Jinsong Han

dblp:96/6606 · DBLP profile ↗
← Back
164ranked-venue papers
7as first author
84since 2021 · last 2026
0000-0001-5064-1955ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 110 · 6 first-author · 61 since 2021Systems, architecture and hardware · 22 · 1 first-author · 4 since 2021Security and privacy · 15 · 14 since 2021Human-computer interaction and ubiquitous computing · 6 · 1 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Turning GPU into an FM Radio: A Practical Data Exfiltration Framework from Air-gapped Systems
Rui Xiao 0002, Sibo Feng, Jinsong Han
INFOCOM3
2026 EchoFence: Non-Intrusive Forgery Detection in Video Conferencing via Ultrasonic Sensing
Leqi Zhao, Luxin Shi, Jianwei Liu 0008, Rui Xiao 0002, Jinsong Han
INFOCOM5
2026 Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-Channel
Rui Xiao 0002, Sibo Feng, Soundarya Ramesh, Jun Han 0001, Jinsong Han
NDSS5
2026 Zero-Effort Cross-Domain Wireless Respiration Monitoring Under Free Movements With Commercial UWB Devices
abstract
Respiratory monitoring using wireless technologies has garnered significant attention for its potential in healthcare, smart cockpits, and various applications. Though extensively studied, existing systems face practical challenges in adapting to new data domains without substantial customization efforts. Current solutions attempt to address this limitation through domain-independent feature extraction or cross-domain feature translation, employing either knowledge-based sensing models or data-driven neural networks. However, these approaches typically require additional data collection or model retraining for new domains, significantly hindering their practical deployment. This paper proposes RF-Carer, a fully zero-effort cross-domain respiration monitoring system. Our key innovation lies in building an explainable propagation model to transform any heterogeneous signals under unknown domains into a unified form in the signal processing layer. To further address accidental irrelevant factors, we propose to align the feature spaces while suppressing the noisy ones with contrastive learning. On this basis, we develop a one-fits-all model that requires only one-time training but can adapt to 12 domains with 57 cases like unconstrained movements, unknown users, untrained environments, etc.. To the best of our knowledge, RF-Carer is the first zero-effort cross-domain respiration monitoring work with wireless RF signals and would be a fundamental step toward real-world deployments.
Ge Wang 0003, Jiazheng Chen, Zhe Chen 0015, Fei Wang 0037, Cong Zhao 0006, Han Ding 0002, Cui Zhao, Wei Xi 0003, Jinsong Han
SenSys10
2026 Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel Attacks
Xutong Zhang, Leqi Zhao, Kaiyan Cui, Ming Gao 0023, Jinsong Han, Fu Xiao 0001
WWW8
2026 High-Fidelity and Location-Robust Respiratory Waveform Monitoring With Single-Antenna Wi-Fi
Hefei Wang, Jianwei Liu 0008, Yinghui He, Guanding Yu, Jinsong Han
IEEE Internet Things J.5
2026 Ultrasound-Assisted Tamper-Proof Detection Against Speech Editing, Tampering, and Forgery in Real-Time Voice Applications
abstract
Unauthorized editing of speech recordings poses a significant threat to the security and authenticity of speeches, particularly in the forensic and legal fields. Even worse, the speech is increasingly at risk of being tampered with due to the development of AI techniques (e.g., Audio Deepfake). It is difficult for normal users to guarantee what they say has not been illegally changed. Audio watermark techniques are recognized as an active method against speech forgery. However, such techniques suffer from audio quality degradation and non-real-time insertion. Therefore, they cannot be adopted into real-time voice applications against forgery on remote recordings, e.g., phone calls, live broadcasts, and online meetings. Fortunately, high-definition (HD) audio techniques provide ultrasonic bands without distortion. Therefore, ultrasonic creditable factors can be utilized. We propose an audio tamper-proof system, named Aegis. It provides commodity mobile devices (e.g., smartphones) with an effective method of real-time insertion of inaudible creditable factors. Users can claim that audio with no or mismatched ultrasound is invalid and illegal. In particular, we explore a novel acoustic nonlinear phenomenon where audible signals can be modulated onto the ultrasonic spectrum. By emphasizing the correlation between speech signals and ultrasound, we realize effective defense against various tampering methods. Extensive evaluations demonstrate that Aegis yields a detection accuracy of 99.5% on average even against unseen tampering methods.
Ming Gao 0023, Lingfeng Zhang 0004, Yike Chen, Feng Qian 0006, Kaiyan Cui, Fu Xiao 0001, Jinsong Han
IEEE Trans. Dependable Secur. Comput.7
2026 Anti-Spoofing and Mask-Supported Face Authentication Using mmWave Without On-Site Registration
abstract
Face authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and susceptible to masks and vulnerable to spoofing attacks. This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans faces by moving a commodity mmWave radar along a specific trajectory. The signals bounced off the face carry facial biometric and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well when users wear masks. To en- hance security, we develop a liveness detection method and an amplitude modulation-based method to defend against spoofing attacks and replay attacks. We enhance the basic version of mmFace [1] by improving its performance under mask occlusion and replay attack resilience. Besides, we explore a distance-resistant structure feature to suppress the impact of unstable face- to-device distance. To avoid on-site registration, we propose a novel virtual registration approach based on the cross-modal transformation from photos to mmWave. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments demonstrate mmFace's accuracy in FA and effectiveness in attack detection.
Wenfan Song, Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Xinhuai Wang, Jinsong Han
IEEE Trans. Dependable Secur. Comput.7
2026 Quick-Pass Continuous Authentication With Real-Time Biometrics Extraction on COTS Earphones Using Out-Ear Microphones
abstract
Continuous authentication is increasingly critical for cyber security. However, existing approaches are time-consuming due to their simplistic signal modulation and low efficiency in feature extraction. In this paper, we propose a continuous authentication technique, OnePiece. OnePiece is free from the requirement of in-ear microphones, which are necessary for existing earphone authentication systems. It exploits out-ear microphones for biometrics extraction, which are ubiquitous on off-the-shelf earphones. We analyze the acoustic response model of ears towards out-ear microphones via the air, which is different from that towards in-ear microphones. A frequency-varying ultrasonic modulation scheme is proposed to characterize in-depth ear biometrics in user-friendly, error-free, and time-efficient ways. Therefore, OnePiece enables quick-pass authentication once users wear the earphones, followed by continuous authentication covering the whole course. Moreover, we propose a wake-up mechanism to reduce the consumed power, which addresses the key power consumption issue in ultrasonic sensing techniques. Particularly, OnePiece can be smoothly deployed on off-the-shelf wired and wireless earphones. It performs good cross-device performance in which users just register only once. Extensive evaluations are conducted to validate its effectiveness under real-world scenarios.
Ming Gao 0023, Jiatong Chen, Ruitong Ye, Yike Chen, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.7
2026 Practical WiFi Indoor Localization: Unleashing the Potential of GNNs for Accuracy and Robustness
abstract
WiFi-based indoor localization, supported by comprehensive infrastructure, is considered a highly promising solution. However, practical applications of existing WiFi-based methods often struggle due to dynamic antenna configurations and potential influence from obstacles, which can undermine the reliability of channel state information and frustrate localization. Even worse, environmental changes may lead to a domain shift, further degrading localization accuracy and system robustness. To address these problems, this paper introduces GraphFi, a novel system that leverages graph neural networks (GNNs) to deliver accurate and robust localization using nearby access points (APs). GraphFi designs two types of graph structures: intra-AP graph and inter-AP graph, to maximize the use of information from all available APs. They aggregate the local features among antennas within each AP and global features across APs, effectively addressing the problem of dynamic antenna configurations. Two specialized GNNs are utilized to derive accurate user locations from these graphs. Additionally, we introduce an anomaly detection method to identify and exclude obstacle-affected APs. This method also employs a tailored GNN to mitigate influence from unpredictable obstacles. Furthermore, we integrate an unsupervised domain adaptation mechanism based on a gradient reversal layer into GNNs. This helps maintain localization performance in a cost-efficient manner and ensures sustained effectiveness in a cross-domain setting. We prototype GraphFi using commodity WiFi devices and conduct extensive experiments in various scenarios. The results demonstrate that GraphFi achieves average localization errors of 0.17 m in a single-domain setting and 0.2851 m in a cross-domain setting, surpassing existing solutions in both precision and robustness.
Ziqi Ye, Qiqi Xiao, Jianwei Liu 0008, Yinghui He, Guanding Yu, Jinsong Han
IEEE Trans. Mob. Comput.6
2025 HiLoTs: High-Low Temporal Sensitive Representation Learning for Semi-Supervised LiDAR Segmentation in Autonomous Driving
abstract
LiDAR point cloud semantic segmentation plays a crucial role in autonomous driving. In recent years, semi-supervised methods have gained popularity due to their significant reduction in annotation labor and time costs. Current semi-supervised methods typically focus on point cloud spatial distribution or consider short-term temporal representations, e.g., only two adjacent frames, often overlooking the rich long-term temporal properties inherent in autonomous driving scenarios. In driving experience, we observe that nearby objects, such as roads and vehicles, remain stable while driving, whereas distant objects exhibit greater variability in category and shape. This natural phenomenon is also captured by Li-DAR, which reflects lower temporal sensitivity for nearby objects and higher sensitivity for distant ones. To lever-age these characteristics, we propose HiLoTs, which learns high-temporal sensitivity and low-temporal sensitivity representations from continuous LiDAR frames. These representations are further enhanced and fused using a cross-attention mechanism. Additionally, we employ a teacher-student framework to align the representations learned by the labeled and unlabeled branches, effectively utilizing the large amounts of unlabeled data. Experimental results on the SemanticKITTI and nuScenes datasets demonstrate that our proposed HiLoTs outperforms state-of-the-art semi-supervised methods, and achieves performance close to Li-DAR+Camera multimodal approaches.
R. D. Lin, Pengcheng Weng, Yinqiao Wang, Han Ding 0002, Jinsong Han, Fei Wang 0037
CVPR5
2025 Communication-efficient Verifiable and Oblivious Aggregation with Client Dropouts
abstract
Federated learning (FL) allows each client to train data locally and share only model parameters with an aggregation server. A critical component of FL is secure aggregation (SA), which protects user privacy during the server-side aggregation of client model parameters. However, SA-based FL still faces several challenges from a malicious server, affecting both performance and security. To address these issues, we propose the first 2-round-trip verifiable and oblivious aggregation protocol. Specifically, our protocol incorporates: (1) a consistent temporary key disclosure mechanism for round-trip-efficient communication with client dropout resilience; (2) a message authentication code to verify aggregation results; and (3) a multi-round oblivious aggregation scheme that conceals both individual and global model parameters. These three key techniques collectively enable efficient communication while preventing a malicious server from tampering with aggregation results and accessing any individual or global parameters. We conducted a comprehensive evaluation to demonstrate the practicality and efficiency of our design compared to existing schemes.
Zhangshuang Guan, Longyun Yang, Zhiguo Wan, Jinsong Han
ICASSP5
2025 Exploring Acoustic Reverse Nonlinearity Against Speech Forgery in Real-Time Voice Applications
Ming Gao 0023, Lingfeng Zhang 0004, Yike Chen, Sifeng He, Feng Qian 0006, Lei Yang 0061, Fu Xiao 0001, Jinsong Han
INFOCOM8
2025 Argus-ear: Unconstrained-Vocabulary Sound Eavesdropping via μm-level mmWave Sensing
abstract
Speech carries a wealth of sensitive information, and many studies have investigated various methods of speech eavesdropping. Recent research has shown that even in soundproof indoor environments, speech systems can still be compromised by outdoor RF sensing technologies. However, existing approaches either rely heavily on prior knowledge of the target environment, fail when the primary sound source is occluded, or are limited to word-level classification. Consequently, they have not fully exposed the severe threats that RF sensing poses to speech privacy. To bridge these gaps, this paper presents Argus-ear, a mmWave-based speech eavesdropping system. By localizing and identifying sound sources throughout the target room, Argus-ear captures subtle vibrations from the most eavesdropping-worthy reflectors and reconstructs speech using deep neural networks. A series of techniques are proposed to enhance weak vibration sensing, suppress noise interference, and improve the fidelity of speech reconstruction. Extensive experiments demonstrate that Argus-ear can identify various types of sound sources and accurately reconstruct unconstrained vocabulary-level speech across different languages, speakers, and sound sources.
Jiyang Chen, Jianwei Liu 0008, Jinsong Han
MASS3
2025 Poster: Zero-effort Cross-domain Wireless Respiration Monitoring under Free Body Movement
abstract
Wireless respiratory monitoring has garnered significant attention for its potential in various applications. However, existing systems face practical challenges in adapting to new data domains without substantial customization efforts. Current solutions attempt to address this limitation through domain-independent feature extraction or cross-domain feature translation, employing either knowledge-based sensing models or data-driven neural networks. However, these approaches typically require additional data collection or model retraining for new domains, significantly hindering their practical deployment. This paper proposes RF-Carer, a fully zero-effort cross-domain respiration monitoring system. Our key innovation lies in building an explainable propagation model to transform any heterogeneous signals under unknown domains into a unified form in the signal processing layer. To further address accidental irrelevant factors, we propose to align the feature spaces while suppressing the noisy ones with contrastive learning. On this basis, we develop a one-fits-all model that requires only one-time training but can adapt to unknown scenarios with unconstrained user movements, postures, positions, etc. To the best of our knowledge, RF-Carer is the first zero-effort cross-domain respiration monitoring work with wireless RF signals and would be a fundamental step toward real-world deployments.Chen
Jiazheng Chen, Ge Wang 0003, Zhe Chen 0015, Fei Wang 0037, Wei Xi 0003, Jinsong Han
MobiCom6
2025 Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi
Rui Xiao 0002, Xiankai Chen, Yinghui He, Jun Han 0001, Jinsong Han
NDSS5
2025 DiskSpy: Exploring a Long-Range Covert-Channel Attack via mmWave Sensing of μm-level HDD Vibrations
Weiye Xu 0001, Danli Wen, Jianwei Liu 0008, Zixin Lin, Yuanqing Zheng, Jinsong Han
USENIX Security Symposium7
2025 BullyDetect: Detecting School Physical Bullying With Wi-Fi and Deep Wavelet Transformer
abstract
More than 246 million children and adolescents suffer from school violence and bullying, e.g., verbal harassment, social harassment, and physical bullying, every year, according to a report from the United Nations Educational, Scientific and Cultural Organization. School violence and bullying severely harm the physical and emotional well-being of the victims, increasing the risks of depression, anxiety, sleep difficulties, lower academic achievement, dropping out of school, and even suicide attempts. Since school physical bullying always happens in the low-visibility areas spots of surveillance cameras, in this article, we propose to utilize Wi-Fi, a widely deployed infrastructure, to detect school physical bullying. We design residual wavelet transformer networks to conduct noise removal and action feature learning in an end-to-end manner. Besides, we propose two data augmentation methods in the temporal domain of Wi-Fi signals to simulate the different speeds and extents of bullying actions performed. Extensive evaluation of 20-paired volunteers demonstrates that 1) Wi-Fi can effectively detect physical school bullying; 2) the proposed approaches outperform long-short-time-memory networks, ResNet-1D, vision transformer, etc.; and 3) the proposed data augmentation methods can work as plug-and-play modules to improve the detection accuracy of all the above-mentioned approaches.
Fei Wang 0037, Lekun Xia, Fan Nai, Shiqiang Nie, Han Ding 0002, Jinsong Han
IEEE Internet Things J.7
2025 Efficient One-Shot Gesture Recognition for WiFi ISAC via Aug-Meta Learning
abstract
WiFi-based gesture recognition (WGR) has emerged as a promising technology due to its potential for integration with communication systems under the concept of integrated sensing and communication (ISAC). However, current WGR systems face two primary challenges: limited scalability for recognizing new gestures and poor compatibility with ISAC. These systems typically require extensive data collection and retraining for each new gesture and struggle to handle the dimensional variability of channel state information (CSI) caused by fluctuating data traffic in communication networks. To overcome these limitations, we introduce OneSense, a one-shot WGR system designed for seamless integration with communication systems. OneSense designs a data enrichment technique based on the law of signal propagation to generate virtual gestures. Based on enriched dataset, OneSense leverages an aug-meta learning (AML) framework to facilitate efficient and scalable FSL. OneSense also incorporates a data cropping strategy to enhance gesture feature prominence and a dynamic size-adaptive backbone model that ensures compatibility with CSI samples exhibiting dimensional inconsistencies. Experimental results show that OneSense achieves over 94% accuracy in one-shot gesture recognition. A case study further illustrates its effectiveness in ISAC contexts. Furthermore, our proposed AML framework reduces pre-training latency by more than 86% compared to conventional meta-learning approaches.
Jianwei Liu 0008, Jiantao Yuan, Guanding Yu, Jinsong Han
IEEE J. Sel. Areas Commun.4
2025 OPSA: Efficient and Verifiable One-Pass Secure Aggregation With TEE for Federated Learning
abstract
Federated learning enables collaborative model training while preserving data privacy by keeping data local. To protect user privacy during model aggregation, secure aggregation (SA) protocols are widely adopted to mask models. However, existing SA protocols require at least three round trips per aggregation and lack mechanisms to verify aggregation results. Verifiable SA addresses the verification gap but incurs high communication costs. TEE-based SA minimizes round trips but faces computational bottlenecks due to TEE's limited physical memory, especially when handling larger models or numerous clients. In this work, we introduce OPSA, an efficient and verifiable one-pass SA protocol based on TEE. By handling client dropouts via server-side TEE, OPSA enables the server to aggregate masked models in a single pass, significantly reducing round trips. To mitigate TEE's limitations, OPSA offloads tasks like model aggregation and mask elimination outside TEE, with only shared keys processed within TEE. Building on this design, we propose KhPRF-OPSA (single masking) and POT-OPSA (double masking) protocols, both incorporating novel cryptographic primitives. Furthermore, OPSA integrates commitment and signature mechanisms to ensure result verifiability with only$O(1)$additional communication overhead per client. Compared to state-of-the-art schemes, OPSA achieves a 2$\sim 10\times$speedup in multi-round aggregation while guaranteeing result verification.
Zhangshuang Guan, Zhiguo Wan, Jinsong Han
IEEE Trans. Dependable Secur. Comput.4
2025 Replay-Resistant Few-Shot Disk Authentication Using Electromagnetic Fingerprint
abstract
External disks (henceforth referred to as disks) are commonly used data storage peripherals for hosts. Verifying the legitimacy of these disks is essential to mitigate security risks, such as privacy breaches and virus propagation, before initiating interactions with a host. To address this challenge, we proposeDiskPrint, a novel replay-resistant, few-shot disk authentication system that relies on unintentional electromagnetic (EM) emanations from the internal components of disks. The core idea ofDiskPrintis that EM signals emitted during data writing operations can reveal unique hardware discrepancies among different disks. Building on electromagnetic theory, we develop a theoretical model that links EM signals to the underlying electronic components of the disk, demonstrating the feasibility of extracting distinctive disk fingerprints from these emanations. We also propose a set of signal enhancement techniques aimed at mitigating EM interface noise and improving the signal-to-noise ratio (SNR) of the EM measurements. To further strengthen the security ofDiskPrint, we introduce a device-agnostic, replay-resistant approach by incorporating randomness into the leaked EM signals. Real-world experiments with 60 disks, spanning both hard disk drives (HDDs) and solid-state drives (SSDs) from seven brands and 14 different models, indicate thatDiskPrintachieves an authentication success rate exceeding 99.6% with only three registration samples. A robustness analysis confirms its stability over time, while a security evaluation shows its resilience against various attack scenarios.
Jianwei Liu 0008, Wenfan Song, Jiantao Yuan, Guanding Yu, Jinsong Han
IEEE Trans. Dependable Secur. Comput.6
2025 Real-Time Video Forgery Detection via Vision-WiFi Silhouette Correspondence
abstract
For safety guard and crime prevention, video surveillance systems have been pervasively deployed in many security-critical scenarios, such as the residence, retail stores, and banks. However, these systems could be infiltrated by the adversary and the video streams would be modified or replaced, i.e., under the video forgery attack. The prevalence of Internet of Things (IoT) devices and the emergence of Deepfake-like techniques severely emphasize the vulnerability of video surveillance systems under such attacks. To secure existing surveillance systems, in this paper we propose a vision-WiFi cross-modal video forgery detection system, namelyWiSil. Leveraging a theoretical model based on the principle of signal propagation,WiSilconstructs wave front information of the object in the monitoring area from WiFi signals. With a well-designed deep learning network,WiSilfurther recovers silhouettes from the wave front information. Based on a Siamese network-based semantic feature extractor,WiSilcan eventually determine whether a frame is manipulated by comparing the semantic feature vectors extracted from the video’s silhouette with those extracted from the WiFi’s silhouette. We enhance the basic version ofWiSilFang et al. 2023 by developing a model compression method and a forgery trace localization method. Extensive experiments show thatWiSilachieves 95%$+$accuracy in detecting tampered frames.
Jianwei Liu 0008, Xinyue Fang, Yike Chen, Jiantao Yuan, Guanding Yu, Jinsong Han
IEEE Trans. Mob. Comput.6
2025 Hierarchical and Heterogeneous Federated Learning via a Learning-on-Model Paradigm
abstract
Federated Learning (FL) collaboratively trains a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., smartphones and wearables) typically have disparate system resources. Traditional FL, however, adopts a one-size-fits-all solution, where a homogeneous large model is sent to and trained on each client. This method results in an overwhelming workload for less capable clients and starvation for others. To tackle this, we proposeFedConv, a client-friendly FL framework, minimizing the system overhead on resource-constrained clients by providing heterogeneous customized sub-models.FedConvfeatures a novellearning-on-modelparadigm that learns the parameters of heterogeneous sub-models viaconvolutional compression. To aggregate heterogeneous sub-models, we proposetransposed convolutional dilationto convert them back to large models with a unified size while retaining personalized information. The compression and dilation processes, transparent to clients, are tuned on the server using a small public dataset. We further propose ahierarchical and clustering-based local trainingstrategy for enhanced performance. Extensive experiments on six datasets show thatFedConvoutperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively).
Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han
IEEE Trans. Mob. Comput.7
2025 You Can Wash Hands Better: Accurate Daily Handwashing Assessment With a Smartwatch
abstract
Hand hygiene is among the most effective daily practices for preventing infectious diseases such as influenza, malaria, and skin infections. While professional guidelines emphasize proper handwashing to reduce the risk of viral infections, surveys reveal that adherence to these recommendations remains low. To address this gap, we propose UWash, a wearable solution leveraging smartwatches to evaluate handwashing procedures, aiming to raise awareness and cultivate high-quality handwashing habits. We frame the task of handwashing assessment as an action segmentation problem, similar to those in computer vision, and introduce a simple yet efficient two-stream UNet-like network to achieve this goal. Experiments involving 51 subjects demonstrate that UWash achieves 92.27% accuracy in handwashing gesture recognition, an error of$\lt $0.5 seconds in onset/offset detection, and an error of$\lt $5 points in gesture scoring under user-dependent settings. The system also performs robustly in user-independent and user-independent-location-independent evaluations. Remarkably, UWash maintains high performance in real-world tests, including evaluations with 10 random passersby at a hospital 9 months later and 10 passersby in an in-the-wild test conducted 2 years later. UWash is the first system to score handwashing quality based on gesture sequences, offering actionable guidance for improving daily hand hygiene. The code and dataset are publicly available athttps://github.com/aiotgroup/UWash.
Fei Wang 0037, Xilei Wu, Xin Wang 0195, Han Ding 0002, Jingang Shi, Jinsong Han
IEEE Trans. Mob. Comput.8
2024 Person-in-WiFi 3D: End-to-End Multi-Person 3D Pose Estimation with Wi-Fi
abstract
Wi-Fi signals, in contrast to cameras, offer privacy protection and occlusion resilience for some practical scenarios such as smart homes, elderly care, and virtual reality. Recent years have seen remarkable progress in the estimation of single-person 2D pose, single-person 3D pose, and multi-person 2D pose. This paper takes a step forward by introducing Person-in- WiFi 3D, a pioneering Wi-Fi system that accomplishes multi-person 3D pose estimation. Person-in- WiFi 3D has two main updates. Firstly, it has a greater number of Wi-Fi devices to enhance the capability for capturing spatial reflections from multiple individuals. Secondly, it leverages the Transformer for end-to-end estimation. Compared to its predecessor, Person-in- WiFi 3D is storage-efficient and fast. We deployed a proof-of-concept system in$4m\times 3.5m$areas and collected a dataset of over 97K frames with seven volunteers. Person-in- WiFi 3D at-tains 3D joint localization errors of 9I.7mm (I-person), I08.Imm (2-person), and I25.3mm (3-person), comparable to cameras and millimeter-wave radars. The project page is at https:/laiotgroup.github.ioIPerson-in-WiFi-3D.
Kangwei Yan, Fei Wang 0037, Han Ding 0002, Jinsong Han
CVPR5
2024 UltraFace: Secure User-friendly Facial Authentication on Smartphones Using Ultrasound
abstract
With a wide range of common and privacy-sensitive applications, smartphones are frequently accessed for substantial personal information. Therefore, user-friendliness and security are crucial for user authentication on smartphones. Recently, convenient and secure biometric-based authentication is widely employed for smartphones, where the facial authentication stands out due to its potential for advancements in both user-friendliness and security. However, existing facial authentication methods possess some defects. For example, camera-based methods require good illumination conditions and are susceptible to 2D spoofing attacks. Moreover, previous acoustic-based methods either require camera assistance, or still suffer from 3D spoofing attacks. Even worse, some acoustic-based methods use audible sound waves, causing discomfort to users. To solve these questions, in this paper we propose UltraFace, an anti-spoofing and user-friendly facial authentication system on smartphones. It extracts facial geometry features and acoustic impedance features from imperceptible ultrasound. Leveraging the principle of ultrasound propagation, UltraFace correlates spectrograms of reflected signals with facial biometrics. Utilizing a deep learning model as a feature extractor, UltraFace mines fine-grained facial geometry features and acoustic impedance features from the spectrograms for accurate user authentication. Extensive experiments show that UltraFace achieves $97.2 \%$ accuracy in user authentication and can effectively defend against spoofing attacks. Furthermore, UltraFace exhibits robustness for long-term usage.
Xinyue Fang, Jianwei Liu 0008, Yike Chen, Jinsong Han
ICPADS4
2024 Talk2Radar: Talking to mmWave Radars via Smartphone Speaker
abstract
Integrated Sensing and Communication (ISAC) is gaining a tremendous amount of attention from both academia and industry. Recent work has brought communication capability to sensing-oriented mmWave radars, enabling more innovative applications. These solutions, however, either require hardware modifications or suffer from limited data rates. This paper presents Talk2Radar, which builds a faster communication channel between smartphone speakers and mmWave radars, without any hardware modification to either commodity smartphones or off-the-shelf radars. In Talk2Radar, a smartphone speaker sends messages by playing carefully designed sounds. A mmWave radar acting as a data receiver captures the emitted sounds by detecting the sound-induced smartphone vibrations, and then decodes the messages. Talk2Radar characterizes smartphone speakers for speaker-to-mmWave radar communication and addresses a series of technical challenges, including modulation and demodulation of extremely weak sound-induced vibrations, multi-speaker concurrent communication and human motion suppression. We implement and evaluate Talk2Radar in various practical settings. Experimental results show that Talk2Radar can achieve a data rate of up to 400bps with an average BER of less than 5%, outperforming the state-of-the-art by approximately 33×.
Kaiyan Cui, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han
INFOCOM5
2024 One is Enough: Enabling One-shot Device-free Gesture Recognition with COTS WiFi
abstract
In recent years, WiFi-based gesture recognition (WGR) has gained popularity due to its privacy-preserving nature and the wide availability of WiFi infrastructure. However, existing WGR systems suffer from scalability issues, i.e., requiring extensive data collection and re-training for each new gesture class. To address these limitations, we propose OneSense, a one-shot WiFi-based gesture recognition system that can efficiently and easily adapt to new gesture classes. Specifically, we first propose a data enrichment approach based on the law of signal propagation in physical world to generate virtual gestures, enhancing the diversity of the training set without extra overhead of real sample collection. Then, we devise an aug-meta learning (AML) framework to enable efficient and scalable few-short learning. This framework leverages two pre-training stages (i.e., aug-training and meta-training) to improve the model’s feature extraction and generalization abilities, and ultimately achieves accurate one-shot gesture recognition through fine-tuning. Experimental results demonstrate that OneSense achieves 93% one-shot gesture recognition accuracy, which outperforms the state-of-the-art approaches. Moreover, it maintains high recognition accuracy when facing new environments, user locations, and user orientations. Furthermore, the proposed AML framework reduces 86%+ pre-training latency compared to conventional meta-learning method.
Leqi Zhao, Rui Xiao 0002, Jianwei Liu 0008, Jinsong Han
INFOCOM4
2024 WristPass: Secure Wearable Continuous Authentication via Ultrasonic Sensing
abstract
Smartwatches have become increasingly prevalent in people’s daily lives, offering support for a wide range of privacy and security-sensitive applications, such as SMS messaging and mobile payment. Consequently, there is an imperative need for independent user authentication on smartwatches to safeguard against property loss and personal privacy breaches. However, current authentication methods rely on passwords, leaving users vulnerable to shoulder surfing attacks. Moreover, existing biometric-based authentication methods either require dedicated sensors or cannot support continuous authentication. In this paper, we propose a replay-resistant continuous authentication system on smartwatches, namely WristPass. It extracts acoustic impedance biometrics from ultrasonic signals. Leveraging a theoretical model based on the principle of ultrasound propagation, WristPass correlates spectrograms of reflected signals with impedance features of wrist skin. Utilizing a deep learning model as a feature extractor, WristPass mines fine-grained impedance features from the spectrograms for accurate user authentication. Additionally, to prevent WristPass from replay attacks, we design a device fingerprinting method to detect replayed signals. Extensive experiments show that WristPass can achieve 96.7% accuracy in user authentication. Furthermore, WristPass exhibits robustness for long-term usage.
Xinyue Fang, Jianwei Liu 0008, Yike Chen, Jinsong Han
IWQoS5
2024 Manipulating Semantic Communication by Adding Adversarial Perturbations to Wireless Channel
abstract
To break through the transmission rate bottleneck of traditional communication, semantic communication is proposed to support emerging applications with extremely low latency requirements such as remote surgery and autonomous vehicle. Unlike the transmission of verbose symbols in traditional communication, mainstream semantic communications use deep learning technology to extract compact semantic information from data and convey it. However, the application of deep neural networks also poses security concerns, i.e., vulnerabilities to adversarial attacks. In this paper, we perform the first study on the security of semantic communication against both whitebox and black-box attacks by compromising the wireless channel between the transmitter and receiver. To launch practical and effective attacks, a systematic and universal attack framework is designed to craft content-agnostic, undetectable, robust whitebox perturbation signals as well as highly-transferable blackbox ones. Extensive experiments on two open-source datasets demonstrate that our attack framework can achieve over 87%, 99%, and 89% success rates in untargeted white-box, targeted white-box, and untargeted black-box attacks. This means that the proposed attack methods could severely threaten the quality of service of current semantic communications. We also propose two mitigation methods to resist such attacks.
Jianwei Liu 0008, Yinghui He, Weiye Xu 0001, Jinsong Han
IWQoS5
2024 Practical Optical Camera Communication Behind Unseen and Complex Backgrounds
abstract
Optical camera communication (OCC) holds potential for location-aware data transfer, facilitating applications such as localization and overlaying digital content for mixed reality experiences. However, existing OCC designs commonly require a clean background for reliable demodulation, rendering its use disruptive and impractical. To this end, we propose WinkLink, a novel OCC system capable of robust transmission behind complex backgrounds, even under low signal-to-noise ratio (SNR) conditions. We address the key challenge of extracting subtle signals in the lossy OCC channel by designing a two-stage deep neural network and a context-aware demodulation protocol. The proposed system is trained solely on a synthesized dataset yet generalizes effectively to unseen real-world backgrounds. Through experiments in 12 diverse environments, we demonstrate that WinkLink successfully transmits OCC signals under a low SNR of -20 dB, achieving a substantial 5.8 dB SNR gain. This low SNR translates to an extended distance to 5.5× of baseline (11m with a 10W LED transmitter) and negligible interference on concurrent vision applications. Finally, WinkLink proves its efficacy even when the device is moving, i.e., dynamic backgrounds, making it ready for deployment on mobile devices.
Rui Xiao 0002, Leqi Zhao, Feng Qian 0006, Lei Yang 0061, Jinsong Han
MobiSys5
2024 FedConv: A Learning-on-Model Paradigm for Heterogeneous Federated Clients
abstract
Federated Learning (FL) facilitates collaborative training of a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., edge servers, smartphones, and wearables) typically have disparate system resources. Conventional FL, however, adopts a one-size-fits-all solution, where a homogeneous large global model is transmitted to and trained on each client, resulting in an overwhelming workload for less capable clients and starvation for other clients. To address this issue, we propose FedConv, a client-friendly FL framework, which minimizes the computation and memory burden on resource-constrained clients by providing heterogeneous customized sub-models. FedConv features a novel learning-on-model paradigm that learns the parameters of the heterogeneous sub-models via convolutional compression. Unlike traditional compression methods, the compressed models in FedConv can be directly trained on clients without decompression. To aggregate the heterogeneous sub-models, we propose transposed convolutional dilation to convert them back to large models with a unified size while retaining personalized information from clients. The compression and dilation processes, transparent to clients, are optimized on the server leveraging a small public dataset. Extensive experiments on six datasets demonstrate that FedConv outperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively).
Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han
MobiSys7
2024 Replay-resistant Disk Fingerprinting via Unintentional Electromagnetic Emanations
abstract
External disks (abbr., disks) are common data storage peripherals for hosts. Verifying the disk’s legitimacy is crucial to prevent security issues on a host like privacy leakage and virus propagation before interaction setup. To address this issue, we propose DiskPrint, a novel non-intrusive and replay-resistant disk authentication system that relies on unintentional electromagnetic (EM) emanations from disks’ internal components. The core idea of DiskPrint is that EM signals emitted during data writing can reflect hardware discrepancies among different disks. Based on electromagnetic principles, we establish a theoretical model associating EM signals with built-in electronic components to demonstrate the feasibility of extracting disk fingerprints from such EM emanations. We also propose a series of signal enhancement methods to remove the EM interface and improve the signal-to-noise ratio (SNR) of the EM measurements. To boost the security of DiskPrint, we propose a device-agnostic replay-resistant method by introducing randomness into leaked EM signals. Real-world experiments with 60 disks including hard disk drives (HDDs) and solid state drives (SSDs) from seven brands and 14 models indicate that DiskPrint achieves a 99%+ authentication success rate. Robustness analysis demonstrates DiskPrint’s stability over time. Security study shows its ability to defend against various attacks.
Wenfan Song, Jianwei Liu 0008, Jinsong Han
RAID4
2024 Eternity in a Second: Quick-pass Continuous Authentication Using Out-ear Microphones
abstract
Continuous authentication is increasingly critical for cyber security. However, existing approaches are time-inefficient due to their simple signal modulation with low-effective feature extraction throughput. In this paper, we propose a continuous authentication technique, OnePiece. OnePiece is free from the requirement of in-ear microphones, which are necessary for existing earphone authentication systems. It exploits out-ear microphones for biometrics extraction, which are ubiquitous on off-the-shelf earphones. We analyze the acoustic response model of ears towards out-ear microphones via the air, which is different from that towards in-ear microphones. A frequency-varying ultrasonic modulation scheme is proposed to characterize in-depth ear biometrics in user-friendly, error-free, and time-efficient ways. Therefore, OnePiece enables quick-pass authentication once users wear the earphones, followed by continuous authentication covering the whole course. Moreover, we propose a wake-up mechanism to reduce the consumed power, which addresses the key power consumption issue in ultrasonic sensing techniques. Particularly, OnePiece can be smoothly deployed on off-the-shelf wired and wireless earphones. It performs good cross-device performance in which users just register only once. Extensive evaluations are conducted to validate its effectiveness under real-world scenarios.
Ming Gao 0023, Jiatong Chen, Yike Chen, Fu Xiao 0001, Jinsong Han
SenSys6
2024 A Location Correlation Differential Privacy Extension Scheme Based on User Spatiotemporal Characteristics
abstract
With the popularity of mobile terminals with GPS functions, location-based services are widely used, and all kinds of user information attached to the location are facing the risk of disclosure, and privacy protection is being challenged. In current researches, it is usually assumed that the locations of different users are independent of each other. However, in real world, the locations of different users have some certain internal correlation. Even if the locations of a single user are well protected, attackers can still mine user privacy through the correlation analysis of locations. To solve the above problems, this article proposes a multiuser location-correlated differential privacy extension scheme under strict privacy budget. In this scheme, we first extract the user spatiotemporal characteristics by mining the stay points and stay areas from trajectories based on locations with timestamps, and then, we calculate the correlation degree among users using the Jaccard correlation coefficient according to the spatiotemporal characteristics, and further, we realize the adaptive differential privacy protection of different users by introducing the concept of individual correlation sensitivity, and finally, we design the differential privacy extension method to protect sensitive locations in the stay areas. Experimental results show that, compared with the existing methods, our proposed scheme not only can improve the usability of the trajectories after privacy protection, but also can enhance the privacy protection of the sensitive locations in the stay areas.
Ruowei Gui, Xingjun Zhang, Xiaolin Gui, Jinsong Han
IEEE Internet Things J.4
2024 U-Shape Networks Are Unified Backbones for Human Action Understanding From Wi-Fi Signals
abstract
Wi-Fi is well-known in communication and deployment for indoor localization. Recently, Wi-Fi has been exploited for human action understanding, e.g., elder fall detection, smoking detection, and hand-gesture recognition. Many researchers have made great efforts to associate their own expertise on Wi-Fi signals with deep networks like convolutional neural networks, recurrent neural networks, and Transformers for representation learning, and demonstrate that expertise can promote action understanding accuracy. However, expert knowledge always relies on the existing personal understanding and assumptions of Wi-Fi signals, which limits the scalability of associated models and may introduce subjective bias to the models. Besides, requiring expertise raises an inescapable barrier and cost to the model design. Recent years have witnessed the great value of backbone networks, such as ResNet, in advancing the research progress in computer vision. We believe a backbone network for Wi-Fi signals will also play a crucial role. In this article, instead of proposing novel algorithms with expertise, we present that simple U-shape deep networks, such as FCN, U-Net, and U-Net++, are efficient and unified backbones for Wi-Fi-based human action understanding tasks, i.e., action recognition, action detection, and action segmentation. Results on three public data sets, Wi-Fi activity recognition, action recognition and indoor localization, and human-to-human interaction, show that all these U-shape deep networks have superior or competitive performance compared with original papers as well as state-of-the-art approaches, e.g., >97% recognition accuracy,90% segmentation accuracy. We envision this work breaks the barrier of network design and facilitates human action understanding from Wi-Fi signals.
Fei Wang 0037, Yiao Gao, Han Ding 0002, Jingang Shi, Jinsong Han
IEEE Internet Things J.6
2024 Forward-Compatible Integrated Sensing and Communication for WiFi
abstract
Given the fact that WiFi-based sensing can be realized through the reuse of WiFi communication facilities and frequency bands, integrated sensing and communication (ISAC) emerges as a pivotal direction for future WiFi standards, such as IEEE 802.11bf. Traditional WiFi sensing systems extract channel state information (CSI) from exclusive WiFi packets to quantify the characteristics of the sensing target. This poses challenges for existing WiFi systems originally designed for communication purposes, as it demands high-quality and sufficient CSI measurements. In this paper, we propose SenCom as a step towards forward-compatible ISAC solution. SenCom extracts CSI from general WiFi packets, enabling CSI calibration across different WiFi communication modes and delivering quality CSI measurements for upper-layer sensing applications. A fitting-resampling scheme and an incentive strategy are also developed. The former one is to obtain evenly sampled CSI with consistent dimensionality and the latter one is to guarantee sufficient CSI measurements over time. We build a prototype of SenCom and conduct extensive experiments involving 15 participants. The results show that SenCom’s competence for a variety of sensing tasks while making minimal compromises to WiFi communication performance.
Yinghui He, Jianwei Liu 0008, Mo Li 0001, Guanding Yu, Jinsong Han
IEEE J. Sel. Areas Commun.5
2024 Practical EMI Attacks on Smartphones With Users' Commands Cancelled
abstract
Human-machine interactions (HMIs), e.g., touchscreens, are essential for users to interact with mobile devices. They are also beneficial in resisting emerging active attacks, which aim at maliciously controlling mobile devices, e.g., smartphones and tablets. With touchscreen-like HMIs, users can notice and interrupt malicious actions conducted by the attackers timely and perform necessary countermeasures, e.g., tapping the ‘Quit’ button on the touchscreen. However, the effect of HMI-oriented active attacks has not been investigated yet. In this paper, we present a practical attack towards touch-based devices, namely Expelliarmus. It reveals a new attack surface of active attacks for hijacking users’ operations and thus taking full control over victim devices. Expelliarmus neutralizes users’ touch commands by producing a reverse current via electromagnetic interference (EMI). Since the reverse current offsets the current change caused by a touch, the touchscreen detects no current change and thus ignores users’ commands. Besides this basic denial-of-service attack, we also realize a target cancellation attack, which can neutralize target commands, e.g., ‘Quit’ without interference in irrelevant operations. Thus, the active attack can be completely performed without interruption from users, even if they are alerted by the abnormal events. Extensive evaluations demonstrate the effectiveness of Expelliarmus on 29 off-the-shelf devices.
Ming Gao 0023, Fu Xiao 0001, Wentao Guo 0007, Zixin Lin, Jinsong Han
IEEE Trans. Dependable Secur. Comput.6
2024 Time to Think the Security of WiFi-Based Behavior Recognition Systems
abstract
Behavior recognition plays an essential role in numerous behavior-driven applications (e.g., virtual reality and smart home) and even in the security-critical applications (e.g., security surveillance and elder healthcare). Recently, WiFi-based behavior recognition (WBR) technique stands out among many behavior recognition techniques due to its advantages of being non-intrusive, device-free, and ubiquitous. However, existing WBR research mainly focuses on improving the recognition precision, while rarely studying the security aspects. In this article, we reveal that WBR systems are vulnerable to manipulating physical signals. For instance, our observation shows that WiFi signals can be changed by jamming signals. By exploiting the vulnerability, we propose two approaches to generate physically online adversarial samples to perform untargeted attack and targeted attack, respectively. The effectiveness of these attacks are extensively evaluated over four real-world WBR systems. The experiment results show that our attack approaches can achieve 80% and 60% success rates for untargeted attack and targeted attack in physical world, respectively. We also show that our attack approaches can be generalized to other WiFi-based sensing applications, such as user authentication.
Jianwei Liu 0008, Yinghui He, Chaowei Xiao, Jinsong Han, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.4
2024 Privacy Leakage in Wireless Charging
abstract
Wireless charging is becoming an essential power supply pattern for electronic devices. Currently, mainstream smartphones are almost compatible with wireless charging. However, when the charging efficiency is continuously improved, its security challenge still remains open yet overlooked. In this paper, we reveal that severe security flaws exist in the wireless charging procedure of off-the-shelf commodity smartphones. Specifically, we find that an attacker can utilize the electromagnetic induction effect between the wireless charger and the smartphone to detect the activities and operations performed on the smartphone. We term such attack asEM-Surfingside-channel attack and build a theoretical model to show its feasibility. To explore the hazard ofEM-Surfing, we propose a three-module attack method, with which we conduct real-world experiments over three mainstream models of smartphones. The results show that the attacker can achieve over 99%, 96%, 94%, and 97% accuracy when inferring the passcode, keystroke, App information, and speech content, respectively. We also design an App namedSecChargingto prevent smartphones fromEM-Surfingattacks. The defense experiment results demonstrate thatSecChargingcan mitigate the threats posed byEM-Surfingeffectively.
Jianwei Liu 0008, Leqi Zhao, Yusheng Tao, Sideng Hu, Jinsong Han, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.6
2024 Towards ISAC-Empowered mmWave Radars by Capturing Modulated Vibrations
abstract
Integrated Sensing and Communication (ISAC) has emerged as a promising technology for next-generation mobile networks. Towards ISAC, we developmmRipplethat empowers commodity mmWave radars with communication capabilities through smartphone vibrations. InmmRipple, a smartphone (transmitter) sends messages by modulating smartphone vibrations, while a mmWave radar (receiver) receives the messages by detecting and decoding the smartphone vibrations. By doing so, a smartphone user can not only be passively sensed by a mmWave radar, but also actively send messages to the radar without any hardware modifications. Although promising, the data rate ofmmRippleis limited by Morse-style communication. To address this, we presentmmRipple+, which leverages the Pulse Width and Amplitude Modulation (PWAM) technique and suppresses inter-symbol interference to enable faster communication. We prototypemmRippleandmmRipple+on commodity mmWave radars and different types of smartphones. Experimental results show thatmmRippleachieves an average vibration pattern recognition accuracy of 98.60% within a$ 2$m communication range, and 97.74% within$ 3$m. The maximum communication range extends to$ 5$m. Meanwhile,mmRipple+achieves a bit rate of 100 bps with a BER of less than 3%, improving the data rate by 4× overmmRippewith the same symbol duration. This work pioneers smartphone-to-COTS mmWave radar communication via vibrations, unlocking diverse applications.
Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.6
2024 A Resilience Evaluation Framework on Ultrasonic Microphone Jammers
abstract
Covert eavesdropping via microphones has always been a major threat to user privacy. Benefiting from the acoustic non-linearity property, the ultrasonic microphone jammer (UMJ) is effective in resisting this long-standing attack. However, prior UMJ researches underestimate adversary's attacking capability in reality and miss critical metrics for a thorough evaluation. The strong assumptions of adversary unable to retrieve information under low word recognition rate, and adversary's weak denoising abilities in the threat model make these works overlook the vulnerability of existing UMJs. As a result, their UMJs' resilience is overestimated. In this paper, we refine the adversary model and completely investigate potential eavesdropping threats. Correspondingly, we define a total of 12 metrics that are necessary for evaluating UMJs' resilience. Using these metrics, we propose a comprehensive framework to quantify UMJs' practical resilience. It fully covers three perspectives that prior works ignored to some degree, i.e., ambient information, semantic comprehension, and collaborative recognition. Guided by this framework, we can thoroughly and quantitatively evaluate the resilience of existing UMJs towards eavesdroppers. Our extensive assessment results reveal that most existing UMJs are vulnerable to sophisticated adverse approaches. We further outline the key factors influencing jammers' performance and present constructive suggestions for UMJs' future designs.
Ming Gao 0023, Yike Chen, Lingfeng Zhang 0004, Jianwei Liu 0008, Li Lu 0008, Feng Lin 0004, Jinsong Han, Kui Ren 0001
IEEE Trans. Mob. Comput.8
2024 Exploring Practical Acoustic Transduction Attacks on Inertial Sensors in MDOF Systems
abstract
In cyber-physical systems, inertial sensors are the basis for identifying motion states and making actuation decisions. However, extensive studies have proved the vulnerability of those sensors under acoustic transduction attacks, which leverage malicious acoustics to trigger sensor measurement errors. Unfortunately, the threat from such attacks is not assessed properly because of the incomplete investigation on the attack's potential, especially towards multiple-degree-of-freedom systems, e.g., drones. To thoroughly explore the threat of acoustic transduction attacks, we revisit the attack model and design a new yet practical acoustic modulation-based attack, named KITE. Such an attack enables stable and controllable injections, even under frequency offset based distortions that limit the effect of prior attacking approaches. KITE exploits the potential threat of transduction attacks without the need of strengthening attackers' abilities. Furthermore, we extend the attack surface to multiple-degree-of-freedom (MDOF) systems, which are more widely deployed but ignored by prior work. Our study also covers the scenario of attacking moving targets. By revealing the practical threat from acoustic transduction attacks, we appeal for both the attention to their harm and necessary countermeasures.
Ming Gao 0023, Lingfeng Zhang 0004, Leming Shen, Jinsong Han, Feng Lin 0004, Kui Ren 0001
IEEE Trans. Mob. Comput.5
2024 UWTracking: Passive Human Tracking Under LOS/NLOS Scenarios Using IR-UWB Radar
abstract
Passive human tracking plays a critical role in the field of ubiquitous sensing, offering customized services such as real-time location tracking for vital sign monitoring and motion detection. Traditional contact-free tracking systems are primarily designed for Line-of-Sight (LOS) scenarios, requiring a direct path between the radio device and the target. However, in Non-Line-of-Sight (NLOS) scenarios, where obstacles obstruct this direct path, these systems suffer from sensing failures and are unable to accurately obtain the motion trajectory of the sensing target. In this paper, we propose the UWTracking system, which utilizes the Commercial Off-the-Shelf (COTS) Impulse Radio-Ultra Wideband (IR-UWB) radars to enable precise indoor passive human tracking in both LOS and NLOS scenarios. To effectively capture the motion information of a moving target in NLOS scenarios, we present the Reconstructed Distributed- Doppler Frequency Shift (RD-DFS) features. We then binarize the RD-DFS features and design the Distance Extraction Algorithm (DEA) to obtain the target's distance in both scenarios. Subsequently, the Circle Intersection Method with Distance Stretching (CIM-DS) algorithm is developed to determine the indoor position of the sensing target, and the Scanning Angle and Velocity Particle Filter (SAV-PF) algorithm facilitates high-precision trajectory tracking. We implement a prototype of UWTracking system and conduct extensive evaluations to showcase its trajectory tracking performance under various scenarios. The results demonstrate that UWTracking achieves effective real-time tracking, with a median tracking error of 17.65 cm in the LOS scenario and 23.34 cm in the NLOS scenario, outperforming the state-of-the-art trajectory tracking systems based on COTS IR-UWB Radars.
Dongzi Wang 0001, Linqing Gui, Biyun Sheng, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.7
2024 Anti-Spoofing Facial Authentication Based on COTS RFID
abstract
Current facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, but they are still vulnerable to feature manipulation, e.g., 3D-printed human faces. In this article, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. Unlike images, RF signals are not perceptible to human eyes, so RFace protects user's privacy. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between facial features and RF signals. To enhance the security of RFace, we specify the tag reading order for each authentication to defend against the signal replay attack. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7$\%$and an EER of 4.4$\%$. More importantly, no replay attack or spoofing attack succeeds in deceiving RFace in the experiments.
Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Fu Xiao 0001, Jinsong Han
IEEE Trans. Mob. Comput.7
2024 Exploring Polarization in Hybrid Modulation for LED-Camera Communication
abstract
With the popularity of LED infrastructure and the camera on smartphone, LED-Camera visible light communication (VLC) has become a realistic and promising technology. However, the existing LED-Camera VLC has limited throughput due to the sampling manner of camera. In this paper, by introducing a polarization dimension, we propose a hybrid modulation scheme with LED and polarization signals to boost throughput. Nevertheless, directly mixing LED and polarized signals may suffer from channel conflict. We exploit well-designed packet structure and Symmetric Return-to-Zero Inverted (SRZI) coding to overcome the conflict. In addition, in the demodulation of hybrid signal, we alleviate the noise of polarization on the LED signals by the polarization background subtraction. We further propose a pixel-free approach to correct the perspective distortion caused by the shift of view angle by adding polarizers around the liquid crystal array. We build a prototype of this hybrid modulation scheme using off-the-shelf optical components. We enhance the basic version (Zou et al. 2023) of preliminary work by analyzing the performance with FSK modulation. Extensive experimental results demonstrate that the hybrid modulation scheme can achieve reliable communication, achieving 13.4 kbps throughput, which is 400$\%$of the existing state-of-the-art LED-Camera VLC.
Jianwei Liu 0008, Jinsong Han, Zhi Wang 0002
IEEE Trans. Mob. Comput.3
2024 An Imperceptible Eavesdropping Attack on WiFi Sensing Systems
abstract
Recent years have witnessed enormous research efforts on WiFi sensing to enable intelligent services of Internet of Things. However, due to the omni-directional broadcasting manner of WiFi signals, the activity semantic underlying the signals can be leaked to adversaries for surveillance, as demonstrated by our previous work. In this paper, we further extend the attack capability ofActListenerto impersonation attack, which could eavesdrop on users’ behavioral uniqueness imperceptibly using a WiFi infrastructure in any location of user sensing area. In particular,ActListener detects each human activityand converts the eavesdropped signals to that by legitimate devices based on our proposed signal propagation models. To extract noise-resilient individual behavioral uniqueness from converted CSI of WiFi signals, we further add user identification models into the substitute model set for training the signal pattern calibration generative model. Experimental results demonstrate thatActListenercould achieve over 80% accuracy in activity semantics retrieval and impersonation by using the converted signals.
Li Lu 0008, Meng Chen 0011, Jiadi Yu, Zhongjie Ba, Feng Lin 0004, Jinsong Han, Yanmin Zhu 0006, Kui Ren 0001
IEEE/ACM Trans. Netw.6
2024 TomFi: Small Object Tracking Using Commodity WiFi
abstract
Rodent infestation has always been one of the most severe threats to humans, which to solve consumes massive manpower and resources. People usually use traps or poisons to treat rat infestation. Such passive countermeasures are inefficient. Damage often occurs when the rats are finally trapped or killed, not to mention the potential risk to injure humans or cause pollution. In this article, we propose a WiFi-based active small object tracking system named TomFi . The core components of TomFi include several deep learning techniques that bridge rat locations/motions and WiFi signal variations (represented by the channel state information). TomFi first employs a detection model to detect the appearance of the rat and then localize it based on a two-branch localization model. Through the design of the two-branch localization model, to our best knowledge, we are the first to solve the information loss and distortion problem. We conducted extensive experiments in both the laboratory environment and real-world kitchen scenarios. The results show that TomFi can achieve a detection success rate of 99%+ and a centimeter-level localization accuracy in real time.
Hongzhe Xu, Jianwei Liu 0008, Jinsong Han
ACM Trans. Sens. Networks4
2023 Nowhere to Hide: Detecting Live Video Forgery via Vision-WiFi Silhouette Correspondence
Xinyue Fang, Jianwei Liu 0008, Yike Chen, Jinsong Han, Kui Ren 0001, Gang Chen 0001
INFOCOM4
2023 Expelliarmus: Command Cancellation Attacks on Smartphones using Electromagnetic Interference
abstract
Human-machine interactions (HMIs), e.g., touchscreens, are essential for users to interact with mobile devices. They are also beneficial in resisting emerging active attacks, which aim at maliciously controlling mobile devices, e.g., smartphones and tablets. With touchscreen-like HMIs, users can notice and interrupt malicious actions conducted by the attackers timely and perform necessary countermeasures, e.g., tapping the ‘Quit’ button on the touchscreen. However, the effect of HMI-oriented active attacks has not been investigated yet. In this paper, we present a practical attack towards touch-based devices, namely Expelliarmus. It reveals a new attack surface of active attacks for hijacking users’ operations and thus taking full control over victim devices. Expelliarmus neutralizes users’ touch commands by producing a reverse current via electromagnetic interference (EMI). Since the reverse current offsets the current change caused by a touch, the touchscreen detects no current change and thus ignores users’ commands. Besides this basic denial-of-service attack, we also realize a target cancellation attack, which can neutralize target commands, e.g., ‘Quit’ without interference in irrelevant operations. Thus, the active attack can be completely performed without interruption from users, even if they are alerted by the abnormal events. Extensive evaluations demonstrate the effectiveness of Expelliarmus on 29 off-the-shelf devices.
Ming Gao 0023, Fu Xiao 0001, Wentao Guo 0007, Yangtao Huang, Jinsong Han
INFOCOM7
2023 Breaking the Throughput Limit of LED-Camera Communication via Superposed Polarization
abstract
With the popularity of LED infrastructure and the camera on smartphone, LED-Camera visible light communication (VLC) has become a realistic and promising technology. However, the existing LED-Camera VLC has limited throughput due to the sampling manner of camera. In this paper, by introducing a polarization dimension, we propose a hybrid modulation scheme with LED and polarization signals to boost throughput. Nevertheless, directly mixing LED and polarized signals may suffer from channel conflict. We exploit well-designed packet structure and Symmetric Return-to-Zero Inverted (SRZI) coding to overcome the conflict. In addition, in the demodulation of hybrid signal, we alleviate the noise caused by polarization on the LED signals by polarization background subtraction. We further propose a pixel-free approach to correct the perspective distortion caused by the shift of view angle by adding polarizers around the liquid crystal array. We build a prototype of this hybrid modulation scheme using off-the-shelf optical components. Extensive experimental results demonstrate that the hybrid modulation scheme can achieve reliable communication, achieving 13.4 kbps throughput, which is 400 % of the existing state-of-the-art LED-Camera VLC.
Jianwei Liu 0008, Jinsong Han
INFOCOM3
2023 mmRipple: Communicating with mmWave Radars through Smartphone Vibration
abstract
This paper presents the design and implementation of mmRipple, which empowers commodity mmWave radars with the communication capability through smartphone vibrations. In mmRipple, a smartphone (transmitter) sends messages by modulating smartphone vibrations, while a mmWave radar (receiver) receives the messages by detecting and decoding the smartphone vibrations with mmWave signals. By doing so, a smartphone user can not only be passively sensed by a mmWave radar, but also actively send messages to the radar using her smartphone without any hardware modifications to either the smartphone or the mmWave radar. mmRipple addresses a series of unique technical challenges, including vibration signal generation, tiny vibration sensing, multiple object separation, and movement interference mitigation. We implement and evaluate mmRipple using commodity mmWave radars and smartphones in different practical conditions. Experimental results show that mmRipple achieves an average vibration pattern recognition accuracy of 98.60% within a 2m communication range, and 97.74% within 3m on 11 different types of smartphones. The communication range can be further extended up to 5m with an accuracy of 91.67% with line-of-sight path. To our best knowledge, mmRipple is the first work that allows smartphones to send data to COTS mmWave radars via smartphone vibrations and will enable many new applications such as vibration-based near field communication and pedestrian-to-sensing-infrastructure communication.
Kaiyan Cui, Qiang Yang 0018, Yuanqing Zheng, Jinsong Han
IPSN4
2023 WiHunter: Enabling Real-time Small Object Detection via Wireless Sensing
abstract
Rodent infestation is a great danger to human society, continuously threatening food safety and inducing disease spread. Existing methods to deal with rodent infestation are mainly based on passive bait traps and poisoning. These methods lack timeliness and effectiveness due to the missing of real-time detection. In this paper, we develop WiHunter, a new wireless sensing system to discover small objects (e.g., rat). Our idea is to exploit reflection signal effect of wireless channels induced by the movement of small objects around the receiver antenna. However, existing wireless sensing works usually employ customized or costly device-dependency Network Interface Cards(NIC), which are impractical to be densely deployed in reality. We implement WiHunter with several CSI-enabled standalone IoT nodes. We show how such devices enable moving small object detection via WiFi signal. The rationale behind this is 1) thanks to the widespread deployments of WiFi infrastructures and IoT devices, the WiFi signal covers almost every location of the corner, 2) the signal amplitude of each device is related to the small object near the receiver antenna. This ability gives us the opportunity to sense object as small as a rat. We implement WiHunter with ESP32 microcontroller on Espressif IoT Development Framework (both of them are cheap commodity off-the-shelf (COTS) devices) and design a practical small object intrusion detection system. Comprehensive and real-world experiments demonstrate that our system is effective in detecting the presence of small objects with an average accuracy of 92.1%.
Jianwei Liu 0008, Jinsong Han, Wei Xi 0003, Zhi Wang 0002
IWQoS3
2023 MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage Signals
abstract
GPU cryptojacking is an attack that hijacks GPU resources of victims for cryptocurrency mining. Such attack is becoming an emerging threat to both local hosts and cloud platforms. These attacks result in huge economic losses for the victims due to significant power consumption by cryptomining applications. Unfortunately, there are no adequate solutions to detect such attacks. In this paper, we propose MagTracer, a novel GPU cryptojacking detection system that leverages magnetic leakage signals emanating from GPUs. We make a key observation that GPUs emanate a distinct magnetic signal while mining, which can be attributed to the core feature of all cryptomining algorithms (as they are compute-intensive as well as memory-bounded). We design and implement a proof-of-concept detection system to demonstrate MagTracer's feasibility. We evaluate MagTracer on 14 heterogeneous GPU models and achieve a high average true positive rate of over 98% and a low false positive rate below 0.7% in all cases. Furthermore, our comprehensive evaluation confirms that MagTracer is scalable across different mining applications and robust against several targeted attacks.
Rui Xiao 0002, Soundarya Ramesh, Jun Han 0001, Jinsong Han
MobiCom5
2023 Cancelling Speech Signals for Speech Privacy Protection against Microphone Eavesdropping
abstract
Ultrasonic microphone jammers protect speech privacy from being eavesdropped by leveraging microphones' non-linearity. However, existing jammers merely introduce independent noises and are vulnerable to capable adversaries who adopt advanced denoising techniques. We propose a novel jammer, namely MicFrozen. It reduces the signal-to-noise ratio (SNR) at the adversary's microphone from two perspectives, i.e., cancelling speech signals and adding noises that are difficult to be removed. It effectively cancels out the protected speech signals at the adversary without compromising the delivery of the signal to the targeted individual. MicFrozen further adds coherent noises that are coupled with the speech signals to resist removal by the adversary. Extensive evaluations show that MicFrozen can cause a low SNR (-13.6 dB) at the adversary and up to 96.9% of speech signals are unrecognized at the adversary even if state-of-the-art denoising techniques are adopted by the adversary. Comprehensive experiments demonstrate the effectiveness of MicFrozen confronted by capable adversaries.
Ming Gao 0023, Yike Chen, Jie Xiong 0001, Jinsong Han, Kui Ren 0001
MobiCom5
2023 SenCom: Integrated Sensing and Communication with Practical WiFi
abstract
Given the fact that WiFi-based sensing can be realized by reusing WiFi communication facilities and communication frequency bands, integrated sensing and communication (ISAC) is considered a crucial development direction for future WiFi standards, such as IEEE 802.11bf. Traditional WiFi sensing systems extract channel state information (CSI) from customized WiFi packets to quantify the characteristics of the sensing target. This poses challenges for existing WiFi systems originally designed for communication purposes, as it requires high-quality and sufficient CSI measurements. In this paper, we propose SenCom, which extracts CSI from general WiFi packets. SenCom enables CSI calibration across different WiFi communication modes and provides unified CSI measurements for upper-layer sensing applications. We also devise a fitting-resampling scheme to derive evenly sampled CSI with consistent dimensionality, and an incentive strategy to ensure sufficient CSI measurements over time. We build a prototype of SenCom and perform extensive experiments with 15 participants. The results show that SenCom is competent for a variety of sensing tasks, while incurring little compromise to the WiFi communication performance.
Yinghui He, Jianwei Liu 0008, Mo Li 0001, Guanding Yu, Jinsong Han, Kui Ren 0001
MobiCom5
2023 μMote: Enabling Passive Chirp De-spreading and μW-level Long-Range Downlink for Backscatter Devices
Yihang Song, Li Lu 0001, Jiliang Wang, Chong Zhang 0017, Jinsong Han
NSDI7
2023 Device-Independent Smartphone Eavesdropping Jointly Using Accelerometer and Gyroscope
abstract
Eavesdropping via inertial measurement units (IMUs) has brought growing concerns over smartphone users’ privacy. In such attacks, adversaries utilize IMUs, including accelerometers and gyroscopes, which require zero permissions for access to acquire speeches. A common countermeasure is to limit sampling rates (within 200 Hz) to reduce overlap of vocal fundamental bands (85$\sim$255 Hz) and inertial measurements (0$\sim$100 Hz). Nevertheless, we observe that IMUs sampling below 200 Hz still record adequate speech-related information because of aliasing distortions. Accordingly, we propose a practical side-channel attack, namelyInertiEAR, to break the defense of sampling rate restriction on the zero-permission eavesdropping. It leverages accelerometers and gyroscopes jointly to eavesdrop on both top and bottom speakers in smartphones. We exploit coherence between responses of the built-in accelerometer and gyroscope using a mathematical model. The coherence allows precise segmentation without manual assistance. We also mitigate the impact of hardware diversity and achieve better device-independent performance than existing approaches that have to massively increase training data from different smartphones for a scalable network model. These two advantages re-enable zero-permission attacks but also extend the attacking surface and endangering degree to off-the-shelf smartphones.InertiEARachieves the recognition accuracy of 78.8% with the cross-device accuracy of up to 60.9% among 12 smartphones.
Ming Gao 0023, Yike Chen, Zhongjie Ba, Jinsong Han, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.7
2023 Behavior Privacy Preserving in RF Sensing
abstract
Recent years have witnessed the booming development of RF sensing, which supports both identity authentication and behavior recognition by analysing the signal distortion caused by human body. In particular, RF-based identity authentication is more attractive to researchers, because it can capture the unique biological characteristics of users. However, the openness of wireless transmission raises privacy concerns since human behaviors could expose massive private information of users, which impedes the real-world implementation of RF-based user authentication applications. It is difficult to filter out the behavior information from the collected RF signals. In this article, we propose a privacy-preserving deep neural network namedBPCloakto erase the behavior information in RF signals while retaining the ability of user authentication. We conduct extensive experiments over mainstream RF signals collected from three real wireless systems, including the WiFi, radio frequency identification (RFID), and millimeter-wave (mmWave) systems. The experimental results show thatBPCloaksignificantly reduces the behavior recognition accuracy, i.e., 85%+, 75%+, and 65%+ reduction for WiFi, RFID, and mmWave systems respectively, merely with a slight penalty of accuracy decrease when using these three systems for user authentication, i.e., 1%-, 3%-, and 5%-, respectively.
Jianwei Liu 0008, Chaowei Xiao, Kaiyan Cui, Jinsong Han, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.4
2023 ShakeReader: 'Read' UHF RFID Using Smartphone
abstract
UHF RFID technology becomes increasingly popular in stores, since it can quickly read a large number of RFID tags from afar. The deployed RFID infrastructure, however, does not directly benefit smartphone users in stores, mainly because smartphones cannot read UHF RFID tags or fetch relevant information. This paper aims to bridge the gap and allow users to 'read' UHF RFID tags using their smartphones, without any hardware modification to either deployed RFID systems or smartphone hardware. To ‘read’ an interested tag, a user makes a pre-defined smartphone gesture in front of an interested tag. The smartphone gesture causes changes in 1) RFID measurement data captured by RFID infrastructure, and 2) motion sensor data captured by the user's smartphone. By matching the two data, our system (named ShakeReader) can pair the interested tag with the corresponding smartphone, thereby enabling the smartphone to indirectly 'read' the interested tag. We build a novel reflector polarization model to analyze the impact of smartphone gesture to RFID backscattered signals. We enhance the basic version of ShakeReader [6] by improving its performance in densely deployed scenarios. Experimental results show that ShakeReader can accurately pair interested tags with their corresponding smartphones with an accuracy of >96.3%.
Kaiyan Cui, Yanwen Wang 0001, Yuanqing Zheng, Jinsong Han
IEEE Trans. Mob. Comput.4
2023 Secure User Verification and Continuous Authentication via Earphone IMU
abstract
Biometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods or inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namelyMandiPass.MandiPassleverages inertial measurement units, which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. It provides not only one-time verification function but also continuous authentication function. Both the two functions are secure and user-friendly. We theoretically validate the feasibility ofMandiPassand develop a series of deep learning techniques for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show thatMandiPasscan achieve low equal error rate, even under various harsh environments.
Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001
IEEE Trans. Mob. Comput.4
2023 Mobile Communication Among COTS IoT Devices via a Resonant Gyroscope With Ultrasound
abstract
Incompatible protocols and electromagnetic interference obstruct the realization of an everything-connected Internet of Things (IoT) communication network. Our system, Deaf-Aid, utilizes a stealthy speaker-to-gyroscope channel to build robust communication. Compared with existing solutions adopting physical covert channels, Deaf-Aid is free from the limitations of manual receiver distinction, additional hardware, conditional placement, or physical contact. It exploits ultrasounds to force gyroscopes embedded in receivers to resonate, so as to convey information. We investigate the relationship among axes in a gyroscope to deal with frequency offset and support multi-channel communication. Meanwhile, receivers are identified automatically via device fingerprints consisting of diversity of gyroscopes’ resonant frequency ranges. Furthermore, we enable Deaf-Aid the capability of mobile communication, which is an essential demand for IoT devices. We address the challenge of recovering accurate signals from motion interference. Extensive evaluations, including that on the commercial off-the-shelf devices, demonstrate that Deaf-Aid yields 47 bps with BER below 1%. To our best knowledge, Deaf-Aid is the first work to enable stealthy mobile IoT communication based on inertial sensors.
Feng Lin 0004, Ming Gao 0023, Lingfeng Zhang 0004, Weiye Xu 0001, Jinsong Han, Wenyao Xu, Kui Ren 0001
IEEE/ACM Trans. Netw.6
2023 Reliable Multi-Factor User Authentication With One Single Finger Swipe
abstract
Multi-factor user authentication becomes increasingly popular due to its superior security comparing with single-factor user authentication. However, existing multi-factor user authentication methods usually require multiple interactions between users and different authentication components when inputting the multiple factors, leading to extra overhead and bad user experience. In this paper, we propose a secure and user-friendly multi-factor user authentication system named BioDraw. It utilizes four categories of biometrics (impedance, geometry, behavior, and composition) of human hand plus the pattern-based password to identify and authenticate users. User only needs to draw a pattern on a radio frequency identification tag array, while four biometrics can be collected simultaneously. Specifically, we first design a gradient-based pattern recognition algorithm to precisely extract user’s secret pattern. Then, a convolutional neural network- and long short-term memory-based classifier is utilized for user recognition. Furthermore, to guarantee the systemic security, an anti-replay method called Binary ALOHA is proposed to detect replayed signals. We conduct extensive experiments with 30 volunteers. The experiment results show that BioDraw can achieve high authentication accuracy (with a 2%– false reject rate) and is effective in defending against various attacks.
Jianwei Liu 0008, Kaiyan Cui, Jinsong Han, Feng Lin 0004, Kui Ren 0001
IEEE/ACM Trans. Netw.4
2023 A Generalized Method to Combat Multipaths for RFID Sensing
abstract
There have been increasing interests in exploring the sensing capabilities of RFID to enable numerous IoT applications, including object localization, trajectory tracking, and human behavior sensing. However, most existing methods rely on the signal measurement either in a low multipath environment, which is unlikely to exist in many practical situations, or with special devices, which increase the operating cost. This paper investigates the possibility of measuring ‘multi-path-free’ signal information in multipath-prevalent environments simply using a commodity RFID reader. The proposed solution, Clean Physical Information Extraction (CPIX), is universal, accurate, and compatible to standard protocols and devices. CPIX improves RFID sensing quality with near zero cost – it requires no extra device. We implement CPIX and study three major RFID sensing applications: tag localization, device calibration and human behavior sensing. CPIX reduces the localization error by 30% to 50% and achieves the MOST accurate localization by commodity readers compared to existing work. It also significantly improves the quality of device calibration and human behaviour sensing.
Ge Wang 0003, Haofan Cai, Chen Qian 0001, Han Ding 0002, Wei Xi 0003, Kun Zhao 0002, Jizhong Zhao, Jinsong Han
IEEE/ACM Trans. Netw.9
2022 ActListener: Imperceptible Activity Surveillance by Pervasive Wireless Infrastructures
abstract
Recent years have witnessed enormous research efforts on WiFi sensing to enable intelligent services of Internet of Things. However, due to the omni-directional broadcasting manner of WiFi signals, the activity semantic underlying the signals is leaked to adversaries for surveillance in all probability. To reveal the threat, this paper demonstrates ActListener, which could eavesdrop on user activities imperceptibly using a WiFi infrastructure in any location of user sensing area. The proposed attack requires no direct physical access to the victim user’s devices and prior knowledge of activity recognition model details and device locations. In particular, ActListener first detects the signal segment induced by each human activity, and estimates the locations of legitimate devices and the victim users relative to the adversary’s device for further signal modeling. Then, ActListener models propagating WiFi signals to construct the relationship between physical locations and received signals, and converts the eavesdropped signals to that by legitimate devices based on the models. Furthermore, a neural network-based generative model is designed to calibrate the converted signals for resisting noises in over-the-air WiFi signals. Experiments show ActListener achieves 88.4% average α-similarity on recovering originally signals from eavesdropped ones, and over 90% accuracy in activity recognition.
Li Lu 0008, Zhongjie Ba, Feng Lin 0004, Jinsong Han, Kui Ren 0001
ICDCS4
2022 Big Brother is Listening: An Evaluation Framework on Ultrasonic Microphone Jammers
abstract
Covert eavesdropping via microphones has always been a major threat to user privacy. Benefiting from the acoustic non-linearity property, the ultrasonic microphone jammer (UMJ) is effective in resisting this long-standing attack. However, prior UMJ researches underestimate adversary’s attacking capability in reality and miss critical metrics for a thorough evaluation. The strong assumptions of adversary unable to retrieve information under low word recognition rate, and adversary’s weak denoising abilities in the threat model make these works overlook the vulnerability of existing UMJs. As a result, their UMJs’ resilience is overestimated. In this paper, we refine the adversary model and completely investigate potential eavesdropping threats. Correspondingly, we define a total of 12 metrics that are necessary for evaluating UMJs’ resilience. Using these metrics, we propose a comprehensive framework to quantify UMJs’ practical resilience. It fully covers three perspectives that prior works ignored in some degree, i.e., ambient information, semantic comprehension, and collaborative recognition. Guided by this framework, we can thoroughly and quantitatively evaluate the resilience of existing UMJs towards eavesdroppers. Our extensive assessment results reveal that most existing UMJs are vulnerable to sophisticated adverse approaches. We further outline the key factors influencing jammers’ performance and present constructive suggestions for UMJs’ future designs.
Yike Chen, Ming Gao 0023, Lingfeng Zhang 0004, Li Lu 0008, Feng Lin 0004, Jinsong Han, Kui Ren 0001
INFOCOM7
2022 InertiEAR: Automatic and Device-independent IMU-based Eavesdropping on Smartphones
abstract
IMU-based eavesdropping has brought growing concerns over smartphone users’ privacy. In such attacks, adversaries utilize IMUs that require zero permissions for access to acquire speeches. A common countermeasure is to limit sampling rates (within 200 Hz) to reduce overlap of vocal fundamental bands (85-255 Hz) and inertial measurements (0-100 Hz). Nevertheless, we experimentally observe that IMUs sampling below 200 Hz still record adequate speech-related information because of aliasing distortions. Accordingly, we propose a practical side-channel attack, InertiEAR, to break the defense of sampling rate restriction on the zero-permission eavesdropping. It leverages IMUs to eavesdrop on both top and bottom speakers in smartphones. In the InertiEAR design, we exploit coherence between responses of the built-in accelerometer and gyroscope and their hardware diversity using a mathematical model. The coherence allows precise segmentation without manual assistance. We also mitigate the impact of hardware diversity and achieve better device-independent performance than existing approaches that have to massively increase training data from different smartphones for a scalable network model. These two advantages re-enable zero-permission attacks but also extend the attacking surface and endangering degree to off-the-shelf smartphones. InertiEAR achieves a recognition accuracy of 78.8% with a cross-device accuracy of up to 49.8% among 12 smartphones.
Ming Gao 0023, Yike Chen, Zhongjie Ba, Jinsong Han
INFOCOM7
2022 Physical-World Attack towards WiFi-based Behavior Recognition
abstract
Behavior recognition plays an essential role in numerous behavior-driven applications (e.g., virtual reality and smart home) and even in the security-critical applications (e.g., security surveillance and elder healthcare). Recently, WiFi-based behavior recognition (WBR) technique stands out among many behavior recognition techniques due to its advantages of being non-intrusive, device-free, and ubiquitous. However, existing WBR research mainly focuses on improving the recognition precision, while neglecting the security aspects. In this paper, we reveal that WBR systems are vulnerable to manipulating physical signals. For instance, our observation shows that WiFi signals can be changed by jamming signals. By exploiting the vulnerability, we propose two approaches to generate physically online adversarial samples to perform untargeted attack and targeted attack, respectively. The effectiveness of these attacks are extensively evaluated over four real-world WBR systems. The experiment results show that our attack approaches can achieve 80% and 60% success rates for untargeted attack and targeted attack in physical world, respectively. We also propose three methods to mitigate the hazard of such attacks.
Jianwei Liu 0008, Yinghui He, Chaowei Xiao, Jinsong Han, Kui Ren 0001
INFOCOM4
2022 Mask does not matter: anti-spoofing face authentication using mmWave without on-site registration
abstract
Face authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and hence susceptible to face occlusion (e.g., facial masks) and vulnerable to spoofing attacks (e.g., 3D-printed masks). This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans the human face by moving a commodity off-the-shelf (COTS) mmWave radar along a specific trajectory. The mmWave signals bounced off the human face carry the facial biometric features and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well even if users wear masks. We explore a distance-resistant facial structure feature to suppress the impact of unstable face-to-device distance. To avoid inconvenient on-site registration, we also propose a novel virtual registration approach based on the core idea of cross-modal transformation from photos to mmWave signals. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments show that mmFace can realize accurate FA as well as reliable liveness detection.
Weiye Xu 0001, Wenfan Song, Jianwei Liu 0008, Yuanqing Zheng, Jinsong Han, Xinhuai Wang, Kui Ren 0001
MobiCom7
2022 FakeGuard: Exploring Haptic Response to Mitigate the Vulnerability in Commercial Fingerprint Anti-Spoofing
Aditya Singh Rathore, Yijie Shen, Chenhan Xu, Jacob Snyderman, Jinsong Han, Fan Zhang 0010, Zhengxiong Li, Feng Lin 0004, Wenyao Xu, Kui Ren 0001
NDSS5
2022 ChopTags: An Accurate and Low-cost Interface to Identify User/Item Interactions
abstract
Identifying item-item and user-item interactions is an essential requirement of many ubiquitous computing applications. Recently methods of physically altering RFID tag hardware have been proposed to enable recognizing certain interactions. However, they do not address the problem that when a large number of tags exist in the environment and concurrent interactions may happen, the system may not be able to identify these interactions accurately or efficiently. We propose ChopTags, a low-cost and accurate interaction identification using passive RFID tags, with applications including automatic chess notation, shipment storage tracking, interactive libraries/retail stores/classrooms, and smart conference badges to track the attendees who had conversations. Each ChopTags module contains a passive tag chip and an antenna that are separated and can only be read when the chip is in contact with an antenna (from another pairing ChopTags module). ChopTags costs cheap hardware to scale to many users and items, achieves near 100% accuracy in complex environments, and is easy to use for children, seniors, and others who have difficulty of operating smart devices. We resolve a number of challenges of using ChopTags including improving query throughput/accuracy and identifying concurrent interactions. We build two prototypes based on ChopTags: 1) a chess auto-notation system and 2) a tag array for user interactions. ChopTags allows tracking the moves of 96 tag modules for the chess game with almost 100% accuracy and no prior work can achieve this.
Haofan Cai, Ge Wang 0003, Josue Leyva, Ian Pham, Jinsong Han, Shigang Chen, Chen Qian 0001
SECON5
2022 Integrated Sensing and Communication between Daily Devices and mmWave Radars
abstract
Millimeter wave (mmWave) radar has demonstrated excellent performance in object tracking and micro-displacement detection. Besides the powerful sensing function, this work brings the communication function, allowing daily devices to communicate with mmWave radars through vibrations. In this work, we present VibBeat, in which a daily device (e.g., smartphone and smartwatch) sends messages by modulating vibrations, while a mmWave radar receives the messages by detecting and decoding the vibrations with reflected mmWave signals. By doing so, the device (user) can not only be passively sensed by a mmWave radar, but also actively send messages to the radar for a personalized response. We implement our system using a COTS mmWave radar and smartphones without any hardware modification. Experimental results show that VibBeat supports multiple object communication and achieves a communication range of up to 5m.
Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Jinsong Han
SenSys5
2022 KITE: Exploring the Practical Threat from Acoustic Transduction Attacks on Inertial Sensors
abstract
In cyber-physical systems, inertial sensors are the basis for identifying motion states and making actuation decisions. However, extensive studies have proved the vulnerability of those sensors under acoustic transduction attacks, which leverage malicious acoustics to trigger sensor measurement errors. Unfortunately, the threat from such attacks is not assessed properly because of the incomplete investigation on the attack's potential, especially towards multiple-degree-of-freedom systems, e.g., drones. To thoroughly explore the threat of acoustic transduction attacks, we revisit the attack model and design a new yet practical acoustic modulation-based attack, named KITE. Such an attack enables stable and controllable injections, even under frequency offset based distortions that limit the effect of prior attacking approaches. KITE exploits the potential threat of transduction attacks without the need of strengthening attackers' abilities. Furthermore, we extend the attack surface to multiple-degree-of-freedom systems, which are more widely deployed but ignored by prior work. Our study also covers the scenario of attacking moving targets. By revealing the practical threat from acoustic transduction attacks, we appeal for both the attention to their harm and necessary countermeasures.
Ming Gao 0023, Lingfeng Zhang 0004, Leming Shen, Jinsong Han, Feng Lin 0004, Kui Ren 0001
SenSys5
2022 Arbitrator2.0: Preventing Unauthorized Access on Passive Tags
abstract
As the ultra high frequency (UHF) passive radio frequency identification (RFID) technology becomes increasingly deployed, it faces an array of new security attacks. In this paper, we consider a type of attack in which a malicious RFID reader could arbitrarily access the tags, e.g., retrieve or modify IDs or other data in the memory, via standard commands. To deal with this type of attack, we propose a physical-layer tag protection framework, namely Arbitrator2.0, that involves two operating mode, i.e., one is to passively listen on RF channels and identify unauthorized readers, the other is working as normal reader to access tag information but resilient to one-antenna eavesdropper. Our solution does not need to modify RFID tags or the underlying communication standards. In this study, we have implemented a prototype Arbitrator2.0 over the universal software radio peripheral (USRP) platform, and conducted extensive experiments to evaluate its performance. The results show that Arbitrator2.0 can effectively diminish the unauthorized access attacks and prevent eavesdropping.
Han Ding 0002, Jinsong Han, Cui Zhao, Ge Wang 0003, Wei Xi 0003, Zhiping Jiang, Jizhong Zhao
IEEE Trans. Mob. Comput.2
2022 A Fingertip Profiled RF Identifier
abstract
This paper presents RF-Mehndi, a passive commercial RFID tag array formed identifier. The key RF-Mehndi novelty is that when the user’s fingertip touching on the tag array surface during the communication, the backscattered signals by the tag array become user-dependent and unique. Hence, if we enhance the communication modality of many personal cards nowadays by RF-Mehndi, in case that a card gets lost or stolen, it cannot be used illegally by the adversaries. To harvest such a benefit, we leverage two key observations in designing RF-Mehndi. The first one is when tags are nearby, their interrogated currents can change each other’s circuit characteristics, based on which unique phase features can be obtained from backscattered signals. The second observation is that when the user’s fingertip touches the tag array surface during communication, the phase feature can be further profiled by this user. Based on these observations, the card and its holder can be potentially authenticated at the same time. To transfer the RF-Mehndi idea to a practical system, we further address technical challenges. We implement a prototype system. Extensive evaluations show the effectiveness of RF-Mehndi, achieving excellent authentication performance.
Cui Zhao, Zhenjiang Li 0001, Han Ding 0002, Wei Xi 0003, Ruowei Gui, Jinsong Han
IEEE Trans. Mob. Comput.7
2021 MandiPass: Secure and Usable User Authentication via Earphone IMU
abstract
Biometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods and inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namely MandiPass. MandiPass leverages inertial measurement units (IMU), which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. The authentication merely requires user to voice a short ‘EMM’ for generating the vibration. In this way, MandiPass enables a secure and user-friendly biometric-based authentication. We theoretically validate the feasibility of MandiPass and develop a two-branch deep neural network for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show that MandiPass can achieve an equal error rate of 1.28%, even under various harsh environments.
Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001
ICDCS4
2021 Hand-Key: Leveraging Multiple Hand Biometrics for Attack-Resilient User Authentication Using COTS RFID
abstract
Biometrics have been widely used in user authentications. However, existing outer-body biometrics (e.g., fingerprint), collecting from body surface, are vulnerable to spoofing attacks. Although inner-body biometrics, such as the electrocardiogram, are hard to be forged, their complex acquisition methods and instability lead to unsatisfactory user experience. Therefore, achieving good user-friendliness and high security simultaneously in biometric-based authentication is challenging. In this paper, we propose Hand-Key, an attack-resilient and user-friendly user authentication system to address the above challenge. Hand-Key utilizes a low-cost radio frequency identification (RFID) tag array to simultaneously collect the inner-body composition and outer-body geometric features of human hand to identify users. Users are merely required to hold their hands in a ‘handshaking’ pose between a reader's antenna and a tag array during authentication. To further enhance the security, we tactfully leverage the inherent randomness of the anti-collision scheme in RFID systems to make Hand-Key immune against replay attacks. We built a prototype of Hand-Key and conducted extensive experiments with 30 volunteers. The results show that Hand-Key achieves an authentication success rate of 99%+.
Jianwei Liu 0008, Feng Lin 0004, Jinsong Han, Kui Ren 0001
ICDCS4
2021 ShakeReader: 'Read' UHF RFID using Smartphone
abstract
UHF RFID technology becomes increasingly popular in RFID-enabled stores (e.g., UNIQLO), since UHF RFID readers can quickly read a large number of RFID tags from afar. The deployed RFID infrastructure, however, does not directly benefit smartphone users in the stores, mainly because smartphones cannot read UHF RFID tags or fetch relevant information (e.g., updated price, real-time promotion). This paper aims to bridge the gap and allow users to `read' UHF RFID tags using their smartphones, without any hardware modification to either deployed RFID systems or smartphone hardware. To `read' an interested tag, a user makes a pre-defined smartphone gesture in front of an interested tag. The smartphone gesture causes changes in 1) RFID measurement data (e.g., phase) captured by RFID infrastructure, and 2) motion sensor data (e.g., accelerometer) captured by the user's smartphone. By matching the two data, our system (named ShakeReader) can pair the interested tag with the corresponding smartphone, thereby enabling the smartphone to indirectly `read' the interested UHF tag. We build a novel reflector polarization model to analyze the impact of smartphone gesture to RFID backscattered signals. Experimental results show that ShakeReader can accurately pair interested tags with their corresponding smartphones with an accuracy of >94.6%.
Kaiyan Cui, Yanwen Wang 0001, Yuanqing Zheng, Jinsong Han
INFOCOM4
2021 RFace: Anti-Spoofing Facial Authentication Using COTS RFID
abstract
Current facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, which are still easy to deceive with the feature manipulation, e.g., 3D-printed human faces. In this paper, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. RFace only requires users to pose their faces in front of a tag array for a few seconds, without leaking their visual facial information. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between the facial features and RF signals. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7% and an EER of 4.4%. More importantly, no spoofing attack succeeds in deceiving RFace in the experiments.
Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Jinsong Han, Fu Xiao 0001, Kui Ren 0001
INFOCOM6
2021 A Behavior Privacy Preserving Method towards RF Sensing
abstract
Recent years have witnessed the booming development of RF sensing, which supports both identity authentication and behavior recognition by analysing the signal distortion caused by human body. In particular, RF-based identity authentication is more attractive to researchers, because it can capture the unique biological characteristics of users. However, the openness of wireless transmission raises privacy concerns since human behaviors can expose the massive private information of users, which impedes the real-world implementation of RF-based user authentication applications. Unfortunately, it is difficult to filter out the behavior information from the collected RF signals.In this paper, we propose a privacy-preserving deep neural network named BPCloak to erase the behavior information in RF signals while retaining the ability of user authentication. We conduct extensive experiments over mainstream RF signals collected from three real wireless systems, including the WiFi, Radio Frequency IDentification (RFID), and millimeter-wave (mmWave) systems. The experimental results show that BPCloak significantly reduces the behavior recognition accuracy, i.e., 85%+, 75%+, and 65%+ reduction for WiFi, RFID, and mmWave systems respectively, merely with a slight penalty of accuracy decrease when using these three systems for user authentication, i.e., 1%-, 3%-, and 5%-, respectively.
Jianwei Liu 0008, Chaowei Xiao, Kaiyan Cui, Jinsong Han, Kui Ren 0001, Xufei Mao
IWQoS4
2021 Wavoice: A Noise-resistant Multi-modal Speech Recognition System Fusing mmWave and Audio Signals
abstract
With the advance in automatic speech recognition, voice user interface has gained popularity recently. Since the COVID-19 pandemic, VUI is increasingly preferred in online communication due to its non-contact. Additionally, various ambient noise impedes the public applications of voice user interfaces due to the requirement of audio-only speech recognition methods for a high signal-to-noise ratio. In this paper, we present Wavoice, the first noise-resistant multi-modal speech recognition system that fuses two distinct voice sensing modalities, i.e., millimeter-wave (mmWave) signals and audio signals from a microphone, together. One key contribution is that we model the inherent correlation between mmWave and audio signals. Based on it, Wavoice facilitates the real-time noise-resistant voice activity detection and user targeting from multiple speakers. Furthermore, we elaborate on two novel modules into the neural attention mechanism for multi-modal signals fusion, and result in accurate speech recognition. Extensive experiments verify Wavoice's effectiveness under various conditions with the character recognition error rate below 1% in a range of 7 meters. Wavoice outperforms existing audio-only speech recognition methods with lower character error rate and word error rate. The evaluation in complex scenes validates the robustness of Wavoice.
Tiantian Liu 0002, Ming Gao 0023, Feng Lin 0004, Chao Wang 0097, Zhongjie Ba, Jinsong Han, Wenyao Xu, Kui Ren 0001
SenSys6
2021 OneFi: One-Shot Recognition for Unseen Gesture via COTS WiFi
abstract
WiFi-based Human Gesture Recognition (HGR) becomes increasingly promising for device-free human-computer interaction. However, existing WiFi-based approaches have not been ready for real-world deployment due to the limited scalability, especially for unseen gestures. The reason behind is that when introducing unseen gestures, prior works have to collect a large number of samples and re-train the model. While the recent advance of few-shot learning has brought new opportunities to solve this problem, the overhead has not been effectively reduced. This is because these methods still require enormous data to learn adequate prior knowledge, and their complicated training process intensifies the regular training cost. In this paper, we propose a WiFi-based HGR system, namely OneFi, which can recognize unseen gestures with only one (or few) labeled samples. OneFi fundamentally addresses the challenge of high overhead. On the one hand, OneFi utilizes a virtual gesture generation mechanism such that the massive efforts in prior works can be significantly alleviated in the data collection process. On the other hand, OneFi employs a lightweight one-shot learning framework based on transductive fine-tuning to eliminate model re-training. We additionally design a self-attention based backbone, termed as WiFi Transformer, to minimize the training cost of the proposed framework. We establish a real-world testbed using commodity WiFi devices and perform extensive experiments over it. The evaluation results show that OneFi can recognize unseen gestures with the accuracy of 84.2, 94.2, 95.8, and 98.8% when 1, 3, 5, 7 labeled samples are available, respectively, while the overall training process takes less than two minutes.
Rui Xiao 0002, Jianwei Liu 0008, Jinsong Han, Kui Ren 0001
SenSys3
2021 Implement of a secure selective ultrasonic microphone jammer
Yike Chen, Ming Gao 0023, Jianwei Liu 0008, Jinsong Han
CCF Trans. Pervasive Comput. Interact.7
2021 Corrections to "HMO: Ordering RFID Tags With Static Devices in Mobile Environments"
abstract
Presents corrections to the acknowledgement section for the above named article.
Ge Wang 0003, Chen Qian 0001, Longfei Shangguan, Han Ding 0002, Jinsong Han, Kaiyan Cui, Wei Xi 0003, Jizhong Zhao
IEEE Trans. Mob. Comput.5
2020 A Universal Method to Combat Multipaths for RFID Sensing
abstract
There have been increasing interests in exploring the sensing capabilities of RFID to enable numerous IoT applications, including object localization, trajectory tracking, and human behavior sensing. However, most existing methods rely on the signal measurement either in a low multipath environment, which is unlikely to exist in many practical situations, or with special devices, which increase the operating cost. This paper investigates the possibility of measuring `multi-path-free' signal information in multipath-prevalent environments simply using a commodity RFID reader. The proposed solution, Clean Physical Information Extraction (CPIX), is universal, accurate, and compatible to standard protocols and devices. CPIX improves RFID sensing quality with near zero cost - it requires no extra device. We implement CPIX and study two major RFID sensing applications: tag localization and human behavior sensing. CPIX reduces the localization error by 30% to 50% and achieves the MOST accurate localization by commodity readers compared to existing work. It also significantly improves the quality of human behaviour sensing.
Ge Wang 0003, Chen Qian 0001, Kaiyan Cui, Han Ding 0002, Wei Xi 0003, Jizhong Zhao, Jinsong Han
INFOCOM8
2020 BioDraw: Reliable Multi-Factor User Authentication with One Single Finger Swipe
abstract
Multi-factor user authentication (MFUA) becomes increasingly popular due to its superior security comparing with single-factor user authentication. However, existing MFUAs require multiple interactions between users and different authentication components when sensing the multiple factors, leading to extra overhead and bad use experiences. In this paper, we propose a secure and user-friendly MFUA system, namely BioDraw, which utilizes four categories of biometrics (impedance, geometry, composition, and behavior) of human hand plus the pattern-based password to identify and authenticate users. A user only needs to draw a pattern on a RFID tag array, while four biometrics can be simultaneously collected. Particularly, we design a gradient-based pattern recognition algorithm for pattern recognition and then a CNN-LSTM-based classifier for user recognition. Furthermore, to guarantee the systemic security, we propose a novel anti-spoofing scheme, called Binary ALOHA, which utilizes the inhabit randomness of RFID systems. We perform extensive experiments over 21 volunteers. The experiment result demonstrates that BioDraw can achieve a high authentication accuracy (with a false reject rate less than 2%) and is effective in defending against various attacks.
Jianwei Liu 0008, Jinsong Han, Feng Lin 0004, Kui Ren 0001
IWQoS3
2020 Deaf-aid: mobile IoT communication exploiting stealthy speaker-to-gyroscope channel
abstract
Internet of Things (IoT) devices are hindered from communicating with their neighbors by incompatible protocols or electromagnetic interference. Existing solutions adopting physical covert channels have limitations in receiver distinction, additional hardware, conditional placement, or physical contact. Our system, Deaf-Aid, utilizes the stealthy speaker-to-gyroscope channel to build robust protocol-independent communication with automatic receiver identification. Deaf-Aid exploits ultrasonic signals at a frequency corresponding to the target receiver, forcing the gyroscope inside to resonate, so as to convey information. We probe the relationship among axes in a gyroscope to surmount frequency offset ingeniously and support multi-channel communication. Meanwhile, Deaf-Aid identifies the receivers automatically via device fingerprints constituted by the diversity of resonant frequency ranges. Furthermore, we entitle Deaf-Aid the capability of mobile communication which is an essential demand for IoT devices. We address the challenge of accurate signals recovery from motion interference. Extensive evaluations demonstrate that Deaf-Aid yields 47bps with BER lower than 1% under motion interference. To our best knowledge, Deaf-Aid is the first work to enable stealthy mobile IoT communication on the basis of inertial motion sensors.
Ming Gao 0023, Feng Lin 0004, Weiye Xu 0001, Muertikepu Nuermaimaiti, Jinsong Han, Wenyao Xu, Kui Ren 0001
MobiCom5
2020 Underwater cooperative MIMO communications using hybrid acoustic and magnetic induction technique
Zhangyu Li, Soham Desai, Vaishnendr D. Sudev, Pu Wang 0001, Jinsong Han
Comput. Networks5
2020 HMO: Ordering RFID Tags with Static Devices in Mobile Environments
abstract
Passive Radio Frequency Identification (RFID) tags have been widely applied in many applications, such as logistics, retailing, and warehousing. In many situations, the order of objects is more important than their absolute locations. However, state-of-art ordering methods need a continuing movement of tags and readers, which limit the application domain and scalability. In this paper, we propose a 2-dimension ordering approach for passive tags that requires no device movement. Instead, our method utilizes signal changes caused by arbitrary movement of human beings around tags, who carry no device for horizontal dimension ordering. Hence, our method is called Human Movement based Ordering (HMO). The basic idea of HMO is that when people pass between the reader antenna and tags, the received signal strength will change. By observing the time-series RSS changes of tags, HMO can obtain the order of tags along with a specific horizontal direction. For vertical dimension, we employ a linear programming method that is tolerant of tiny errors in practice. We implement HMO with commodity off-the-shelf RFID devices. The experimental results show that HMO can achieve up to 88.71 and 90.86 percent average accuracies in the signal-and multi-person cases, respectively.
Ge Wang 0003, Chen Qian 0001, Longfei Shangguan, Han Ding 0002, Jinsong Han, Kaiyan Cui, Wei Xi 0003, Jizhong Zhao
IEEE Trans. Mob. Comput.5
2020 Hu-Fu: Replay-Resilient RFID Authentication
abstract
We provide the first solution to an important question, “how a physical-layer authentication method can defend against signal replay attacks”. It was believed that if an attacker can replay the exact same reply signal of a legitimate authentication object (such as an RFID tag), any physical-layer authentication method will fail. This paper presents Hu-Fu, the first physical layer RFID authentication protocol that is resilient to the major attacks including tag counterfeiting, signal replay, signal compensation, and brute-force feature reply. Hu-Fu is built on two fundamental ideas, namely inductive coupling of two tags and signal randomization. Hu-Fu does not require any hardware or protocol modification on COTS passive tags and can be implemented with COTS devices. We implement a prototype of Hu-Fu and demonstrate that it is accurate and robust to device diversity and environmental changes, including locations, distance, and temperature. Hu-Fu provides a new direction of battery-free/low-power device authentication that enables numerous IoT applications.
Ge Wang 0003, Haofan Cai, Chen Qian 0001, Jinsong Han, Shouqian Shi, Xin Li 0057, Han Ding 0002, Wei Xi 0003, Jizhong Zhao
IEEE/ACM Trans. Netw.4
2019 WiPIN: Operation-Free Passive Person Identification Using Wi-Fi Signals
abstract
Wi-Fi signals-based person identification attracts increasing attention in the booming Internet-of-Things era mainly due to its pervasiveness and passiveness. Most previous work applies gaits extracted from WiFi distortions caused by person walking to achieve the identification. However, to extract useful gait, a person must walk along a pre-defined path for several meters, which requires user high collaboration and increases identification time overhead, thus limiting use scenarios. Moreover, gait based work has severe shortcoming in identification performance, especially when the user volume is large. In order to eliminate above limitations, in this paper, we present an operation-free person identification system, namely WiPIN, that requires least user collaboration and achieves good performance. WiPIN is based on an entirely new insight that Wi-Fi signals would carry person body information when propagating through the body, which is potentially discriminated for person identification. Then we demonstrate the feasibility on commodity off-the-shelf Wi-Fi devices by well- designed signal pre-processing, feature extraction, and identity matching algorithms. Results show that WiPIN achieves 92% identification accuracy over 30 users, high robustness to various experimental settings, and low identifying time overhead, i.e., less than 300ms.
Fei Wang 0037, Jinsong Han, Feng Lin 0004, Kui Ren 0001
GLOBECOM2
2019 Person-in-WiFi: Fine-Grained Person Perception Using WiFi
abstract
Fine-grained person perception such as body segmentation and pose estimation has been achieved with many 2D and 3D sensors such as RGB/depth cameras, radars (e.g. RF-Pose), and LiDARs. These solutions require 2D images, depth maps or 3D point clouds of person bodies as input. In this paper, we take one step forward to show that fine-grained person perception is possible even with 1D sensors: WiFi antennas. Specifically, we used two sets of WiFi antennas to acquire signals, i.e., one transmitter set and one receiver set. Each set contains three antennas horizontally lined-up as a regular household WiFi router. The WiFi signal generated by a transmitter antenna, penetrates through and reflects on human bodies, furniture, and walls, and then superposes at a receiver antenna as 1D signal samples. We developed a deep learning approach that uses annotations on 2D images, takes the received 1D WiFi signals as input, and performs body segmentation and pose estimation in an end-to-end manner. To our knowledge, our solution is the first work based on off-the-shelf WiFi antennas and standard IEEE 802.11n WiFi signals. Demonstrating comparable results to image-based solutions, our WiFi-based person perception solution is cheaper and more ubiquitous than radars and LiDARs, while invariant to illumination and has little privacy concern comparing to cameras.
Fei Wang 0037, Sanping Zhou, Stanislav Panev, Jinsong Han
ICCV4
2019 A (Near) Zero-cost and Universal Method to Combat Multipaths for RFID Sensing
abstract
There have been increasing interests in exploring the sensing capabilities of RFID to enable numerous IoT applications, including object localization, trajectory tracking, and human behavior sensing. However, most existing methods rely on the signal measurement either in a low multipath environment, which is unlikely to exist in many practical situations, or with special devices, which increase the operating cost. This paper investigates the possibility of measuring `multipath-free' signal information in multipath-prevalent environments simply using a commodity RFID reader. The proposed solution, Clean Physical Information Extraction (CPIX), is universal, accurate, and compatible to standard protocols and devices. CPIX improves RFID sensing quality with near zero cost - it requires no extra device. We implement CPIX and evaluate its effectiveness on improving the performance on tag localization. The results show that CPIX reduces the localization error by 30% to 50% and achieves the MOST accurate localization by commodity readers compared to existing work.
Ge Wang 0003, Chen Qian 0001, Kaiyan Cui, Han Ding 0002, Haofan Cai, Wei Xi 0003, Jinsong Han, Jizhong Zhao
ICNP7
2019 RF-Mehndi: A Fingertip Profiled RF Identifier
abstract
This paper presents RF-Mehndi, a passive commercial RFID tag array formed identifier. The key RF-Mehndi novelty is that when the user's fingertip touching on the tag array surface during the communication, the backscattered signals by the tag array become user-dependent and unique. Hence, if we enhance the communication modality of many personal cards nowadays by RF-Mehndi, in case that a card gets lost or stolen, it cannot be used illegally by the adversaries. To harvest such a benefit, we have two key observations in designing RF-Mehndi. The first observation is when tags are nearby, their interrogated currents can change each other's circuit characteristics, based on which unique phase features can be obtained from backscattered signals. The second observation is that when the user's fingertip touches the tag array surface during communication, the phase feature can be further profiled by this user. Based on these observations, the card and its holder can be potentially authenticated at the same time. To transfer the RF-Mehndi idea to a practical system, we further address technical challenges. We implement a prototype system. Extensive evaluations show the effectiveness of RF-Mehndi, achieving excellent authentication performance.
Cui Zhao, Zhenjiang Li 0001, Han Ding 0002, Jinsong Han, Wei Xi 0003, Ruowei Gui
INFOCOM5
2019 Continuous User Authentication by Contactless Wireless Sensing
abstract
This paper presents BodyPIN, which is a continuous user authentication system by contactless wireless sensing using commodity Wi-Fi. BodyPIN can track the current user's legal identity throughout a computer system's execution. In case the authentication fails, the consequent accesses will be denied to protect the system. The recent rich wireless-based user identification designs cannot be applied to BodyPIN directly, because they identify a user's various activities, rather than the user herself. The enforced to be performed activities can thus interrupt the user's operations on the system, highly inconvenient and not user-friendly. In this paper, we leverage the bio-electromagnetics domain human model for quantifying the impact of human body on the bypassing Wi-Fi signals and deriving the component that indicates a user's identity. Then, we extract suitable Wi-Fi signal features to fully represent such an identity component, based on which we fulfill the continuous user authentication design. We implement a BodyPIN prototype by commodity Wi-Fi NICs without any extra or dedicated wireless hardware. We show that BodyPIN achieves promising authentication performances, which is also lightweight and robust under various practical settings.
Fei Wang 0037, Zhenjiang Li 0001, Jinsong Han
IEEE Internet Things J.3
2019 Close-Proximity Detection for Hand Approaching Using Backscatter Communication
abstract
Smart environments and security systems require automatic detection of human behaviors including approaching to or departing from an object. Existing human motion detection systems usually require human beings to carry special devices, which limits their applications. In this paper, we present a system called APID to detect hand approaching behaviors by analyzing backscatter communication signals from a passive RFID tag on the object. APID does not require human beings to carry any device. The idea is based on the influence of hand movements to the vibration of backscattered tag signals. APID is compatible with commodity off-the-shelf devices and the EPCglobal Class-1 Generation-2 protocol. In APID, a commercial RFID reader continuously queries tags through emitting RF signals and tags simply respond with their IDs. A USRP monitor passively analyzes the communication signals and reports the approach and departure behaviors. We have implemented the APID system for both single-object and multi-object scenarios. Extensive evaluations demonstrate that APID can achieve high detection accuracy in both scenarios.
Han Ding 0002, Chen Qian 0001, Jinsong Han, Jian Xiao 0002, Xingjun Zhang, Ge Wang 0003, Wei Xi 0003, Jizhong Zhao
IEEE Trans. Mob. Comput.3
2019 Counting Human Objects Using Backscattered Radio Frequency Signals
abstract
In this paper, we propose a system called R# to estimate the number of human objects using passive RFID tags but without attaching anything to human objects. The idea is based on our observation that the more human objects are present, the higher the variation in the RSS values of the tag backscattered RF signals. Thus, based on the received RF signals, the reader can estimate the number of human objects. R# includes an RFID reader and some (say 20) passive tags, which are deployed in the region that we want to monitor the number of human objects, such as the region in front of a supermarket shelf. The RFID reader periodically emits RF signals to identify all tags and the tags simply respond with their IDs via EPCglobal Class 1 Generation 2 protocol. We implemented R# using commercial Impinj H47 passive RFID tags and Impinj reader model R420. We conducted experiments in a simulated picking aisle area of the supermarket environment. The experimental results show that R# can achieve high estimation accuracy (more than 90 percent with up to ten human objects).
Han Ding 0002, Jinsong Han, Alex X. Liu, Wei Xi 0003, Jizhong Zhao, Panlong Yang, Zhiping Jiang
IEEE Trans. Mob. Comput.2
2019 Verifiable Smart Packaging with Passive RFID
abstract
Smart packaging adds sensing abilities to traditional packages. This paper investigates the possibility of using RF signals to test the internal status of packages and detect abnormal internal changes. Towards this goal, we design and implement a nondestructive package testing and verification system using commodity passive RFID systems, called Echoscope. Echoscope extracts unique features from the backscatter signals penetrating the internal space of a package and compares them with the previously collected features during the check-in phase. The use of backscatter signals guarantees that there is no difference in RF sources and the features reflecting the internal status will not be affected. Compared to other nondestructive testing methods such as X-ray and ultrasound, Echoscope is much cheaper and provides ubiquitous usage. Our experiments in practical environments show that Echoscope can achieve very high accuracy and is very sensitive to various types abnormal changes.
Ge Wang 0003, Jinsong Han, Chen Qian 0001, Wei Xi 0003, Han Ding 0002, Zhiping Jiang, Jizhong Zhao
IEEE Trans. Mob. Comput.2
2018 Trio: Utilizing Tag Interference for Refined Localization of Passive RFID
abstract
We study a new problem, refined localization, in this paper. Refined localization calculates the location of an object in high precision, given that the object is in a relatively small region such as the surface of a table. Refined localization is useful in many cyber-physical systems such as industrial autonomous robots. Existing vision-based approaches suffer from several disadvantages, including good lighting conditions, line of sight, pre-learning process, and high computation overhead. Also vision-based approaches cannot differentiate objects with similar colors and shapes. This paper presents a new refined localization system, called Trio, which uses passive Radio Frequency Identification (RFID) tags for low cost and easy deployment. Trio provides a new angle to utilize RF interference for tag localization by modeling the equivalent circuits of coupled tags. We implement our prototype using commercial off-the-shelf RFID reader and tags. Extensive experiment results demonstrate that Trio effectively achieves high accuracy of refined localization, i.e., <; 1 cm errors for several types of main stream tags.
Han Ding 0002, Jinsong Han, Chen Qian 0001, Fu Xiao 0001, Ge Wang 0003, Wei Xi 0003, Jian Xiao 0002
INFOCOM2
2018 Preventing Unauthorized Access on Passive Tags
abstract
As the Ultra High Frequency (UHF) passive Radio Frequency IDentification (RFID) technology becomes increasingly deployed, it faces an array of new security attacks. In this paper, we consider a type of attack in which a malicious RFID reader could arbitrarily modify the tags via standard commands, e.g., IDs or other data in the memory. To deal with this type of attack, we propose a physical-layer RF signal based reader authentication solution, namely Arbitrator, that involves passively listening on RF channels, analyzing the communication signals, identifying unauthorized readers and jamming the commands from such readers. Our solution does not need to modify RFID devices or the underlying communication standards, hence fully compatible with the existing RFID infrastructure. In this study, we have implemented a prototype Arbitrator over the Universal Software Radio Peripheral (USRP) platform, and conducted extensive experiments to evaluate its performance. Our results show that Arbitrator can detect unauthorized RFID readers with high accuracy, and thus effectively diminish the unauthorized access attacks.
Han Ding 0002, Jinsong Han, Yanyong Zhang, Fu Xiao 0001, Wei Xi 0003, Ge Wang 0003, Zhiping Jiang
INFOCOM2
2018 Towards Replay-resilient RFID Authentication
abstract
We provide the first solution to an important question, "how a physical-layer authentication method can defend against signal replay attacks''. It was believed that if an attacker can replay the exact same reply signal of a legitimate authentication object (such as an RFID tag), any physical-layer authentication method will fail. This paper presents Hu-Fu, the first physical layer RFID authentication protocol that is resilient to the major attacks including tag counterfeiting, signal replay, signal compensation, and brute-force feature reply. Hu-Fu is built on two fundamental ideas, namely inductive coupling of two tags and signal randomization. Hu-Fu does not require any hardware or protocol modification on COTS passive tags and can be implemented with COTS devices. We implement a prototype of Hu-Fu and demonstrate that it is accurate and robust to device diversity and environmental changes, including locations, distance, and temperature. Hu-Fu provides a new direction of battery-free/low-power device authentication that enables numerous IoT applications.
Ge Wang 0003, Haofan Cai, Chen Qian 0001, Jinsong Han, Xin Li 0057, Han Ding 0002, Jizhong Zhao
MobiCom4
2017 Poster: Bidimensional Relative Localization Leveraging Interference among Passive Tags
Han Ding 0002, Ge Wang 0003, Jinsong Han, Jizhong Zhao
EWSN4
2017 RFIPad: Enabling Cost-Efficient and Device-Free In-air Handwriting Using Passive Tags
abstract
An important function of smart environments is the ubiquitous access of computing devices. In public areas such as hospitals, libraries, and airports, people may want to interact with nearby computing systems to get information, such as directions to a hospital room, locations of books, and flight departure/arrival information. Touch screen based displays and kiosks, which are commonly used today, may incur extra hardware cost or even possible germ and bacteria infection. This work provides a new solution: users can make queries and inputs by performing in-air handwriting to an array of passive RFID tags, named RFIPad. This input method does not require human hands to carry any device and hence is convenient for applications in public areas. Besides the mobile and contactless property, this system is a cost-efficient extension to current RFID systems: an existing reader can monitor multiple RFIPads while performing its regular applications such as identification and tracking. We implement a prototype of RFIPad using commercial off-the-shelf UHF RFID devices. Experimental results show that RFIPad achieves >91% accuracy in recognizing basic touch-screen operations and English letters.
Han Ding 0002, Chen Qian 0001, Jinsong Han, Ge Wang 0003, Wei Xi 0003, Kun Zhao 0002, Jizhong Zhao
ICDCS3
2017 iType: Using eye gaze to enhance typing privacy
abstract
This paper presents iType, a system that uses eye gaze for typing private information on commodity mobile platforms. The design combats three primary challenges: 1) relatively low accuracy of mobile gaze tracking; 2) difficulties in correcting input errors due to lacking the comparison with the true text-entry value; and 3) device motions and other noises that may interfere gaze tracking accuracy and thus the iType performance. We devise a set of effective techniques, including leveraging a collective behavior of the gaze tracking results, unique correlation of the typing error spatial distributions, and motion sensor hints from mobile devices, to address above challenges. A set of enhancement techniques are applied to further improve iType's robustness and reliability. We consolidate above designs and implement iType on iOS platform. Evaluations show that iType achieves high keystroke detection accuracy for the secure typing within a reasonable short latency.
Zhenjiang Li 0001, Mo Li 0001, Prasant Mohapatra, Jinsong Han, Shuaiyu Chen
INFOCOM4
2017 Poster: Combating Multipaths to Enable RFID Sensing in Practical Environments
abstract
There have been increasing interests in exploring the sensing capabilities of RFID beyond its basic identification task, to reveal more information of tagged objects and the physical world. Phase is a crucial physical feature for many RFID sensing applications, such as tag localization. Most existing methods rely on a low multipath environment for accurate phase measurement. Unfortunately, practical environments are highly likely to be multipath-revalent, especially for indoors. This paper presents the first work to extract "clean" phase measurement of RFID tags in multipath-prevalent environments. We propose CPEX (Clean Phase EXtraction) based on theoretical modeling, which is also validated via experimental results of our prototype implementation. We studied the performance of CPEX on tag localization. CPEX can achieve median errors of 4.3-6.4cm (in different setups), which is the most accurate 3D tag localization result in multipath-prevalent environments.
Ge Wang 0003, Chen Qian 0001, Jinsong Han, Haofan Cai
MobiCom3
2017 HMRL: Relative Localization of RFID Tags with Static Devices
abstract
Passive Radio Frequency Identification (RFID) tags have been widely applied in many applications, such as logistics, retailing, and warehousing. In many situations the relative locations of objects are more important than their absolute locations. However, state-of-art relative localization methods need continuing movement of tags and readers, which limit the application domain and scalability. In this paper, we propose a relative localization approach for passive tags that requires no device movement. Instead, our method utilizes signal changes caused by arbitrary movement of human beings around tags, who carry no device. Hence our method is called Human Movement based Relative Localization (HMRL). The basic idea of HMRL is that when people pass between reader antenna and tags, the received signal strength will change. By observing the time-series RSS changes of tags, HMRL can obtain the order of tags along a specific horizontal direction. HMRL can also get the order of tags in a vertical direction using hyperbolic positioning. We implement HMRL with commodity off-the-shelf RFID devices. The experimental results show that HMRL achieves high accuracy for relative localization of passive tags.
Ge Wang 0003, Chen Qian 0001, Longfei Shangguan, Han Ding 0002, Jinsong Han, Wei Xi 0003, Jizhong Zhao
SECON5
2017 A Platform for Free-Weight Exercise Monitoring with Passive Tags
abstract
Regular free-weight exercise helps to strengthen natural movements and stabilize muscles that are important to strength, balance, and posture of human beings. Prior works have exploited wearable sensors or RF signal changes for activity sensing, recognition, and counting, etc.. However, none of them have incorporated three key factors necessary for a practical free-weight exercise monitoring system: recognizing free-weight activities on site, assessing their qualities, and providing useful feedbacks to the bodybuilder promptly. Our FEMO system provides an integrated free-weight exercise monitoring service that incorporates all the essential functionalities mentioned above. FEMO achieves this by attaching passive RFID tags on the dumbbells and leveraging the Doppler shift profile of the reflected backscatter signals for on-site free-weight activity recognition and assessment. The rationale behind FEMO is 1) since each free-weight activity owns unique arm motions, the corresponding Doppler shift profile should be distinguishable to each other. 2) Doppler profile of each activity has a strong spatial-temporal correlation that implicitly reflects the quality of the activity. We implement FEMO with COTS RFID devices and conduct a two-week experiment. The preliminary result from 15 volunteers demonstrates that FEMO can be applied to a variety of free-weight activities, and provide valuable feedbacks for activity alignment.
Han Ding 0002, Jinsong Han, Longfei Shangguan, Wei Xi 0003, Zhiping Jiang, Zheng Yang 0002, Zimu Zhou, Panlong Yang, Jizhong Zhao
IEEE Trans. Mob. Comput.2
2017 GRfid: A Device-Free RFID-Based Gesture Recognition System
abstract
Gesture recognition has emerged recently as a promising application in our daily lives. Owing to low cost, prevalent availability, and structural simplicity, RFID shall become a popular technology for gesture recognition. However, the performance of existing RFID-based gesture recognition systems is constrained by unfavorable intrusiveness to users, requiring users to attach tags on their bodies. To overcome this, we propose GRfid, a novel device-free gesture recognition system based on phase information output by COTS RFID devices. Our work stems from the key insight that the RFID phase information is capable of capturing the spatial features of various gestures with low-cost commodity hardware. In GRfid, after data are collected by hardware, we process the data by a sequence of functional blocks, namely data preprocessing, gesture detection, profiles training, and gesture recognition, all of which are well-designed to achieve high performance in gesture recognition. We have implemented GRfid with a commercial RFID reader and multiple tags, and conducted extensive experiments in different scenarios to evaluate its performance. The results demonstrate that GRfid can achieve an average recognition accuracy of 96.5 and 92.8 percent in the identical-position and diverse-positions scenario, respectively. Moreover, experiment results show that GRfid is robust against environmental interference and tag orientations.
Yongpan Zou, Jiang Xiao 0001, Jinsong Han, Kaishun Wu, Yun Li 0002, Lionel M. Ni
IEEE Trans. Mob. Comput.3
2016 Instant and Robust Authentication and Key Agreement among Mobile Devices
abstract
Device-to-device communication is important to emerging mobile applications such as Internet of Things and mobile social networks. Authentication and key agreement among multiple legitimate devices is the important first step to build a secure communication channel. Existing solutions put the devices into physical proximity and use the common radio environment as a proof of identities and the common secret to agree on a same key. However they experience very slow secret bit generation rate and high errors, requiring several minutes to build a 256-bit key. In this work, we design and implement an authentication and key agreement protocol for mobile devices, called The Dancing Signals (TDS), being extremely fast and error-free. TDS uses channel state information (CSI) as the common secret among legitimate devices. It guarantees that only devices in a close physical proximity can agree on a key and any device outside a certain distance gets nothing about the key. Compared with existing solutions, TDS is very fast and robust, supports group key agreement, and can effectively defend against predictable channel attacks. We implement TDS using commodity off-the-shelf 802.11n devices and evaluate its performance via extensive experiments. Results show that TDS only takes a couple of seconds to make devices agree on a 256-bit secret key with high entropy.
Wei Xi 0003, Chen Qian 0001, Jinsong Han, Kun Zhao 0002, Sheng Zhong 0002, Xiang-Yang Li 0001, Jizhong Zhao
CCS3
2016 Device-free detection of approach and departure behaviors using backscatter communication
abstract
Smart environments and security systems require automatic detection of human behaviors including approaching to or departing from an object. Existing human motion detection systems usually require human beings to carry special devices, which limits their applications. In this paper, we present a system called APID to detect arm reaching by analyzing backscatter communication signals from a passive RFID tag on the object. APID does not require human beings to carry any device. The idea is based on the influence of human movements to the vibration of backscattered tag signals. APID is compatible with commodity off-the-shelf devices and the EPCglobal Class-1 Generation-2 protocol. In APID an commercial RFID reader continuously queries tags through emitting RF signals and tags simply respond with their IDs. A USRP monitor passively analyzes the communication signals and reports the approach and departure behaviors. We have implemented the APID system for both single-object and multi-object scenarios in both horizontal and vertical deployment modes. The experimental results show that APID can achieve high detection accuracy.
Han Ding 0002, Chen Qian 0001, Jinsong Han, Ge Wang 0003, Zhiping Jiang, Jizhong Zhao, Wei Xi 0003
UbiComp3
2016 Verifiable smart packaging with passive RFID
abstract
Smart packaging adds sensing abilities to traditional packages. This paper investigates the possibility of using RF signals to test the internal status of packages and detect abnormal internal changes. Towards this goal, we design and implement a nondestructive package testing and verification system using commodity passive RFID systems, called Echoscope. Echoscope extracts unique features from the backscatter signals penetrating the internal space of a package and compares them with the previously collected features during the check-in phase. The use of backscatter signals guarantees that there is no difference in RF sources and the features reflecting the internal status will not be affected. Compared to other nondestructive testing methods such as X-ray and ultrasound, Echoscope is much cheaper and provides ubiquitous usage. Our experiments in practical environments show that Echoscope can achieve very high accuracy and is very sensitive to various types abnormal changes.
Ge Wang 0003, Chen Qian 0001, Jinsong Han, Wei Xi 0003, Han Ding 0002, Zhiping Jiang, Jizhong Zhao
UbiComp3
2016 VADS: Visual attention detection with a smartphone
abstract
Identifying the object that attracts human visual attention is an essential function for automatic services in smart environments. However, existing solutions can compute the gaze direction without providing the distance to the target. In addition, most of them rely on special devices or infrastructure support. This paper explores the possibility of using a smartphone to detect the visual attention of a user. By applying the proposed VADS system, acquiring the location of the intended object only requires one simple action: gazing at the intended object and holding up the smartphone so that the object as well as user's face can be simultaneously captured by the front and rear cameras. We extend the current advances of computer vision to develop efficient algorithms to obtain the distance between the camera and user, the user's gaze direction, and the object's direction from camera. The object's location can then be computed by solving a trigonometric problem. VADS has been prototyped on commercial off-the-shelf (COTS) devices. Extensive evaluation results show that VADS achieves low error (about 1.5° in angle and 0.15m in distance for objects within 12m) as well as short latency. We believe that VADS enables a large variety of applications in smart environments.
Zhiping Jiang, Jinsong Han, Chen Qian 0001, Wei Xi 0003, Kun Zhao 0002, Han Ding 0002, Shaojie Tang 0001, Jizhong Zhao, Panlong Yang
INFOCOM2
2016 CSI feedback reduction by checking its validity period: poster
abstract
Multi-user MIMO (MU-MIMO) is proposed in 802.11ac to achieve more than 3x faster than 802.11n. In the real world no-one gets close to theoretical speeds. The primary reason for this anomaly are the various overheads of channel access and channel state information (CSI) feedback. In order to achieve concurrent data transmission, (CSI) feedback from users is required. However, this overhead can easily overwhelm the actual channel time spent on data transmission in large-scale network. Moreover, due to spontaneous uplink traffic, which makes the problem even more challenging.
Yuanhang Cai, Wei Xi 0003, Zhi Wang 0002, Kun Zhao 0002, Jinsong Han, Chen Qian 0001, Han Ding 0002, Jizhong Zhao
MobiCom5
2016 Task Assignment on Multi-Skill Oriented Spatial Crowdsourcing
abstract
With the rapid development of mobile devices and crowdsourcing platforms, the spatial crowdsourcing has attracted much attention from the database community. Specifically, the spatial crowdsourcing refers to sending location-based requests to workers, based on their current positions. In this paper, we consider a spatial crowdsourcing scenario, in which each worker has a set of qualified skills, whereas each spatial task (e.g., repairing a house, decorating a room, and performing entertainment shows for a ceremony) is time-constrained, under the budget constraint, and required a set of skills. Under this scenario, we will study an important problem, namelymulti-skill spatial crowdsourcing(MS-SC), which finds an optimal worker-and-task assignment strategy, such that skills between workers and tasks match with each other, and workers’ benefits are maximized under the budget constraint. We prove that the MS-SC problem is NP-hard and intractable. Therefore, we propose three effective heuristic approaches, including greedy,$g$-divide-and-conquer and cost-model-based adaptive algorithms to get worker-and-task assignments. Through extensive experiments, we demonstrate the efficiency and effectiveness of our MS-SC processing approaches on both real and synthetic data sets.
Peng Cheng 0003, Xiang Lian 0001, Lei Chen 0002, Jinsong Han, Jizhong Zhao
IEEE Trans. Knowl. Data Eng.4
2016 CBID: A Customer Behavior Identification System Using Passive Tags
abstract
Different from online shopping, in-store shopping has few ways to collect the customer behaviors before purchase. In this paper, we present the design and implementation of an on-site Customer Behavior IDentification system based on passive RFID tags, named CBID. By collecting and analyzing wireless signal features, CBID can detect and track tag movements and further infer corresponding customer behaviors. We model three main objectives of behavior identification by concrete problems and solve them using novel protocols and algorithms. The design innovations of this work include a Doppler effect based protocol to detect tag movements, an accurate Doppler frequency estimation algorithm, an image-based human count estimation protocol and a tag clustering algorithm using cosine similarity. We have implemented a prototype of CBID in which all components are built by off-the-shelf devices. We have deployed CBID in real environments and conducted extensive experiments to demonstrate the accuracy and efficiency of CBID in customer behavior identification.
Jinsong Han, Han Ding 0002, Chen Qian 0001, Wei Xi 0003, Zhi Wang 0002, Zhiping Jiang, Longfei Shangguan, Jizhong Zhao
IEEE/ACM Trans. Netw.1
2016 Twins: Device-Free Object Tracking Using Passive Tags
abstract
Device-free object tracking provides a promising solution for many localization and tracking systems to monitor non-cooperative objects, such as intruders, which do not carry any transceiver. However, existing device-free solutions mainly use special sensors or active RFID tags, which are much more expensive compared to passive tags. In this paper, we propose a novel motion detection and tracking method using passive RFID tags, named Twins. The method leverages a newly observed phenomenon called critical state caused by interference among passive tags. We contribute to both theory and practice of this phenomenon by presenting a new interference model that precisely explains it and using extensive experiments to validate it. We design a practical Twins based intrusion detection system and implement a real prototype by commercial off-the-shelf RFID reader and tags. Experimental results show that Twins is effective in detecting the moving object, with very low location errors of 0.75 m in average (with a deployment spacing of 0.6 m).
Jinsong Han, Chen Qian 0001, Dan Ma 0006, Jizhong Zhao, Wei Xi 0003, Zhiping Jiang, Zhi Wang 0002
IEEE/ACM Trans. Netw.1
2016 GenePrint: Generic and Accurate Physical-Layer Identification for UHF RFID Tags
abstract
Physical-layer identification utilizes unique features of wireless devices as their fingerprints, providing authenticity and security guarantee. Prior physical-layer identification techniques on radio frequency identification (RFID) tags require nongeneric equipments and are not fully compatible with existing standards. In this paper, we propose a novel physical-layer identification system, GenePrint, for UHF passive tags. The GenePrint prototype system is implemented by a commercial reader, a USRP-based monitor, and off-the-shelf UHF passive tags. Our solution is generic and completely compatible with the existing standard, EPCglobal C1G2 specification. GenePrint leverages the internal similarity among pulses of tags' RN16 preamble signals to extract a hardware feature as the fingerprint. We conduct extensive experiments on over 10 000 RN16 preamble signals from 150 off-the-shelf RFID tags. The results show that GenePrint achieves a high identification accuracy of 99.68% +. The feature extraction of GenePrint is resilient to various malicious attacks, such as the feature replay attack.
Jinsong Han, Chen Qian 0001, Panlong Yang, Dan Ma 0006, Zhiping Jiang, Wei Xi 0003, Jizhong Zhao
IEEE/ACM Trans. Netw.1
2015 NFV: Near Field Vibration Based Group Device Pairing
Zhiping Jiang, Jinsong Han, Wei Xi 0003, Jizhong Zhao
CollaborateCom2
2015 EMoD: Efficient Motion Detection of Device-Free Objects Using Passive RFID Tags
abstract
Efficient and accurate tracking of device-free objects is critical for anti-intrusion systems. Prior solutions for device-free object tracking are mainly based on costly sensing infrastructures, resulting in barriers to practical applications. In this paper, we propose an accurate and efficient motion detection system, named EMoD, to track device-free objects based on cheap passive RFID tags. EMoD is the first RFID system that can estimate the moving direction as well as the current location of a device-free object by measuring critical power variation sequences of passive tags. Compared with previous solutions, the unique advantage of EMoD, i.e., the capability to estimate moving directions, enables object tracking using a much sparser tag deployment. We contribute to both theory and practice of this phenomenon by presenting the interference model that precisely explains it and using extensive experiments to validate it. We design a practical EMoD based intrusion detection system and implement a prototype by commercial off-the-shelf (COTS) RFID reader and tags. The real-world experiments results show that EMoD is effective in tracking the trajectory of moving object in various environments.
Kun Zhao 0002, Chen Qian 0001, Wei Xi 0003, Jinsong Han, Xue (Steve) Liu, Zhiping Jiang, Jizhong Zhao
ICNP4
2015 Human object estimation via backscattered radio frequency signal
abstract
In this paper, we propose a system called R# to estimate the number of human objects using passive RFID tags but without attaching anything to human objects. The idea is based on our observation that the more human objects are present, the higher the variance in the RSS values of the tag backscattered RF signal. Thus, based on the received RF signal, the reader can estimate the number of human objects. R# includes an RFID reader and some (say 20) passive tags, which are deployed in the region that we want to monitor the number of human objects, such as the region in front of a painting. The RFID reader periodically emits RF signal to identify all tags and the tags simply respond with their IDs via C1G2 standard protocols. We implemented R# using commercial Impinj H47 passive RFID tags and Impinj reader model R420. We conducted experiments in a simulated picking aisle area of the supermarket environment. The experimental results show that R# can achieve high estimation accuracy (more than 90%).
Han Ding 0002, Jinsong Han, Alex X. Liu, Jizhong Zhao, Panlong Yang, Wei Xi 0003, Zhiping Jiang
INFOCOM2
2015 FEMO: A Platform for Free-weight Exercise Monitoring with RFIDs
abstract
Regular free-weight exercise helps to strengthen the body's natural movements and stabilize muscles that are important to strength, balance, and posture of human beings. Prior works have exploited wearable sensors or RF signal changes (e.g., WiFi and Blue tooth) for activity sensing, recognition and countingetc.. However, none of them have incorporate three key factors necessary for a practical free-weight exercise monitoring system: recognizing free-weight activities on site, assessing their qualities, and providing useful feedbacks to the bodybuilder promptly. Our FEMO system responds to these demands, providing an integrated free-weight exercise monitoring service that incorporates all the essential functionalities mentioned above. FEMO achieves this by attaching passive RFID tags on the dumbbells and leveraging the Doppler shift profile of the reflected backscatter signals for on-site free-weight activity recognition and assessment. The rationale behind FEMO is 1): since each free-weight activity owns unique arm motions, the corresponding Doppler shift profile should be distinguishable to each other and serves as a reliable signature for each activity. 2): the Doppler profile of each activity has a strong spatial-temporal correlation that implicitly reflects the quality of each performed activity. We implement FEMO with COTS RFID devices and conduct a two-week experiment. The preliminary result from 15 volunteers demonstrates that FEMO can be applied to a variety of free-weight activities and users, and provide valuable feedbacks for activity alignment.
Han Ding 0002, Longfei Shangguan, Zheng Yang 0002, Jinsong Han, Zimu Zhou, Panlong Yang, Wei Xi 0003, Jizhong Zhao
SenSys4
2015 ShopMiner: Mining Customer Shopping Behavior in Physical Clothing Stores with COTS RFID Devices
abstract
Shopping behavior data are of great importance to understand the effectiveness of marketing and merchandising efforts. Online clothing stores are capable capturing customer shopping behavior by analyzing the click stream and customer shopping carts. Retailers with physical clothing stores, however, still lack effective methods to identify comprehensive shopping behaviors. In this paper, we show that backscatter signals of passive RFID tags can be exploited to detect and record how customers browse stores, which items of clothes they pay attention to, and which items of clothes they usually match with. The intuition is that the phase readings of tags attached on desired items will demonstrate distinct yet stable patterns in the time-series when customers look at, pick up or turn over desired items. We design ShopMiner,, a framework that harnesses these unique spatial-temporal correlations of time-series phase readings to detect comprehensive shopping behaviors. We have implemented a prototype of ShopMiner, with a COTS RFID reader and four antennas, and tested its effectiveness in two typical indoor environments. Empirical studies from two-week shopping-like data show that ShopMiner, could achieve high accuracy and efficiency in customer shopping behavior identification.
Longfei Shangguan, Zimu Zhou, Xiaolong Zheng 0002, Lei Yang 0025, Yunhao Liu 0001, Jinsong Han
SenSys6
2015 Reliable Diversity-Based Spatial Crowdsourcing by Moving Workers
abstract
With the rapid development of mobile devices and the crowdsourcing platforms, the spatial crowdsourcing has attracted much attention from the database community, specifically, spatial crowdsourcing refers to sending a location-based request to workers according to their positions. In this paper, we consider an important spatial crowdsourcing problem, namely reliable diversity-based spatial crowdsourcing (RDB-SC), in which spatial tasks (such as taking videos/photos of a landmark or firework shows, and checking whether or not parking spaces are available) are time-constrained, and workers are moving towards some directions. Our RDB-SC problem is to assign workers to spatial tasks such that the completion reliability and the spatial/temporal diversities of spatial tasks are maximized. We prove that the RDB-SC problem is NP-hard and intractable. Thus, we propose three effective approximation approaches, including greedy, sampling, and divide-and-conquer algorithms. In order to improve the efficiency, we also design an effective cost-model-based index, which can dynamically maintain moving workers and spatial tasks with low cost, and efficiently facilitate the retrieval of RDB-SC answers. Through extensive experiments, we demonstrate the efficiency and effectiveness of our proposed approaches over both real and synthetic datasets.
Peng Cheng 0003, Xiang Lian 0001, Zhao Chen 0003, Lei Chen 0002, Jinsong Han, Jizhong Zhao
Proc. VLDB Endow.6
2015 WizBee: Wise ZigBee Coexistence via Interference Cancellation with Single Antenna
abstract
Coexistence of Wi-Fi and ZigBee in 2.4 GHz ISM band is a long standing and challenging problem. Previous solutions either require modifications of current ZigBee protocols or Wi-Fi re-configurations, which is not feasible in large-scale wireless sensor networks. In this paper, we present WizBee, a coexistence system using single-antenna sink without changing current Wi-Fi and ZigBee design. WizBee is based on an observation that Wi-Fi signal is about 5 to 20 dB stronger than ZigBee signal in symmetric area, which leaves much room for applying interference cancelation technique to mitigate Wi-Fi interference, and extract ZigBee signals. However, we need to cancel the Wi-Fi interference perfectly for residual ZigBee signal decoding, which needs more accurate channel coefficient across data transmissions in spite of cross technology interference. For robust and accurate Wi-Fi decoding, we use soft Viterbi decoding with weighted confidence value over interfered subcarriers. Consequently, our solution uses decoded data for channel coefficient estimation instead of conventional training symbol based methods. The key insight is that, the signal recovery opportunity for cross technology coexistence, lies in multi-domain information, such as power, frequency and coding discrepancies. Using these information properly will improve the coexistence network throughput effectively. We implemented WizBee in USRP/GNURadio software radio platform, and studied the decoding performance of interference cancelation technique. Our extensive evaluations under real wireless conditions show that WizBee improves ZigBee throughput up to 1.9x, with median throughput gain of 1.2x.
Yubo Yan, Panlong Yang, Xiang-Yang Li 0001, Jianjiang Lu, Lizhao You, Jiliang Wang, Jinsong Han, Yan Xiong 0001
IEEE Trans. Mob. Comput.8
2015 Unlocking Smart Phone through Handwaving Biometrics
abstract
Screen locking/unlocking is important for modern smart phones to avoid the unintentional operations and secure the personal stuff. Once the phone is locked, the user should take a specific action or provide some secret information to unlock the phone. The existing unlocking approaches can be categorized into four groups: motion, password, pattern, and fingerprint. Existing approaches do not support smart phones well due to the deficiency of security, high cost, and poor usability. We collect 200 users' handwaving actions with their smart phones and discover an appealing observation: the waving pattern of a person is kind of unique, stable and distinguishable. In this paper, we propose OpenSesame, which employs the users' waving patterns for locking/unlocking. The key feature of our system lies in using four fine-grained and statistic features of handwaving to verify users. Moreover, we utilize support vector machine (SVM) for accurate and fast classification. Our technique is robust compatible across different brands of smart phones, without the need of any specialized hardware. Results from comprehensive experiments show that the mean false positive rate of OpenSesame is around 15 percent, while the false negative rate is lower than 8 percent.
Lei Yang 0025, Yi Guo 0008, Jinsong Han, Yunhao Liu 0001, Cheng Wang 0001, Changwei Hu
IEEE Trans. Mob. Comput.4
2015 Shelving Interference and Joint Identification in Large-Scale RFID Systems
abstract
Prior work on anti-collision for radio frequency identification (RFID) systems usually schedule adjacent readers to exclusively interrogate tags for avoiding reader collisions. Although such a pattern can effectively deal with collisions, the lack of readers' collaboration wastes numerous time on the scheduling process and dramatically degrades the throughput of identification. Even worse, the tags within the overlapped interrogation regions of adjacent readers (termed as contentious tags), even if the number of such tags is very small, introduce a significant delay to the identification process. In this paper, we propose a new strategy for collision resolution. First, we shelve the collisions and identify the tags that do not involve reader collisions. Second, we perform a joint identification, in which adjacent readers collaboratively identify the contentious tags. In particular, we find that neighboring readers can cause a new type of tag collision, cross-tag-collision, which may impede the joint identification. We propose a protocol stack, named Season, to undertake the tasks in two phases and solve the cross-tag-collision. We conduct extensive simulations and preliminary implementation to demonstrate the efficiency of our scheme. The results show that our scheme can achieve above 6× improvement on the identification throughput in a large-scale dense reader environment.
Lei Yang 0025, Yong Qi 0001, Jinsong Han, Cheng Wang 0001, Yunhao Liu 0001
IEEE Trans. Parallel Distributed Syst.3
2014 CBID: A Customer Behavior Identification System Using Passive Tags
abstract
Different from online shopping, in-store shopping has few ways to collect the customer behaviors before purchase. In this paper, we present the design and implementation of an on-site Customer Behavior Identification system based on passive RFID tags, named CBID. By collecting and analyzing wireless signal features, CBID can detect and track tag movements and further infer corresponding customer behaviors. We model three main objectives of behavior identification by concrete problems and solve them using novel protocols and algorithms. The design innovations of this work include a Doppler effect based protocol to detect tag movements, an accurate Doppler frequency estimation algorithm, a multi-RSS based tag localization protocol, and a tag clustering algorithm using cosine similarity. We have implemented a prototype of CBID in which all components are built by off-the-shelf devices. We have deployed CBID in real environments and conducted extensive experiments to demonstrate the accuracy and efficiency of CBID in customer behavior identification.
Jinsong Han, Han Ding 0002, Chen Qian 0001, Dan Ma 0006, Wei Xi 0003, Zhi Wang 0002, Zhiping Jiang, Longfei Shangguan
ICNP1
2014 A fine-grained indoor localization using multidimensional Wi-Fi fingerprinting
abstract
Although fingerprint based localization is promising for indoor applications, its accuracy still remains a huge challenge. Most of existing approaches rely on the Radio Signal Strength (RSS) to generate fingerprints. However, merely using RSS is unable to accurately localize objects since such an one-dimensional fingerprint will be seriously influenced by the interference and multi-path effect in the indoor environment. In this paper, we propose a new localization approach based on multidimensional Wi-Fi fingerprint. Instead of only using RSS to construct fingerprint, we employ RSS, transmitted power, and channel information to construct an integrated fingerprint. The extended fingerprint enables fine-grained localization and tracking services. We also deign a cosine similarity based matching algorithm and enhanced particle filter mechanism to achieve accurate localization and tracking. Extensive experiment and implementation results show that the new fingerprint and proposed algorithms can achieve an accuracy within two meters in 90% of testing points, while demonstrating a good adaptability to complex indoor environments.
Deng Chen, Zhiping Jiang, Wei Xi 0003, Jinsong Han, Kun Zhao 0002, Jizhong Zhao, Zhi Wang 0002, Rui Li 0047
ICPADS5
2014 Nowhere to hide: An empirical study on hidden UHF RFID tags
abstract
Radio Frequency Identification (RFID) techniques are widely used in many ubiquitous applications. The most important usage of RFID techniques is to read the tags within a reader's interrogation area such that the objects attached with those tags can be identified. In real practice, it is common that a tag is physically in the interrogation range, but cannot be read by the reader, due to the multipath effect and other interference. This phenomenon, namely the hidden tag problem, is a big challenge to achieve high identification rate. To address this problem, most prior works depend on empirical or measurement-based methods to tune the transmission power for readers. Such a case-by-case solution is impractical for generic implementation. In this paper, we theoretically and experimentally explore the reasons why hidden tag problem occurs. To alleviate its impact, we propose a unified and measurable model, PAL, to formulate this problem and its impact. Different from previous works, our solution is generic and fully compatible with existing EPC C1G2 protocol. The analysis and measurement based on our model can help to design and deploy RFID systems with high identification rate.
Rui Li 0047, Han Ding 0002, Jinsong Han, Shaoping Li, Hui Liu 0006, Jizhong Zhao
ICPADS3
2014 Twins: Device-free object tracking using passive tags
abstract
Device-free based object tracking provides a promising solution for many localization and tracking systems to monitor non-cooperative objects which do not carry any transceiver such as intruders. However, existing device-free solutions mainly use sensors and active RFID tags, which are much more expensive compared to passive tags. In this paper, we propose a novel motion detection and tracking method using passive RFID tags, named Twins. The method leverages a phenomenon called critical state caused by interference among passive tags. We theoretically explain this phenomenon via an interference model and conduct extensive experiment to validate it. We design a practical Twins based intrusion detection system and implement a real prototype with commercial off-the-shelf reader and tags. Experimental results show that Twins is effective in detecting the moving object, with low location errors of 0.75m in average.
Jinsong Han, Chen Qian 0001, Dan Ma 0006, Jizhong Zhao, Pengfeng Zhang, Wei Xi 0003, Zhiping Jiang
INFOCOM1
2014 KEEP: Fast secret key extraction protocol for D2D communication
abstract
Device to device (D2D) communication is expected to become a promising technology of the next-generation wireless communication systems. Security issues have become technical barriers of D2D communication due to its “open-air” nature and lack of centralized control. Generating symmetric keys individually on different communication parties without key exchange or distribution is desirable but challenging. Recent work has proposed to extract keys from the measurement of physical layer random variations of a wireless channel, e.g., the channel state information (CSI) from orthogonal frequency-division multiplexing (OFDM). Existing CSI-based key extraction methods usually use the measurement results of individual subcarriers. However, our real world experiment results show that CSI measurements from near-by subcarriers have strong correlations and a generated key may have a large proportion of repeated bit segments. Hence attackers may crack the key in a relatively short time and hence reduce the security level of the generated keys. In this work, we propose a fast secret key extraction protocol, called KEEP. KEEP uses a validation-recombination mechanism to obtain consistent secret keys from CSI measurements of all subcarriers. It achieves high security level of the keys and fast key-generation rate. We implement KEEP using off-the-shelf 802.11n devices and evaluate its performance via extensive experiments. Both theoretical analysis and experimental results demonstrate that KEEP is safer and more effective than the state-of-the-art approaches.
Wei Xi 0003, Xiang-Yang Li 0001, Chen Qian 0001, Jinsong Han, Shaojie Tang 0001, Jizhong Zhao, Kun Zhao 0002
IWQoS4
2014 Poster: locating RFID tags by rotation
abstract
Locating objects labeled with RFID tags is an important issue which should be addressed in many applications, such as warehouse management, goods management in supermarket and finding of lost objects. Some existing works use large numbers of reference tags which involve lots of manpower to deploy them. Others achieve high accuracy, but rely on sophisticated equipments which are hardly available in large scale to the industry. This work exploits the radiation pattern of existing directional panel antenna which is steerable and derives angle-of-arrival (AoA) information from the energy reflected by the target tag when the antenna is rotating. We use Commercial Off-The-Shelf (COTS) equipments and get median position accuracy of 29cm in our preliminary experiment.
Wei Xi 0003, Shaojie Tang 0001, Jinsong Han, Jizhong Zhao, Xiang-Yang Li 0001, Zhi Wang 0002, Zhiping Jiang
MobiCom4
2014 Communicating Is Crowdsourcing: Wi-Fi Indoor Localization with CSI-Based Speed Estimation
Zhiping Jiang, Wei Xi 0003, Xiang-Yang Li 0001, Shaojie Tang 0001, Jizhong Zhao, Jinsong Han, Kun Zhao 0002, Zhi Wang 0002
J. Comput. Sci. Technol.6
2014 Efficient and secure key extraction using channel state information
Zhi Wang 0002, Jinsong Han, Wei Xi 0003, Jizhong Zhao
J. Supercomput.2
2014 OTrack: Towards Order Tracking for Tags in Mobile RFID Systems
abstract
In many logistics applications of RFID technology, luggage attached with tags are placed on moving conveyor belts for processing. It is important to figure out the order of goods on the belts so that further actions like sorting can be accurately taken on proper goods. Due to arbitrary goods placement or the irregularity of wireless signal propagation, neither of the order of tag identification nor the received signal strength provides sufficient evidence on their relative positions on the belts. In this study, we observe, from experiments, a critical region of reading rate when a tag gets close enough to a reader. This phenomenon, as well as other signal attributes, yields the stable indication of tag order. We establish a probabilistic model for recognizing the transient critical region and propose the OTrack protocol to continuously monitor the order of tags. To validate the protocol, we evaluate the accuracy and effectiveness through a one-month experiment conducted through a working conveyor at Beijing Capital International Airport.
Longfei Shangguan, Zhenjiang Li 0001, Zheng Yang 0002, Mo Li 0001, Yunhao Liu 0001, Jinsong Han
IEEE Trans. Parallel Distributed Syst.6
2013 Collision-driven physical-layer identification of RFID UHF tags
abstract
In this paper, we develop novel physical-layer identification schemes for passive Radio Frequency IDentification (RFID) tags. Due to the collision among tags, existing RFID systems suffer from a low identification efficiency. In this paper, we propose to use the unique physical-layer information of tags as the identification basis. We design a batch identification scheme for passive tags. Our Scheme can fully utilize the collided signals to achieve efficient and trustworthy identification. Leveraging collided signals, we also propose an AoA-based spatial identification scheme for providing location service. Our scheme are seamlessly compatible with commercial off-the-shelf RFID devices. The initial result shows the feasibility of our proposals.
Dan Ma 0006, Jinsong Han, Zhi Wang 0002
ICNP2
2013 GenePrint: Generic and accurate physical-layer identification for UHF RFID tags
abstract
Physical-layer identification utilizes unique features of wireless devices as their fingerprints, providing authenticity and security guarantee. Prior physical-layer identification techniques on RFID tags require non-generic equipments and are not fully compatible with existing standards. In this paper, we propose a novel physical-layer identification system, GenePrint, for UHF passive tags. The GenePrint prototype system is implemented by a commercial reader, a USRP-based monitor, and off-the-shelf UHF passive tags. Our solution is generic and completely compatible with the existing standard, EPCglobal C1G2 specification. GenePrint leverages the internal similarity among the pulses of tags' RN16 preamble signals to extract a hardware feature as the fingerprint. We conduct extensive experiments on over 10,000 RN16 preamble signals from 150 off-the-shelf RFID tags. The results show that GenePrint achieves a high identification accuracy of 99.68%+. The feature extraction of GenePrint is resilient to various malicious attacks, such as the feature replay attack.
Dan Ma 0006, Chen Qian 0001, Wenpu Li, Jinsong Han, Jizhong Zhao
ICNP4
2013 OpenSesame: Unlocking smart phone through handshaking biometrics
abstract
Screen locking/unlocking is important for modern smart phones to avoid the unintentional operations and secure the personal stuff. Once the phone is locked, the user should take a specific action or provide some secret information to unlock the phone. Existing approaches do not support smart phones well due to the deficiency of security, high cost, and poor usability. We collect 200 users' handshaking actions with their smart phones and discover an appealing observation: the shaking pattern of a person is kind of unique, stable and distinguishable. In this paper, we propose OpenSesame, which employs the users' shaking patterns for locking/unlocking. The key feature of our system lies in using four fine-grained and statistic features of handshaking to verify users. Moreover, we utilize support vector machine (SVM) for accurate classification. Results from comprehensive experiments show that our technique is robust compatible across different brands of smart phones, without the need of any specialized hardware.
Yi Guo 0008, Lei Yang 0025, Jinsong Han, Yunhao Liu 0001
INFOCOM4
2013 Rejecting the attack: Source authentication for Wi-Fi management frames using CSI Information
abstract
Comparing to well protected data frames, Wi-Fi management frames (MFs) are extremely vulnerable to various attacks. Since MFs are transmitted without encryption or authentication, attackers can easily launch various attacks by forging the MFs. In a collaborative environment with many Wi-Fi sniffers, such attacks can be easily detected by sensing the anomaly RSS changes. However, it is quite difficult to identify these spoofing attacks without assistance from other nodes. By exploiting some unique characteristics (e.g., rapid spatial decorrelation, independence of Txpower, and much richer dimensions) of 802.11n Channel State Information (CSI), we design and implement CSITE, a prototype system to authenticate the Wi-Fi management frames on PHY layer merely by one station. Our system CSITE, built upon off-the-shelf hardware, achieves precise spoofing detection without collaboration and in-advance fingerprint. Several novel techniques are designed to address the challenges caused by user mobility and channel dynamics. To verify the performances of our solution, we conduct extensive evaluations in various scenarios. Our test results show that our design significantly outperforms the RSS-based method. We observe about 8 times improvement by CSITE over RSS-based method on the falsely accepted attacking frames.
Zhiping Jiang, Jizhong Zhao, Xiang-Yang Li 0001, Jinsong Han, Wei Xi 0003
INFOCOM4
2013 MISS: Multi-dimensional Information Sensing Surveillance for Cold Chain Logistics
abstract
Cold chain logistics is of great importance for transporting temperature and vibration sensitive products. However, fine-grained surveillance remains challenging in cold chain logistics, due to the lack of multi-dimensional information that reflects the status of monitored objects. In this paper, we propose a multi-dimensional information sensing surveillance framework, named MISS, to timely detect abnormal events that occur in cold chain logistics. The sensed information, including temperature and acceleration etc., can be integrated to provide accurate detection on the abnormal events. By adopting minimum entropy and AVC algorithms, we can classify various status in cold chain logistics. We further perform real implementations and evaluations on a prototype, and examine the effectiveness of MISS.
Han Ding 0002, Rui Li 0047, Shaoping Li, Jinsong Han, Jizhong Zhao
MASS4
2013 Wi-Fi Fingerprint Based Indoor Localization without Indoor Space Measurement
abstract
Numerous indoor localization techniques have been proposed recently to meet the intensive demand for location-based service. Fingerprint-based approach is one of most popular and inexpensive solution. In terms of constructing the fingerprint database, there have to be a synchronized measurement for both indoor space(eg by labor-intensive site-survey or sensor-based crowd sensing) and fingerprint space, by this means the fingerprints database is established. It is the indoor space measurement hinders the usability of fingerprint-based localization system. In this work, we propose a sensor-free crowds ensing indoor localization scheme, protocol. The main contribution of our protocol is that we don't need indoor space measurement. Floor plan and RSS samples temporal sequence is the only requirement. The core of our method is a graph matching based manifold alignment process, which automatically finds the best correspondence between floor plan and wireless fingerprint transition structure. With no more need of indoor space measurement, the system deployment complexity and cost are significantly reduced. We implement our protocol at AP-end and deploy it in a 2000m^2 office environment. The evaluation has shown that our protocol can handle complex environment mapping and achieve high localization & tracking accuracy.
Zhiping Jiang, Jizhong Zhao, Jinsong Han, Shaojie Tang 0001, Wei Xi 0003
MASS3
2012 Mining Frequent Trajectory Patterns for Activity Monitoring Using Radio Frequency Tag Arrays
abstract
Activity monitoring, a crucial task in many applications, is often conducted expensively using video cameras. Effectively monitoring a large field by analyzing images from multiple cameras remains a challenging issue. Other approaches generally require the tracking objects to attach special devices, which are infeasible in many scenarios. To address the issue, we propose to use RF tag arrays for activity monitoring, where data mining techniques play a critical role. The RFID technology provides an economically attractive solution due to the low cost of RF tags and readers. Another novelty of this design is that the tracking objects do not need to be equipped with any RF transmitters or receivers. By developing a practical fault-tolerant method, we offset the noise of RF tag data and mine frequent trajectory patterns as models of regular activities. Our empirical study using real RFID systems and data sets verifies the feasibility and the effectiveness of this design.
Yunhao Liu 0001, Lei Chen 0002, Jian Pei 0001, Jinsong Han
IEEE Trans. Parallel Distributed Syst.5
2011 Privacy Leakage in Access Mode: Revisiting Private RFID Authentication Protocols
abstract
Existing RFID Privacy-Preserving Authentication (PPA) solutions mainly focus on the design of crypto based interactive protocols between readers and tags. Although the cryptographic mechanisms enable randomization and enhance protocol-level privacy, the access mode in RFID systems is less random and may leak private information. We introduce anew attack based on such privacy leakage in access mode, where we show that the mainstream RFID PPA protocols, including the linear, tree-based, and synchronization-based solutions, are not private. We also show that this new attack is easy to conduct, e.g., we can track tags that employ typical tree-based PPA protocols without the need of compromising tags. We discuss the applicability of the attack. Moreover, we provide useful recommendations to strengthen existing PPA protocols in defending against such attacks. The simulation results demonstrate the practicability and effectiveness of this attack.
Qingsong Yao, Jinsong Han, Yong Qi 0001, Lei Yang 0025, Yunhao Liu 0001
ICPP2
2011 Season: Shelving interference and joint identification in large-scale RFID systems
abstract
Prior work on anti-collision for Radio Frequency IDentification (RFID) systems usually schedule adjacent readers to exclusively interrogate tags for avoiding reader collisions. Although such a pattern can effectively deal with collisions, the lack of readers' collaboration wastes numerous time on the scheduling process and dramatically degrades the throughput of identification. Even worse, the tags within the overlapped interrogation regions of adjacent readers (termed as contentious tags), even if the number of such tags is very small, introduce a significant delay to the identification process. In this paper, we propose a new strategy for collision resolution. First, we shelve the collisions and identify the tags that do not involve reader collisions. Second, we perform a joint identification, in which adjacent readers collaboratively identify the contentious tags. In particular, we find that neighboring readers can cause a new type of collisions, cross-tag-collision, which may impede the joint identification. We propose a protocol stack, named Season, to undertake the tasks in two phases and solve the cross-tag-collision. We conduct extensive simulations and preliminary implementation to demonstrate the efficiency of our scheme. The results show that our scheme can achieve above 6 times improvement on the identification throughput in a large-scale dense reader environment.
Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Tao Gu 0001, Yunhao Liu 0001
INFOCOM2
2011 MAP: Authenticating Multiple-Tags
abstract
The prevalence of Radio Frequency Identification (RFID) technology requires Privacy-Preserving Authentication (PPA) protocols to combat the privacy leakage during authentication. Existing PPA protocols employ the per-tag authentication, in which the reader has to sequentially authenticate the tags within the detecting region. Such a processing pattern becomes a bottleneck in current RFID enabled systems, especially for batch-type processing applications. In this paper, we propose an efficient authentication protocol, which leverages the collaboration among multiple tags for accelerating the authentication speed. We also find that the collision, usually considered as a negative factor, is a helpful media to enable collaborative authentication among tags. Our protocol, termed as Multiple-tags privacy-preserving Authentication Protocol (MAP), authenticates a batch of tags concurrently with strong privacy protection and high efficiency guarantee. The analytical and simulation results show that the efficiency of MAP is better than O(logN) and asymptotically approaches O(1).
Qingsong Yao, Jinsong Han, Saiyu Qi
MASS2
2011 Rumor Riding: Anonymizing Unstructured Peer-to-Peer Systems
abstract
Although anonymizing Peer-to-Peer (P2P) systems often incurs extra traffic costs, many systems try to mask the identities of their users for privacy considerations. Existing anonymity approaches are mainly path-based: peers have to pre-construct an anonymous path before transmission. The overhead of maintaining and updating such paths is significantly high. We propose Rumor Riding (RR), a lightweight and non-path-based mutual anonymity protocol for decentralized P2P systems. Employing a random walk mechanism, RR takes advantage of lower overhead by mainly using the symmetric cryptographic algorithm. We conduct comprehensive trace-driven simulations to evaluate the effectiveness and efficiency of this design, and compare it with previous approaches. We also introduce some early experiences on RR implementations.
Yunhao Liu 0001, Jinsong Han, Jilong Wang 0001
IEEE Trans. Parallel Distributed Syst.2
2010 Identification-free batch authentication for RFID tags
abstract
Cardinality estimation and tag authentication are two major issues in large-scale Radio Frequency Identification (RFID) systems. While there exist both per-tag and probabilistic approaches for the cardinality estimation, the RFID-oriented authentication protocols are mainly per-tag based: the reader authenticates one tag at each time. For a batch of tags, current RFID systems have to identify them and then authenticate each tag sequentially, incurring large volume of authentication data and huge communication cost. We study the RFID batch authentication issue and propose the first probabilistic approach, termed as Single Echo based Batch Authentication (SEBA), to meet the requirement of prompt and reliable batch authentications in large scale RFID applications, e.g., the anti-counterfeiting solution. Without the need of identifying tags, SEBA provides a provable probabilistic guarantee that the percentage of potential counterfeit products is under the user-defined threshold. The experimental result demonstrates the effectiveness of SEBA in fast batch authentications and significant improvement compared to existing approaches.
Lei Yang 0025, Jinsong Han, Yong Qi 0001, Yunhao Liu 0001
ICNP2
2010 Utilizing RF Interference to Enable Private Estimation in RFID Systems
abstract
Counting or estimating the number of tags is crucial for RFID system. Researchers have proposed several fast cardinality estimation schemes to estimate the quantity of a batch of tags within a short time frame. Existing estimation schemes scarcely consider the privacy issue. Without effective protection, the adversary can utilize the responding signals to estimate the number of tags as accurate as the valid reader. To address this issue, we propose a novel privacy-preserving estimation scheme, termed as MEAS, which provides an active RF countermeasure against the estimation from invalid readers. MEAS comprises of two components, an Estimation Interference Device (EID) and two well-designed Interference Blanking Estimators (IBE). EID is deployed with the tags to actively generate interfering signals, which introduce sufficiently large estimation errors to invalid or malicious readers. Using a secret interference factor shared with EID, a valid reader can perform accurate estimation via two IBEs. Our theoretical analysis and simulation results show the effectiveness of MEAS. Meanwhile, MEAS can also maintain a high estimation accuracy using IBEs.
Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Qingsong Yao, Ying Chen 0004, Xiao Zhong
ICPADS2
2010 Revisting Tag Collision Problem in RFID Systems
abstract
In RFID systems, the reader is unable to discriminate concurrently reported IDs of tags from the overlapped signals, and a collision happens. Many algorithms for anticollision are proposed to improve the throughput and reduce the latency for tag identification. Existing anti-collision algorithms mainly employ CRC based collision detection functions for determining whether the collision happens. Generating CRC codes, however, requires complicated computations for both RF tags and readers, and hence incurs non-trivial time consumption, becoming the bottleneck. In this study, we design a Quick Collision Detection (QCD) scheme based on the bitwise complement function plus collision preamble, which significantly reduces the number of gates for computation and facilitates to simplify the IC design of RFID tags. The QCD scheme does not require any modification on upperlevel air protocols, so it can be seamlessly adopted by current anti-collision algorithms. Through comprehensive analysis and simulations, we show that QCD improves the identification efficiency by 40%.
Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Yunhao Liu 0001, Ying Chen 0004, Xiao Zhong
ICPP2
2009 ACTION: Breaking the Privacy Barrier for RFID Systems
abstract
In order to protect privacy, radio frequency identification (RFID) systems employ privacy-preserving authentication (PPA) to allow valid readers to explicitly authenticate their dominated tags without leaking private information. Typically, an RF tag sends an encrypted message to the reader, then the reader searches for the key that can decrypt the cipher to identify the tag. Due to the large-scale deployment of today's RFID systems, the key search scheme for any PPA requires a short response time. Previous designs construct balance-tree based key management structures to accelerate the search speed to 0(logN), where N is the number of tags. Being efficient, such approaches are vulnerable to compromising attacks. By capturing a small number of tags, compromising attackers are able to identify other tags that have not been corrupted. To address this issue, we propose an Anti- Compromising authenticaTION protocol, ACTION, which employs a novel sparse tree architecture, such that the key of every tag is independent from one another. The advantages of this design include: 1) resilience to the compromising attack, 2) reduction of key storage for tags from 0(logN) to 0(1), which is significant for resource critical tag devices, and 3) high search efficiency, which is 0(logN), as good as the best in the previous designs.
Li Lu 0001, Jinsong Han, Renyi Xiao, Yunhao Liu 0001
INFOCOM2
2009 An Enhanced Synchronization Approach for RFID Private Authentication
abstract
Radio frequency identification (RFID) technologies are on their highway to pervasive usage. However privacy protection is still an important problem since RFID tags attached to items are so cost constrained. Privacy preserving authentication approaches are proposed to authenticate tags without private information leaking. Previously designed approaches based on synchronization seeks O(1) complexity. While these synchronization based methods are efficient in normal case, they have weak points when desynchronized. When maliciously scanned, information stored in tag and reader goes farther and farther away from each other. An adversary can utilize this point to track a tag. We propose an enhanced synchronization approach for RFID private authentication, ESP, to solve this problem. ESP can eliminate the problem caused by desynchronization attack and help detecting replay attack. Analysis shows that ESP enhances privacy protection while still maintaining the authentication efficiency.
Qingsong Yao, Yong Qi 0001, Jizhong Zhao, Jinsong Han
MASS4
2009 Randomizing RFID Private Authentication
abstract
Privacy protection is increasingly important during authentications in Radio Frequency Identification (RFID) systems. In order to achieve high-speed authentication in large-scale RFID systems, researchers propose tree-based approaches, in which any pair of tags share a number of key components. Such designs, being efficient, often fail to achieve forward secrecy and resistance to attacks, such as compromising and desynchronization. Indeed, these attacks may still take effect even after a tag successfully finishes the authentication and key-updating procedure. To address the issue, we propose a lightweight RFID private authentication protocol, RWP, based on the random walk concept. RWP also provides the forward security and temporal resistance to the tracking attack. The analysis results show that RWP effectively enhances the security protection for RFID private authentication, and increases the authentication efficiency from O(logN) to O(1).
Qingsong Yao, Yong Qi 0001, Jinsong Han, Jizhong Zhao, Xiang-Yang Li 0001, Yunhao Liu 0001
PerCom3
2009 Popularity adaptive search in hybrid P2P systems
Xiaoqiu Shi, Jinsong Han, Yunhao Liu 0001, Lionel M. Ni
J. Parallel Distributed Comput.2
2009 Multiscale Representations for Fast Pattern Matching in Stream Time Series
abstract
Similarity-based time-series retrieval has been a subject of long-term study due to its wide usage in many applications, such as financial data analysis, weather data forecasting, and multimedia data retrieval. Its original task was to find those time series similar to a pattern (query) time-series data, where both the pattern and data time series are static. Recently, with an increasing demand on stream data management, similarity-based stream time-series retrieval has raised new research issues due to its unique requirements during the stream processing, such as one-pass search and fast response. In this paper, we address the problem of matching both static and dynamic patterns over stream time-series data. We will develop a novel multiscale representation, called multiscale segment mean, for stream time-series data, which can be incrementally computed and thus perfectly adapted to the stream characteristics. Most importantly, we propose a novel multistep filtering mechanism, step by step, over the multiscale representation. Analysis indicates that the mechanism can greatly prune the search space and thus offer fast response. Furthermore, batch processing optimization and the dynamic case where patterns are also from stream time series are discussed. Extensive experiments show the multiscale representation together with the multistep filtering scheme can efficiently filter out false candidates and detect patterns, compared to the multiscale wavelet.
Xiang Lian 0001, Lei Chen 0002, Jeffrey Xu Yu, Jinsong Han
IEEE Trans. Knowl. Data Eng.4
2008 DHT-assisted probabilistic exhaustive search in unstructured P2P networks
abstract
Existing replication strategies in unstructured P2P networks, such as square-root principle based replication, can effectively improve search efficiency. How to get optimal replication strategy, however, is not trivial. In this paper we show, through mathematical proof, that random replication strategy achieves the optimal results. By randomly distributing rather small numbers of item and query replicas in the unstructured P2P network, we can guarantee perfect search success rate comparable to exhaustive search with high probability. Our analysis also shows that the cost for such replication strategy is determined by the network size of a P2P system. We propose a hybrid P2P architecture which combines a lightweight DHT with an unstructured P2P overlay to address the problems of network size estimating and random peer sampling. We conduct comprehensive simulation to evaluate this design. Results show that our scheme achieves perfect search success rate with quite small overhead.
Xucheng Luo, Zhiguang Qin, Jinsong Han, Hanhua Chen
IPDPS3
2008 Road Network Based Adaptive Query Evaluation in VANET
abstract
In the Vehicle Ad-hoc NETwork (VANET), moving vehicles organize into a mobile wireless Ad-hoc network to share online traffic information. Each vehicle can issue a declarative query for aggregating the traffic information from others in order to facilitate the navigation and avoid traffic jam. Existing query methods suffer from high latency, incomplete results, and large messages due to the movement of the vehicles in VANET. In this paper, we propose an adaptive query evaluation method based on the road network. In order to overcome the problems incurred by the movement, a relative static query evaluation plan is constructed based on the road network, and each vehicle can participate in the query evaluation plan autonomously. We also introduce control messages to notify the changed location of the query originator to other vehicles involved in the evaluation plan. In addition, we propose an one time message transferring based results collecting method to reduce the message cost. The optimization over the multiple queries is also discussed to reduce the messages further. We evaluate the performance of our method by extensive simulations. Experimental results show that our method can provide complete results within a short response time and small traffic overhead.
Jun Gao 0003, Jinsong Han, Dongqing Yang, Tengjiao Wang 0003
MDM2
2008 Mutual Anonymity for Mobile P2P Systems
abstract
Mobile peer-to-peer networks (MOPNETs) have become popular applications due to their ease of communication and resource sharing patterns in unfixed network infrastructures. As privacy and security are coming under increasing attention, many mobile and ad hoc network protocols attempt to provide mutual anonymity for users. Most existing anonymous designs, however, are path based, where the anonymous communications are achieved via a predetermined path. Such a design suffers from unreliable delivery and high processing overheads and is not practical. We propose a scalable secret-sharing-based mutual anonymity protocol, termed PUZZLE, which enables anonymous query issuance and file delivery for MOPNETs in ad hoc environments by employing Shamir's secret sharing scheme. We present the design of PUZZLE, analyze its degree of security and anonymity, and evaluate its performance by comprehensive trace-driven simulations. Experimental results show that compared with previous designs, PUZZLE achieves mutual anonymous communications with a lower cryptography processing overhead and higher degree of anonymity.
Jinsong Han, Yunhao Liu 0001
IEEE Trans. Parallel Distributed Syst.1
2008 Pseudo Trust: Zero-Knowledge Authentication in Anonymous P2Ps
abstract
Most of the current trust models in peer-to-peer (P2P) systems are identity based, which means that in order for one peer to trust another, it needs to know the other peer's identity. Hence, there exists an inherent tradeoff between trust and anonymity. To the best of our knowledge, there is currently no P2P protocol that provides complete mutual anonymity as well as authentication and trust management. We propose a zero-knowledge authentication scheme called pseudo trust (PT), where each peer, instead of using its real identity, generates an unforgeable and verifiable pseudonym using a one-way hash function. A novel authentication scheme based on zero-knowledge proof is designed so that peers can be authenticated without leaking any sensitive information. With the help of PT, most existing identity-based trust management schemes become applicable in mutual anonymous P2P systems. We analyze the security and the anonymity in PT, and evaluate its performance using trace-driven simulations and a prototype PT-enabled P2P network. The strengths of our design include (1) no need for a centralized trusted party or CA, (2) high scalability and security, (3) low traffic and cryptography processing overheads, and (4) man-in-middle attack resistance.
Li Lu 0001, Jinsong Han, Yunhao Liu 0001, Lei Hu 0003, Jinpeng Huai, Lionel M. Ni
IEEE Trans. Parallel Distributed Syst.2
2007 Pseudo Trust: Zero-Knowledge Based Authentication in Anonymous Peer-to-Peer Protocols
abstract
Most of the current trust models in peer-to-peer (P2P) systems are identity based, which means that in order for one peer to trust another, it needs to know the other peer's identity. Hence, there exists an inherent tradeoff between trust and anonymity. To the best of our knowledge, there is currently no P2P protocol that provides complete mutual anonymity as well as authentication and trust management. We propose a zero-knowledge authentication scheme called pseudo trust (PT), where each peer, instead of using its real identity, generates an unforgeable and verifiable pseudonym using a one-way hash function. A novel authentication scheme based on zero-knowledge proof is designed so peers can be authenticated without leaking any sensitive information. With the help of PT, most existing identity-based trust management schemes become applicable in mutual anonymous P2P systems. We analyze the levels of security and anonymity in PT, and evaluate its performance using trace-driven simulations and a prototype implementation. The strengths of pseudo trust include the lack of need for a centralized trusted party or CA, high scalability and security, low traffic and cryptography processing overheads, and man-in-middle attack resistance. We aim for the pseudo trust design to be included in the P2P trust and anonymity context.
Li Lu 0001, Jinsong Han, Lei Hu 0003, Jinpeng Huai, Yunhao Liu 0001, Lionel M. Ni
IPDPS2
2007 Popularity Adaptive Search in Hybrid P2P Systems
abstract
In a hybrid peer-to-peer (P2P) system, flooding and DHT are both employed for content locating. The decision to use flooding or DHT largely depends on the population of desired data. Previous works either use local information only, or do not consider dynamic factors of P2P systems. In this paper, we propose a popularity adaptive search method for hybrid (PASH) P2P systems. By dynamically detecting the content popularity, PASH properly selects search methods and efficiently saves query traffic cost and response time. We comprehensively evaluate PASH through synthetic and trace-driven simulations. The results show that PASH outperforms existing approaches and it also scales well.
Xiaoqiu Shi, Jinsong Han, Yunhao Liu 0001, Lionel M. Ni
IPDPS2
2007 Dynamic Key-Updating: Privacy-Preserving Authentication for RFID Systems
abstract
The objective of private authentication for radio frequency identification (RFID) systems is to allow valid readers to explicitly authenticate their dominated tags without leaking tags' private information. To achieve this goal, RFID tags issue encrypted authentication messages to the RFID reader, and the reader searches the key space to locate the tags. Due to the lack of efficient key updating algorithms, previous schemes are vulnerable to many active attacks, especially the compromising attack. In this paper, we propose a strong and lightweight RFID private authentication protocol, SPA. By designing a novel key updating method, we achieve the forward secrecy in SPA with an efficient key search algorithm. We also show that, compared with existing designs, SPA is able to effectively defend against both passive and active attacks, including compromising attacks. Through prototype implementation, we observe that SPA is practical and scalable in current RFID infrastructures
Li Lu 0001, Jinsong Han, Lei Hu 0003, Yunhao Liu 0001, Lionel M. Ni
PerCom2
2006 HAND: An Overlay Optimization Algorithm in Peer-to-Peer Systems
Xiaoming Chen 0007, Zhoujun Li 0001, Yongzhen Zhuang, Jinsong Han, Lei Chen 0002
HPCC4
2006 Rumor Riding: Anonymizing Unstructured Peer-to-Peer Systems
abstract
Although anonymizing Peer-to-Peer (P2P) systems often incurs extra costs in terms of transfer efficiency, many systems try to mask the identities of their users for privacy considerations. Existing anonymity approaches are mainly path-based: peers have to pre-construct an anonymous path before transmission. The overhead of maintaining and updating such paths is significantly high. In this paper, we propose Rumor Riding (RR), a lightweight mutual anonymity protocol for decentralized P2P systems. RR employs a random walk scheme which frees initiating peers from the heavy load of path construction. Compared with previous RSA-based anonymity approaches, RR also takes advantage of lower cryptographic overhead by mainly utilizing a symmetric cryptographic algorithm to achieve anonymity. We demonstrate the effectiveness of this design through trace-driven simulations. The analytical and experimental results show that RR is more efficient than existing protocols. We also discuss our early implementation experiences with the RR prototype.
Jinsong Han, Yunhao Liu 0001
ICNP1
2005 Efficient data retrieving in distributed data-streaming environments
abstract
In a potential distributed application, automobile tracking system (ATS), automobile location data is continuously generated, kept in a distributed manner. As large amount of traffic will be incurred during search process, it is critical to construct an efficient overlay multicast structure for the ATS so as to distribute traffic to all the physical links evenly, as well as balance the load among group members. In this paper, we propose a distributed protocol, MMT scheme, in which end hosts self-organize into multiple multicast trees. We evaluate the performance of MMT with comprehensive simulations. Experimental results show that MMT outperforms existing approaches in load balance, and its performance penalties are low from the network and the application perspectives.
Yunhao Liu 0001, Lionel M. Ni, Jinsong Han
ICCCN4