployed, but their security has not been well studied. Existing attacks on wireless home alarm systems exploit the vulnerabilities of networking protocols while neglecting the problems arising from the physical component of IoT devices. In this paper, we present new event-eliminating and event-spoofing attacks on commercial wireless home alarm systems by interfering with the reed switch in almost all COTS alarm sensors. In both attacks, the external adversary uses his own magnet to control the state of the reed switch in order to either eliminate legitimate alarms or spoof false alarms. We also present a new battery-depletion attack with programmable electromagnets to deplete the alarm sensor's battery quickly and stealthily in hours which is expected to last a few years. The efficacy of our attacks is confirmed by detailed experiments on a representative Ring alarm system. Tao Li 0042, Dianqi Han, Jiawei Li 0010, Ang Li 0013, Yan Zhang 0091, Rui Zhang 0007 |
INFOCOM | 1 |
| 2021 | Deep Learning-Guided Jamming for Cross-Technology Wireless Networks: Attack and DefenseabstractWireless networks of different technologies may interfere with each other when they are deployed at proximity. Such cross-technology interference (CTI) has become prevalent with the surge of IoT devices. In this paper, we exploit CTI in coexisting WiFi-Zigbee networks and propose DeepJam, a new stealthy jamming strategy, to jam Zigbee traffic. DeepJam relies on deep learning techniques to capture the temporal pattern of the past wireless traffic and predict the future wireless traffic. By only jamming the victim’s transmissions that are not disrupted by CTI, DeepJam can significantly reduce the victim’s throughput with far fewer jamming signals and is thus much more stealthy than conventional jamming strategies. Detailed evaluations show that DeepJam can converge within 10 sec and achieve the jamming-efficiency gains of up to 742% and 285% over conventional random and reactive jamming strategies, respectively, in practical scenarios. We also propose a simple yet effective countermeasure against DeepJam. Dianqi Han, Ang Li 0013, Yan Zhang 0091, Jiawei Li 0010, Tao Li 0042, Ting Zhu 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2020 | IndoorWaze: A Crowdsourcing-Based Context-Aware Indoor Navigation SystemabstractIndoor navigation systems are very useful in large complex indoor environments such as shopping malls. Current systems focus on improving indoor localization accuracy and must be combined with an accurate labeled floor plan to provide usable indoor navigation services. Such labeled floor plans are often unavailable or involve a prohibitive cost to manually obtain. In this paper, we present IndoorWaze, a novel crowdsourcing-based context-aware indoor navigation system that can automatically generate an accurate context-aware floor plan with labeled indoor POIs for the first time in literature. IndoorWaze combines the Wi-Fi fingerprints of indoor walkers with the Wi-Fi fingerprints and POI labels provided by POI employees to produce a high-fidelity labeled floor plan. As a lightweight crowdsourcing-based system, IndoorWaze involves very little effort from indoor walkers and POI employees. We prototype IndoorWaze on Android smartphones and evaluate it in a large shopping mall. Our results show that IndoorWaze can generate a high-fidelity labeled floor plan, in which all the stores are correctly labeled and arranged, all the pathways and crossings are correctly shown, and the median estimation error for the store dimension is below 12%. Tao Li 0042, Dianqi Han, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth |
IEEE Trans. Wirel. Commun. | 1 |
| 2019 | SocialDistance: how far are you from verified users in online social media?abstractVerified users on online social media (OSM) largely determine the quality of OSM services and applications, but most OSM users are unverified due to the significant effort involved in becoming a verified user. This paper presents SocialDistance, a novel technique to identify unverified users that can be considered as trustworthy as verified users. SocialDistance is motivated by the observation that online interactions initiated from verified users towards unverified users can translate into some sort of trustworthiness. It treats all verified users equally and assigns a trust score between 0 and 1 to each unverified user. The higher the trust score, the closer an unverified user to verified users. We propose various metrics to model the interactions from verified to unverified users and then derive corresponding trust scores. SocialDistance is thoroughly evaluated with large Twitter datasets containing 276,143 verified users and 19,047,202 unverified users. Our results demonstrate that SocialDistance can produce a non-trivial number of unverified users that can be regarded as verified users for OSM applications. We also show the high efficacy of SocialDistance in sybil detection, a fundamental operation performed by virtually every OSM operator. Ang Li 0013, Tao Li 0042, Yan Zhang 0091 |
IWQoS | 2 |
| 2018 | Secure Crowdsourced Indoor Positioning SystemsabstractIndoor positioning systems (IPSes) can enable many location-based services in large indoor environments where GPS is not available or reliable. Mobile crowdsourcing is widely advocated as an effective way to construct IPS maps. This paper presents the first systematic study of security issues in crowd-sourced WiFi-based IPSes to promote security considerations in designing and deploying crowdsourced IPSes. We identify three attacks on crowdsourced WiFi-based IPSes and propose the corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other crowdsourced IPSes. Tao Li 0042, Yimin Chen 0004, Rui Zhang 0007, Terri Hedgpeth |
INFOCOM | 1 |
| 2018 | Proximity-Proof: Secure and Usable Mobile Two-Factor AuthenticationabstractMobile two-factor authentication (2FA) has become commonplace along with the popularity of mobile devices. Current mobile 2FA solutions all require some form of user effort which may seriously affect the experience of mobile users, especially senior citizens or those with disability such as visually impaired users. In this paper, we propose Proximity-Proof, a secure and usable mobile 2FA system without involving user interactions. Proximity-Proof automatically transmits a user's 2FA response via inaudible OFDM-modulated acoustic signals to the login browser. We propose a novel technique to extract individual speaker and microphone fingerprints of a mobile device to defend against the powerful man-in-the-middle (MiM) attack. In addition, Proximity-Proof explores two-way acoustic ranging to thwart the co-located attack. To the best of our knowledge, Proximity-Proof is the first mobile 2FA scheme resilient to the MiM and co-located attacks. We empirically analyze that Proximity-Proof is at least as secure as existing mobile 2FA solutions while being highly usable. We also prototype Proximity-Proof and confirm its high security, usability, and efficiency through comprehensive user experiments. Dianqi Han, Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth |
MobiCom | 3 |
| 2018 | EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsabstractKeystroke inference attacks pose an increasing threat to ubiquitous mobile devices. This paper presents EyeTell, a novel video-assisted attack that can infer a victim's keystrokes on his touchscreen device from a video capturing his eye movements. EyeTell explores the observation that human eyes naturally focus on and follow the keys they type, so a typing sequence on a soft keyboard results in a unique gaze trace of continuous eye movements. In contrast to prior work, EyeTell requires neither the attacker to visually observe the victim's inputting process nor the victim device to be placed on a static holder. Comprehensive experiments on iOS and Android devices confirm the high efficacy of EyeTell for inferring PINs, lock patterns, and English words under various environmental conditions. Yimin Chen 0004, Tao Li 0042, Rui Zhang 0007, Terri Hedgpeth |
IEEE Symposium on Security and Privacy | 2 |
| 2017 | Your face your heart: Secure mobile face authentication with photoplethysmogramsabstractFace authentication emerges as a powerful method for preventing unauthorized access to mobile devices. It is, however, vulnerable to photo-based forgery attacks (PFA) and videobased forgery attacks (VFA), in which the adversary exploits a photo or video containing the user's frontal face. Effective defenses against PFA and VFA often rely on liveness detection, which seeks to find a live indicator that the submitted face photo or video of the legitimate user is indeed captured in real time. In this paper, we propose FaceHeart, a novel and practical face authentication system for mobile devices. FaceHeart simultaneously takes a face video with the front camera and a fingertip video with the rear camera on COTS mobile devices. It then achieves liveness detection by comparing the two photoplethysmograms independently extracted from the face and fingertip videos, which should be highly consistent if the two videos are for the same live person and taken at the same time. As photoplethysmograms are closely tied to human cardiac activity and almost impossible to forge or control, FaceHeart is strongly resilient to PFA and VFA. Extensive user experiments on Samsung Galaxy S5 have confirmed the high efficacy and efficiency of FaceHeart. Yimin Chen 0004, Jingchao Sun, Xiaocong Jin, Tao Li 0042, Rui Zhang 0007 |
INFOCOM | 4 |
| 2016 | DPSense: Differentially Private Crowdsourced Spectrum SensingabstractDynamic spectrum access (DSA) has great potential to address worldwide spectrum shortage by enhancing spectrum efficiency. It allows unlicensed secondary users to access the underutilized licensed spectrum when the licensed primary users are not transmitting. As a key enabler for DSA systems, crowdsourced spectrum sensing (CSS) allows a spectrum sensing provider (SSP) to outsource the sensing of spectrum occupancy to distributed mobile users. In this paper, we propose DPSense, a novel framework that allows the SSP to select mobile users for executing spatiotemporal spectrum-sensing tasks without violating the location privacy of mobile users. Detailed evaluations on real location traces confirm that DPSense can provide differential location privacy to mobile users while ensuring that the SSP can accomplish spectrum-sensing tasks with overwhelming probability and also the minimal cost. Xiaocong Jin, Rui Zhang 0007, Yimin Chen 0004, Tao Li 0042 |
CCS | 4 |
| 2016 | iLock: Immediate and Automatic Locking of Mobile Devices against Data TheftabstractMobile device losses and thefts are skyrocketing. The sensitive data hosted on a lost/stolen device are fully exposed to the adversary. Although password-based authentication mechanisms are available on mobile devices, many users reportedly do not use them, and a device may be lost/stolen while in the unlocked mode. This paper presents the design and evaluation of iLock, a secure and usable defense against data theft on a lost/stolen mobile device. iLock automatically, quickly, and accurately recognizes the user's physical separation from his/her device by detecting and analyzing the changes in wireless signals. Once significant physical separation is detected, the device is immediately locked to prevent data theft. iLock relies on acoustic signals and requires at least one speaker and one microphone that are available on most COTS (commodity-off-the-shelf) mobile devices. Extensive experiments on Samsung Galaxy S5 show that iLock can lock the device with negligible false positives and negatives. Tao Li 0042, Yimin Chen 0004, Jingchao Sun, Xiaocong Jin |
CCS | 1 |