VLDB 2026 Research / reviewers in the wild / expert
Penghao Wang 0004
dblp:97/8711-4
· DBLP profile ↗
13ranked-venue papers
6as first author
13since 2021 · last 2026
0009-0005-8431-5388ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 4 first-author · 10 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Fragmentation to Correlation: Reliable LoRa Reception over Weak Marine LinksabstractLoRa holds significant promise for marine monitoring and communication due to its advantages of long range, low power consumption, and low cost. However, in marine environments, its communication performance is severely degraded by the strong absorption of electromagnetic waves by seawater. To enhance the reliability of communication under weak channels in the marine environment, this article proposes FCLoRa, a LoRa receiver enhancement system for low signal-to-noise ratio (SNR) marine environments. FCLoRa adopts a dual-domain cooperative strategy between the transmitter and receiver. On the receiver side, it employs a multilevel accumulation scheme to detect packets by aggregating the energy of windowed symbol “fragments” and reconstructs complete signals by fusing weak, fragmented signals from multiple gateways. On the transmitter side, it builds a two-dimensional polarization fingerprint library based on antenna attitude sensing and dynamically adjusts the transmission direction to match the polarization characteristics of the base station, thereby minimizing signal loss. Experimental results show that FCLoRa achieves a packet detection rate of nearly 40% at an extremely low SNR of –35 dB, and improves the average SNR by 1.92 dB compared to conventional LoRa reception, demonstrating its practical value in extreme marine scenarios. Penghao Wang 0004, Jingyang Hu, Hongbo Jiang 0001, Chao Liu 0008 |
ACM Trans. Sens. Networks | 2 |
| 2025 | Threat from Windshield: Vehicle Windows as Involuntary Attack Sources on Automotive Voice AssistantsabstractAs automotive voice assistants (AVAs) become increasingly cen- tral to modern vehicles, their vulnerability to attacks exploiting inaudible sounds should raise security concerns. However, such concerns are often deemed low priority, because it is widely be- lieved that an attacker to AVAs should be strategically positioned inside the concerned vehicle for two main reasons: i) inaudible signals can barely penetrate vehicle hulls and ii) a line-of-sight (LoS) path is needed between the attacker (sound source) and the AVA's microphone. In this paper, we disprove this common belief by proposing ShieldSpear to launch AVA attacks outside vehicle hulls. ShieldSpear exploits a tiny piezo-element placed on the exterior of the windshield to convert it into both a speaker and microphone. While this setting naturally brings the attacking sound source into a vehicle, strategically placing this compactly integrated element may further yield i) covertness (blended into stickers), ii) LoS path to AVA's microphones, and iii) real-time attacking capability dur- ing vehicle motion. To maintain sufficient volume while evading detection, we design novel hardware and signal carriers for deliver- ing attack (voice) commands. Moreover, ShieldSpear leverages the windshield-converted microphone to acquire drivers' voiceprint so as to accurately emulate it in the faked commands. Extensive experiments involving five mainstream vehicles have demonstrated the effectiveness of ShieldSpear by a 90.9% end-to-end success rate in injecting faked voice commands into AVAs. Penghao Wang 0004, Shuo Huai, Yetong Cao, Chao Liu 0008, Jun Luo 0001 |
CCS | 1 |
| 2025 | BEyes: Unseen Eyes Snooping Pattern Lock via BFIabstractWith the proliferation of smartphone application services, the pattern lock remains widely used for authentication. Notably, the risks associated with password entry in public spaces have attracted significant attention from researchers. Various attacks have been explored to steal passwords, but each comes with limitations, such as requiring good lighting conditions, close proximity, pre-deployed devices, or system intrusion. To address these challenges, we propose an attack method called BEyes, which utilizes beamforming feedback information (BFI) to eavesdrop on pattern passwords drawn on smartphone screens. Since BFI is transmitted in clear text and describes the downlink channel state information (CSI), any Wi-Fi 5-enabled device can capture it out of the victim’s view, reducing the likelihood of the attack being detected. To avoid missing critical pattern drawing information, we propose a traffic generation mechanism based on traffic competition, which ensures stable BFI. To mitigate the effects of frequency-selective fading and noise, we apply subcarrier alignment and principal component analysis (PCA) to improve efficiency. Additionally, we introduce a motion-based joint inference model, enabling BEyes to generalize its inference from a few known pattern passwords to unknown ones. Extensive experiments demonstrate that BEyes achieves an accuracy of 89.2% in inferring a 3-line pattern password within the Top-10 attempts. Penghao Wang 0004, Feng Hong 0001, Zhongwen Guo, Chao Liu 0008 |
ICDCS | 2 |
| 2025 | EchoHealth: Non-Contact Rehabilitation Exercises via Active Acoustic SensingabstractWith the aging population, there is an increasing demand for rehabilitation services for people with chronic diseases. However, limitations such as medical resources, geographic barriers, and cost make home rehabilitation an option for more patients. Existing wearable devices and vision methods are effective but face problems with portability, cost, and privacy concerns. As for existing wireless sensing methods, they can only extract coarse features for activity recognition. Therefore, we present EchoHealth, which utilizes a smart speaker for rehabilitation exercise detection and assessment. We upgrade the smart speaker into an active sonar system without hardware modification to generate acoustic micro-distance images with motion information. Then, time-domain motion detection and distance-domain feature extraction are utilized to filter out the effects of non-motion time and distance to extract patient motion features for motion recognition. We further assess the patient's rehabilitation exercises from five aspects, based on which EchoHealth provides rehabilitation guidance. Extensive experiments with 15 participants performing 12 rehabilitation motions confirmed that EchoHealth can achieve 97.4% average accuracy in recognition of rehabilitation motion and provide accurate rehabilitation indicators in various environments. Chao Liu 0008, Jingyang Hu, Qibo Zhang, Siyu Chen 0017, Hongbo Jiang 0001, Penghao Wang 0004 |
INFOCOM | 7 |
| 2025 | Wi-GR: Wi-Fi-Based Gait Recognition Using Multi-Part Velocity ProfileabstractIn recent years, with increasing user demands for convenience, privacy, and personalized experiences, gait recognition has been widely studied across various domains, such as indoor intrusion detection and smart homes. Although computer vision solutions are extensively researched for their visual intuitiveness, Wi-Fi sensing is emerging as a new research focus due to its ability to preserve privacy. However, previous studies have primarily relied on abstract features with limited interpretability or required multiple Wi-Fi links. To address these issues, we propose Wi-GR, which utilizes a Wi-Fi link to extract robust and highly interpretable gait features for user recognition. First, we construct a multi-path gait signal model to establish a clear relationship between Channel State Information (CSI) and gait motion. Then, we design a gait signal separation and enhancement method to mitigate the effects of external non-target reflections and internal multi-part reflections, which significantly impact the extraction and interpretability of gait features. Finally, fine-grained gait features that visualize gait patterns are generated using MUSIC-based and GAN-based multi-part velocity profile generation algorithms, tailored for single-person and multi-person scenarios, respectively. Numerous experiments have demonstrated that Wi-GR achieves single-person recognition accuracies of 95.3%, 94.0%, and 93.2% for 30 persons in the meeting room, corridor, and lobby, respectively, and an average accuracy of 88.3% for two-person recognition. Penghao Wang 0004, Jingyang Hu, Feng Li 0002, Hongbo Jiang 0001, Minglu Li 0001, Chao Liu 0008 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | RefleXnoop: Passwords Snooping on NLoS Laptops Leveraging Screen-Induced Sound ReflectionabstractPassword inference attacks by covert wireless side-channels jeopardize information safety, even for people with high security awareness and vigilance against snoopers. Yet, with limited spatial resolution, existing attacks cannot accurately infer password input on QWERTY keyboards in distance, creating psychological safety in using laptops publicly. To refute this false belief, we propose RefleXnoop, enabling an attacker to snoop a victim's typing details on a non-line-of-sight (NLoS) laptop. Apart from passively overhearing keystroke acoustic emanations, RefleXnoop actively probes with ultrasound, whose larger bandwidth and lower noise floor offers a finer resolution. To further maximize its performance, RefleXnoop exploits the laptop's screen reflection to enhance diversity in sound acquisition, and it innovates in neural models to effectively fuse the diversified sound acquisitions and to achieve robust feature-to-key translation. We implement RefleXnoop with commodity hardware and conduct extensive evaluation on it; the results demonstrate that RefleXnoop achieves 85% top-100 accuracy for inferring 8-character passwords on laptop QWERTY-keyboard and in multiple noisy environments. Penghao Wang 0004, Jingzhi Hu, Chao Liu 0008, Jun Luo 0001 |
CCS | 1 |
| 2024 | AGR: Acoustic Gait Recognition Using Interpretable Micro-Range ProfileabstractIn recent times, gait recognition, a type of biometric identification, has been widely used for area access control and smart homes. It improves convenience, privacy, and personalized experiences. Contemporary academic inquiry centers on privacy-preserving wireless sensing solutions as substitutes for computer vision. Yet, prevailing strategies heavily lean on abstract features, leading to inherent limitations in interpretability and stability. Fortunately, the widespread utilization of smart speakers has opened up opportunities for acoustic sensing, making it possible to extract more interpretable features. In this paper, we further push the limit of acoustic recognition with visual interpretability by sequentially visualizing fine-grained acoustic human gait features. The construction of initial gait profiles involves matrixing and compressing multipath gait echoes, resulting in imperceptible gait indications. Interpretability is then achieved through novel micro-range profiles, incorporating innovations such as clutter elimination using the Mobile Target Detector (MTD), compensation for farther echo strength, and subtraction of macro torso migration. These interpretable gait profiles offer practical benefits by enhancing data utilization, optimizing abnormal data handling, and improving model stability. Extensive evaluations with an open experimental scenario have been conducted to demonstrate accuracy reaching 97.5% in general, and robust performance against impacts from various practical factors. Penghao Wang 0004, Ruobing Jiang, Chao Liu 0008, Jun Luo 0001 |
INFOCOM | 1 |
| 2024 | BeamCount: Indoor Crowd Counting Using Wi-Fi Beamforming Feedback InformationabstractReal-time indoor crowd counting plays an important role in many applications such as crowd control, resource allocation and advertisement. Current research predominantly relies on camera-based methods. However, computer vision-based solutions raise severe privacy and ethical concerns. In this paper, we propose a privacy-preserving counting solution called BeamCount based on Wi-Fi sensing. Instead of using conventional Wi-Fi Channel State Information (CSI) readings, we utilize Wi-Fi Beamforming Feedback Information (BFI) for crowd counting estimation. Compared to CSI which can only be extracted from few commodity Wi-Fi cards (e.g., Intel 5300), BFI readings can be obtained from a large range of commodity Wi-Fi devices. We establish a mapping relationship between BFI and headcount and extract headcounts from BFI inputs through a carefully designed adversarial network. Owing to the adversarial network's cross-domain capability, the proposed counting system can achieve high accuracy across different environments, demonstrating its generalization capability. To mitigate the effect of BFI compression on sensing performance, we adopt a novel time series prediction model. Extensive real-world experiments validate the effectiveness of BeamCount in various environments, achieving an average counting accuracy of 93.6%. Siyu Chen 0017, Hongbo Jiang 0001, Jie Xiong 0001, Jingyang Hu, Penghao Wang 0004, Chao Liu 0008, Zhu Xiao, Bo Li 0001 |
MobiHoc | 5 |
| 2024 | CamShield: Tracing Electromagnetics to Steer Ultrasound Against Illegal CamerasabstractTo balance venue safety with public photography rights, this article presents CamShield—a novel system for selective defense against unauthorized photography. Amid dense electromagnetic environments, CamShield reliably identifies cameras by analyzing their unintended electromagnetic emissions. By tracing frequency drift patterns and harmonic spectral movements unique to each device, CamShield can accurately detect cameras despite environmental noise or model similarities. An integrated antenna amplitude ratio module and Kalman filter further localize threats through resilient positioning. Directional ultrasonic beams then focus tuned acoustic interference toward devices, temporarily disrupting visualization in restricted locations while preserving ambient imaging freedoms. Comprehensive evaluations across three state-of-the-art object detectors quantify real-world reliability. With 30 intruding cameras, CamShield exhibited obstruction latencies below 346 ms. Furthermore, CamShield achieves three times the coverage using the same power as traditional Omnidirectional transmission. Together, the breakthroughs in pervasive camera sensing and context-aware actuation contribute toward advancing policy-centric access controls at the edge of cyber-physical convergence. CamShield sets an important precedent on enforcing venue custom protections in bounded secure zones without undermining positive public photography assumptions elsewhere. Qibo Zhang, Penghao Wang 0004, Jingyang Hu, Fanzi Zeng, Chao Liu 0008, Hongbo Jiang 0001 |
IEEE Internet Things J. | 2 |
| 2024 | AMT$^+$+: Acoustic Multi-Target Tracking With Smartphone MIMO SystemabstractAcoustic target tracking has shown great advantages for device-free human-machine interaction over vision/RF-based mechanisms. However, existing approaches for portable devices solely track a single target, incapable of the ubiquitous and highly challenging multi-target situations such as double-hand multimedia controlling and multi-player gaming. In this paper, we proposeAMT$^+$, a pioneering smartphone MIMO system to achieve centimeter-level multi-target tracking. The challenge of multi-target occlusion is effectively addressed by employing multiple speaker-microphone pairs. However, the unique challenge raised by MIMO is the superposition of multi-source signals due to the cross-correlation among speakers. Initially, we tackle this challenge by designing a weak cross-correlation signal to reduce interference passively. InAMT$^+$, we’ve further integrated self-interference cancellation for active minimize interference. The most distinguishing advantage ofAMT$^+$lies in the elimination of the raised multipath effect, which is commonly ignored in previous work by hastily assuming targets as particles.AMT$^+$employs Doppler filtering over delay subtraction for echo suppression. Further, by non-particle target reflections modeling results, we introduce a distance-projection-based method for continuous target identification and tracking. Implemented on commercial smartphones,AMT$^+$achieves on average 0.54 cm, 1.37 cm, and 2.13 cm errors for single, double, and triple target tracking respectively, and on average 97.0% classification accuracy for 14 controlling gestures. Penghao Wang 0004, Ruobing Jiang, Jingyang Hu, Yanmin Zhu 0006, Hongbo Jiang 0001, Minglu Li 0001, Chao Liu 0008 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Afitness: Fitness Monitoring on Smart Devices via Acoustic Motion ImagesabstractRecently, as fitness has become a popular part of people’s lives, the intention to record fitness processes and assess the standards of fitness movements has grown increasingly keen. However, the existing approaches have some limitations, for example, wearable devices can hinder users’ fitness activities; computer vision–based solutions pose the risk of privacy breach, and so on. Fortunately, we observed that smartspeaker, acoustic-based sensing is a promising method of activity monitoring. In this article, we propose Afitness, an acoustic-based sensing system that enables non-intrusive, passive, and high-precision fitness detection. Afitness has the following three innovations. (i) We utilize pulse compression to generate high-precision motion distance images on commercial devices that can be visually recognized. (ii) We propose a data augmentation algorithm, which also incorporates transfer learning to greatly reduce the pressure of data collection. (iii) We exploit incremental learning techniques that allow Afitness to improve the portability of our system and recognize new actions. Overall, Afitness achieves acoustic signal interpretability and environmental reliability detection. Penghao Wang 0004, Ruobing Jiang, Zhongwen Guo, Chao Liu 0008 |
ACM Trans. Sens. Networks | 1 |
| 2022 | Amaging: Acoustic Hand Imaging for Self-adaptive Gesture RecognitionabstractA practical challenge common to state-of-the-art acoustic gesture recognition techniques is to adaptively respond to intended gestures rather than unintended motions during the real-time tracking on human motion flow. Besides, other disadvantages of under-expanded sensing space and vulnerability against mobile interference jointly impair the pervasiveness of acoustic sensing. Instead of struggling along the bottlenecked routine, we innovatively open up an independent sensing dimension of acoustic 2-D hand-shape imaging. We first deductively demonstrate the feasibility of acoustic imaging through multiple viewpoints dynamically generated by hand movement. Amaging, hand-shape imaging triggered gesture recognition, is then proposed to offer adaptive gesture responses. Digital Dechirp is novelly performed to largely reduce computational cost in demodulation and pulse compression. Mobile interference is filtered by Moving Target Indication. Multi-frame macro-scale imaging with Joint Time-Frequency Analysis is performed to eliminate image blur while maintaining adequate resolution. Amaging features revolutionary multiplicative expansion on sensing capability and dual dimensional parallelism for both hand-shape and gesture-trajectory recognition. Extensive experiments and simulations demonstrate Amaging’s distinguishing hand-shape imaging performance, independent from diverse hand movement and immune against mobile interference. 96% hand-shape recognition rate is achieved with ResNet18 and 60× augmentation rate. Penghao Wang 0004, Ruobing Jiang, Chao Liu 0008 |
INFOCOM | 1 |
| 2021 | AMT: Acoustic Multi-target Tracking with Smartphone MIMO SystemabstractAcoustic target tracking has shown great advantages for device-free human-machine interaction over vision/RF based mechanisms. However, existing approaches for portable devices solely track single target, incapable for the ubiquitous and highly challenging multi-target situation such as double-hand multimedia controlling and multi-player gaming. In this paper, we propose AMT, a pioneering smartphone MIMO system to achieve centimeter-level multi-target tracking. Targets' absolute distance are simultaneously ranged by performing multi-lateration locating with multiple speaker-microphone pairs. The unique challenge raised by MIMO is the superposition of multisource signals due to the cross-correlation among speakers. We tackle this challenge by applying Zadoff-Chu(ZC) sequences with strong auto-correlation and weak cross-correlation. The most distinguishing advantage of AMT lies in the elimination of target raised multipath effect, which is commonly ignored in previous work by hastily assuming targets as particles. Concerning the multipath echoes reflected by each non-particle target, we define the novel concept of primary echo to best represent target movement. AMT then improves tracking accuracy by detecting primary echo and filtering out minor echoes. Implemented on commercial smartphones, AMT achieves on average 1.13 cm and 2.46 cm error for single and double target tracking respectively and on average 97% accuracy for 6 controlling gestures recognition. Chao Liu 0008, Penghao Wang 0004, Ruobing Jiang, Yanmin Zhu 0006 |
INFOCOM | 2 |