Weitao Xu

dblp:98/7731 · DBLP profile ↗
← Back
100ranked-venue papers
17as first author
67since 2021 · last 2026
0000-0001-9741-5912ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 74 · 16 first-author · 52 since 2021Human-computer interaction and ubiquitous computing · 8 · 3 since 2021Security and privacy · 7 · 1 first-author · 4 since 2021Systems, architecture and hardware · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ViM-Q: Scalable Algorithm-Hardware Co-Design for Vision Mamba Model Inference on FPGA
abstract
Vision Mamba (ViM) models offer a compelling efficiency advantage over Transformers by leveraging the linear complexity of State Space Models (SSMs), yet efficiently deploying them on FPGAs remains challenging. Linear layers struggle with dynamic activation outliers that render static quantization ineffective, while uniform quantization fails to capture the weight distribution at low bit-widths. Furthermore, while associative scan accelerates SSMs on GPUs, its memory access patterns are misaligned with the streaming dataflow required by FPGAs. To address these challenges, we present ViM-Q1, a scalable algorithm-hardware co-design for end-to-end ViM inference on the edge. We introduce a hardware-aware quantization scheme combining dynamic per-token activation quantization and per-channel smoothing to mitigate outliers, alongside a custom 4-bit per-block Additive Power-of-Two (APoT) weight quantization. The models are deployed on a runtime-parameterizable FPGA accelerator featuring a linear engine employing a Lookup-Table (LUT) unit to replace multiplications with shift-add operations, and a fine-grained pipelined SSM engine that parallelizes the state dimension while preserving sequential recurrence. Crucially, the hardware supports runtime configuration, adapting to diverse dimensions and input resolutions across the ViM family. Implemented on an AMD ZCU102 FPGA, ViM-Q achieves an average 4.96× speedup and 59.8× energy efficiency gain over a quantized NVIDIA RTX 3090 GPU baseline for low-batch inference on ViM-tiny. This co-design shows a viable path for deploying ViM models on resource-constrained edge devices.
Shengzhe Lyu, Yuhan She, Patrick S. Y. Hung, Ray C. C. Cheung, Weitao Xu
FCCM5
2026 ViM-Q: Energy Efficient Algorithm-Hardware Co-Design for Dynamically Quantized Vision Mamba Models
abstract
State-space models (SSMs), such as Mamba, provide an efficient alternative to Transformers for vision tasks by replacing their quadratic-cost self-attention with linear complexity state update. However, efficiently deploying Vision Mamba (ViM) models on FPGA platforms is challenging, as the latency is dominated by two key components: linear layers and the selective SSM. For the linear layers, highly dynamic activation outliers across tokens render conventional static quantization techniques ineffective. Meanwhile, while the associative scan algorithm is effective in accelerating SSM on GPUs, its data access pattern is fundamentally mismatched with FPGA architectures when mapping the model's inherently sequential recurrence, creating a critical dataflow bottleneck.
Shengzhe Lyu, Yuhan She, Patrick S. Y. Hung, Ray C. C. Cheung, Weitao Xu
FPGA5
2026 AutoEmbed: LLM-driven Automated Software Development for Generic Embedded IoT Systems
abstract
Embedded system development is crucial for enabling seamless connectivity and functionality across a wide range of Internet of Things (IoT) applications. However, such a complex process requires cross-domain knowledge of hardware and software and hence often necessitates direct developer involvement, making it labor-intensive, time-consuming, and error-prone. To address this challenge, this paper introduces AutoEmbed, the first automated software development platform for general-purpose embedded IoT systems. The key idea is to leverage the reasoning ability of Large Language Models (LLMs) and embedded system expertise to automate the hardware-in-the-loop development process. The main methods include a component-aware library resolution method for addressing hardware dependencies, a library knowledge generation method that injects utility domain knowledge into LLMs, and an auto-programming method that ensures successful deployment. We evaluate AutoEmbed’s performance across 71 modules and four mainstream embedded development platforms with over 350 IoT tasks. Experimental results show that AutoEmbed can generate codes with an accuracy of 95.7% and complete tasks with a success rate of 86.5%, surpassing human-in-the-loop baselines by 15.6%–37.7% and 25.5%–53.4%, respectively. We also show AutoEmbed ’s potential through case studies in environmental monitoring and remote control systems development. © 2026 Copyright held by the owner/author(s).
Huanqi Yang, Mingda Han, Zhenjiang Li 0001, Weitao Xu
SenSys5
2026 Efficient Encoding/Decoding Algorithms for Irreducible Polynomial Remainder Codes via Additive FFT
abstract
Polynomial remainder codes form a class of linear codes constructed based on the Chinese Remainder Theorem over polynomial rings, with Reed-Solomon codes as a special case. In particular, irreducible polynomial remainder codes are those where the moduli are pairwise coprime irreducible polynomials. This paper presents an efficient encoding and decoding method for irreducible polynomial remainder codes over F2m, leveraging the additive Fast Fourier Transform (additive FFT). The proposed approach achieves a computational complexity ofO(Nlog2(N−K)), whereNandKdenote the code length and dimension, with the additional requirement thatN−Km−1andN−Kis a power of 2. This substantially outperforms the best known algorithm for such codes, which has a complexity ofO(N2). Furthermore, we conduct a non-asymptotic complexity comparison under specific parameters, with numerical results demonstrating that the proposed algorithms effectively reduces computational complexity. For example, with code lengthN= 256 and dimensionK= 224, our method achieves an approximately 83% reduction in multiplicative complexity for encoding and a 50% reduction for decoding compared to the state-of-the-art approach for polynomial remainder codes.
Zhengyi Jiang 0001, Weitao Xu, Linqi Song, Hanxu Hou
IEEE Trans. Commun.4
2026 Robust Federated Learning Under Heterogeneity via Rank-One and Column-Sparsity Model
abstract
Byzantine-robust federated learning aims to maintain resilient performance in the presence of malicious attacks that can impede the convergence of learning algorithms. Although numerous robust aggregators have been developed to merge the collected gradient information in the server, they either require data homogeneity and are suboptimal for heterogeneous data, or their breakdown points—the smallest proportion of outliers that can make the aggregators fail—are not theoretically analyzed or less than 0.5. In contrast to existing aggregators, this paper formulates the aggregation process as a low-rank plus sparse decomposition model, where the low-rank component, with a rank of one, facilitates accurate gradient computation, while the sparse component, penalized by the ℓ2,0-norm, mitigates the impact of outliers. We prove that the devised rule achieves the maximum breakdown point of 0.5. Besides, we apply our aggregation rule to Byzantine-robust federated learning and employ the Polyak’s momentum to reduce gradient variance among honest workers. It is analyzed that our aggregator achieves order-optimal Byzantine-resilient federated learning for heterogeneous data. Experimental results using MNIST, Fashion-MNIST and CIFAR-10 demonstrate that the developed approach yields higher classification accuracy than the competing aggregators under different attack types and heterogeneity levels.
Zhi-Yong Wang, Hao Nan Sheng, Hing-Cheung So, Jiande Sun 0001, Linqi Song, Weitao Xu
IEEE Trans. Circuits Syst. Video Technol.6
2026 Your Copied Data is Under Monitoring: A Study of Clipboard Usage in Android Applications
abstract
Clipboard usage is prevalent in mobile applications nowadays. However, insufficient access control on the clipboard in mobile operating systems exposes its contained data to high risks where one application can read the data, store it locally, or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile application ecosystem. Therefore, this paper proposes an automated tool, ClipboardScope+, that leverages the principled static program analysis to uncover the clipboard data usage in mobile applications at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an application. ClipboardScope+ is evaluated on over1.2 millionmobile applications available on Google Play, spanning the years 2022 and 2023. It uncovered an increase of 5.9% in behaviors of storing and transferring clipboard data over the one-year time, most of which occur automatically in background services. We also conducted a comprehensive case study to characterize different clipboard usages and reveal their privacy issues. Moreover, we uncovered a prevalent programming habit of using theSharedPreferencesobject to store historical data, which can become an unnoticeable privacy leakage channel.
Jiayimei Wang, Ruoqin Tang, Chaoshun Zuo, Lei Xue 0001, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.6
2026 Characterizing Contactless Side-Channel Eavesdropping on Wireless Chargers
abstract
Today, there are an increasing number of smartphones equipped with wireless charging capabilities that use electromagnetic induction to transfer power from a wireless charger to devices that are being charged. In this paper, we unveil a novelcontactlessandcontext-awareside-channel attack in wire less charging, which harnesses two physical phenomena,i.e., the coil whine and the magnetic field perturbations, emanating from the wireless charging process and further infers user interactions on the charging smartphone. To validate the feasibility of this new side channel, we design and implement a three-stage attack framework, dubbed WISERS+, that first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to builduser interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of our proposed attacks with different commercial-off-the-shelf (COTS) smartphones and wireless chargers. Our evaluation results suggest that WISERS+canachieve over 90.4% accuracy in inferring sensitive information, such as the unlocking passcode on the screen and the launch of mobile apps. In addition, our study also demonstrates that WISERS+ is resilient to several practical impact factors, and presents its potential to be extended to attack the fast charging mode. Finally, we propose effective countermeasures and mitigate threats from the WISERS+ attack.
Tao Ni 0003, Chaoshun Zuo, Jianfeng Li 0006, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.5
2026 E$^{2}$2LLM: Structure-Guided Efficient Inference for LLMs in Distributed Edge-IoT Environments
abstract
Large language models (LLMs) are increasingly deployed in edge computing environments to reduce latency and preserve privacy. However, their inference process presents fundamental challenges for resource-constrained IoT devices. LLM inference involves computationally asymmetric stages: parallelizable prompt processing and sequential token decoding. This asymmetry creates deployment bottlenecks where IoT devices lack capacity for prompt processing while edge nodes suffer from inefficient sequential decoding. This paper presentsE$^{2}$LLM, an efficient distributed inference framework for large language models in heterogeneous edge-IoT environments.E$^{2}$LLMleverages high-capacity edge devices for structural planning and introduces auxiliary lightweight models to generate segment-specific key-value (KV) caches. These minimal inference artifacts enable collaborative parallel decoding across IoT devices without requiring full model instantiation. The framework employs static-dynamic KV cache separation to minimize communication overhead while maintaining semantic coherence through structure-guided coordination. Extensive evaluation on realistic edge testbeds demonstrates significant performance improvements. Under diverse deployment settings,E$^{2}$LLMachieves 74%–87.7% end-to-end latency reduction compared with several state-of-the-art baselines, while maintaining comparable generation quality; meanwhile, it also delivers a 34.6%–72.2% reduction in communication overhead, improves 9-12 × in energy efficiency. The framework exhibits strong scalability under bandwidth-limited conditions, enabling efficient LLM deployment across heterogeneous edge-IoT environments.
Xingyu Feng 0001, Huanqi Yang, Zhuangzhuang Chen, Chengwen Luo 0001, Zhangbing Zhou, Weitao Xu, Victor C. M. Leung
IEEE Trans. Mob. Comput.7
2026 RFInv: Uncovering Sensitive Data in RF Sensing Systems via Model Inversion
abstract
Deep learning has significantly advanced Radio Frequency (RF) sensing, leading to extensive research and practical applications in both academia and industry. However, these advancements have also introduced potential privacy and security threats to RF sensing data. In this paper, we present RFInv, the first model inversion attack targeting deep learning classifier-empowered RF sensing systems. RFInv can recover users' private sensing data without knowledge of the RF sensing model's structure, relying solely on the output prediction vector of the deep learning classifier. Consequently, this recovered sensitive data can be exploited for malicious purposes such as identity impersonation and unauthorized device control. To realize the proposed attack, we develop a deep generative adversarial network that integrates an inversion module and a critic module, enabling effective RF data recovery in black-box scenarios. To address the unique challenge of preserving physical consistency in RF data, we incorporate attention mechanisms and deformable convolutions to model their complex temporal and spatial dynamics, ensuring physical consistency. Furthermore, a spectrogram alignment loss is introduced to further enhance reconstruction accuracy. The network is trained using an auxiliary dataset, circumventing the need for access to the target model's training data. We systematically evaluate our proposed attack across multiple datasets for various RF sensing tasks and target models with different network architectures. Extensive experiments demonstrate that RFInv can recover diverse types of RF privacy data with an average Structural Similarity Index Measure (SSIM) of 0.78 and achieves an 86.21% Relative Attack Success Rate (RASR).
Mingda Han, Huanqi Yang, Yanni Yang 0003, Yetong Cao, Weitao Xu, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Mob. Comput.6
2026 SwiftChannel: Algorithm-Hardware Co-Design for Deep Learning-Based 5G Channel Estimation
abstract
Channel estimation is crucial in 5G communication networks for optimizing transmission parameters and ensuring reliable, high-speed communication. However, the use of multiple-input and multiple-output (MIMO) and millimeter-wave (mmWave) in 5G networks presents challenges in achieving accurate estimation under strict latency requirements on resource-limited hardware platforms. To address these challenges, we proposeSwiftChannel, an algorithm-hardware co-design framework that integrates a hardware-friendly deep learning-based channel estimator with a dedicated accelerator. Our approach employs a convolutional neural network enhanced with a parameter-free attention mechanism, which effectively reconstructs full-resolution spatial-frequency domain channel matrices from low-resolution least squares (LS) estimates. We further develop a multi-stage model compression pipeline combining knowledge distillation, convolution re-parameterization, and quantization-aware training, resulting in substantial model size reduction with negligible accuracy loss. The hardware accelerator, implementing the compressed model and the LS estimator on FPGA platforms using High-level Synthesis (HLS), features a fine-grained pipeline architecture and optimized dataflow strategies. Tested on a Zynq UltraScale+ RFSoC, the accelerator achieves sub-millisecond latency, providing up to 24x speed-up and over 33x improvement in energy efficiency compared to GPU-based solutions. Extensive evaluations demonstrate that the proposed design generalizes not only across various noise levels and user mobilities, but also to a variety of unseen channel profiles, outperforming state-of-the-art baselines. By unifying algorithmic innovation with hardware-aware design, our work presents a future-proof channel estimation solution for 5G MIMO systems. The source codes for the dataset synthesis, deep learning algorithm, and HLS-based FPGA design are accessible via GitHub.
Shengzhe Lyu, Yuhan She, Di Duan, Tao Ni 0003, Yu Hin Chan, Chengwen Luo 0001, Ray C. C. Cheung, Weitao Xu
IEEE Trans. Mob. Comput.8
2026 Chirp-Level Information-Based Collaborative Key Generation for LoRa Networks via Perturbed Compressed Sensing
abstract
Physical-layer key generation holds significant potential in establishing cryptographic key pairs for emerging LoRa networks. Nevertheless, current key generation solutions may underperform due to critically impaired channel reciprocity, attributed to the low data rate and long range inherent in LoRa networks. In this study, we presentChirpKey, a novel key generation scheme for LoRa networks. We pinpoint the key hurdles as the coarse-grained channel measurement, inefficient quantization methods, and out-of-range device constraints. To capture fine-grained channel information, we introduce a unique, LoRa-specific channel measurement method that focuses on analyzing chirp-level variations in LoRa packets. We also propose a LoRa channel state estimation algorithm to neutralize asynchronous channel sampling. Instead of the traditional quantization approach, we propose an innovative key delivery method based on perturbed compressed sensing, offering enhanced robustness and security. For LoRa devices beyond each other's communication reach, we integrate relay nodes to ensure reliable key generation. To foster secure group communication, we formulate two protocols that facilitate collaborative key generation across both star and chain configurations. Evaluation across diverse real-world scenarios reveals thatChirpKeyenhances the key matching rate by 11.03–26.58% and increases the key generation rate by 27–49× in comparison to existing leading systems. Our security analysis shows thatChirpKeycan effectively withstand a variety of prevalent attacks. Furthermore, we implement aChirpKeyprototype, demonstrating its capability to operate within 0.2 s.
Huanqi Yang, Zehua Sun, Hongbo Liu 0002, Xianjin Xia, Yu Zhang 0093, Tao Gu 0001, Gerhard P. Hancke 0002, Weitao Xu
IEEE Trans. Mob. Comput.8
2026 Enhancing Throughput in Sharded Blockchain via Joint Convex Optimization of System Parameters and Resource Allocation
Fukang Deng, Tengcong Jiang, Weitao Xu, Yuezhong Wu, Xing Chen 0002, Jie Li 0002
IEEE Trans. Netw. Serv. Manag.4
2025 iRadar: Synthesizing Millimeter-Waves from Wearable Inertial Inputs for Human Gesture Sensing
Huanqi Yang, Mingda Han, Di Duan, Tianxing Li 0001, Weitao Xu
INFOCOM6
2025 SpaceSched: A Constellation-Wide Scheduling System for Resolving Ground Track Congestion in Remote Sensing
abstract
The recent proliferation of spacecraft in Earth's orbits has ushered in the rise of large-scale satellite constellations. However, this unprecedented growth of constellations has introduced a previously unforeseen challenge: ground track congestion. Specifically, the increasing density of orbital slots forces satellites to share similar orbit planes, causing their nadir-point projections on Earth's surface (i.e., ground tracks) to overlap or remain in close proximity within short time intervals. Such orbit-endowed ground track congestion can degrade constellation performance in remote sensing operations, specified by limited constellation coverage, redundant satellite count, and delayed data delivery.
Zehua Sun, Tao Ni 0003, Pengfei Hu 0001, Tao Gu 0001, Weitao Xu
MobiCom5
2025 Beyond Models! Explainable Data Valuation and Metric Adaption for Recommendation
abstract
User behavior records serve as the foundation for recommender systems. While the behavior data exhibits ease of acquisition, it often suffers from varying quality. Current methods employ data valuation to discern high-quality data from low-quality data. However, they tend to employ blackbox design, lacking transparency and interpretability. Besides, they are typically tailored to specific evaluation metrics, leading to limited generality across various tasks. To overcome these issues, we propose an explainable and versatile framework DVR which can enhance the efficiency of data utilization tailored to any requirements of the model architectures and evaluation metrics. For explainable data valuation, a data valuator is presented to evaluate the data quality via calculating its Shapley value from the game-theoretic perspective, ensuring robust mathematical properties and reliability. In order to accommodate various evaluation metrics, including differentiable and non-differentiable ones, a metric adapter is devised based on reinforcement learning, where a metric is treated as the reinforcement reward that guides model optimization. Extensive experiments conducted on various benchmarks verify that our framework can improve the performance of current recommendation algorithms on various metrics including ranking accuracy, diversity, and fairness. Specifically, our framework achieves up to 34.7% improvements over existing methods in terms of representative NDCG metric. The code is available at https://github.com/renqii/DVR.
Renqi Jia, Xiaokun Zhang 0001, Bowei He, Qiannan Zhu, Weitao Xu, Jiehao Chen, Chen Ma 0001
SDM5
2025 Argus: Multi-View Egocentric Human Mesh Reconstruction Based on Stripped-Down Wearable mmWave Add-on
abstract
In this paper, we propose Argus, a wearable add-on system based on stripped-down (i.e., compact, lightweight, low-power, limited-capability) mmWave radars. It is the first to achieve egocentric human mesh reconstruction in a multi-view manner. Compared with conventional frontal-view mmWave sensing solutions, it addresses several pain points, such as restricted sensing range, occlusion, and the multipath effect caused by surroundings. To overcome the limited capabilities of the stripped-down mmWave radars (with only one transmit antenna and three receive antennas), we tackle three main challenges and propose a holistic solution, including tailored hardware design, sophisticated signal processing, and a deep neural network optimized for high-dimensional complex point clouds. Extensive evaluation shows that Argus achieves performance comparable to traditional solutions based on high-capability mmWave radars, with an average vertex error of 6.5 cm, solely using stripped-down radars deployed in a multi-view configuration. It presents robustness and practicality across conditions, such as with unseen users and different host devices.
Di Duan, Shengzhe Lyu, Mu Yuan, Hongfei Xue, Tianxing Li 0001, Weitao Xu, Kaishun Wu, Guoliang Xing
SenSys6
2025 RingByte: Enhancing Text-Entry Practicality via A Singular Wearable Rotating Smart Ring
Rucheng Wu, Tao Ni 0003, Zehua Sun, Jiande Sun 0001, Weitao Xu
UIST5
2025 Real-time task dispatching and scheduling in serverless edge computing
abstract
Edge computing brings computing resources closer to the Internet of Things (IoT) devices, significantly reducing transmission latency and bandwidth usage. However, the limited resources of edge servers require efficient management. Serverless computing meets this demand through its elastic resource provisioning , leading to the emergence of serverless edge computing—a promising computing paradigm . Despite its potential, real-time task dispatching and scheduling in the highly complex and dynamic environment of serverless edge computing present significant challenges. On the one hand, task execution requires not only sufficient CPU resources but also free containers; on the other hand, tasks are typically event-driven, with strong burstiness and high concurrency, and impose stringent demands on fast decision-making. To address these challenges, we propose a real-time task dispatching and scheduling method, aiming to maximize the satisfaction rate of Service Level Objectives (SLOs) for tasks. First, we design a task dispatching algorithm named Adaptive Deep Reinforcement Learning (ADRL). This algorithm can quickly decide the execution position of tasks based on coarse information and effectively adapt to the changes in available servers in dynamic environments. Second, we propose a task scheduling algorithm named Warm-aware Shortest Remaining Idle Time (WSRIT), which guides the edge servers to schedule the tasks in the request queue based on the tasks’ remaining idle time and the state of the warm containers. Considering the limited storage space of the edge servers, we further introduce a container replacement algorithm named Low Priority First (LPF) to ensure smooth container launches. Extensive simulation experiments are conducted based on Azure datasets. The results show that our methodcan improve the satisfaction rate of SLOs by 12.57 ∼ 41.87% and achieve the lowest cold start rate compared to existing methods.
Furong Xu, Yuqin Wu, Jianshan Zhang, Weitao Xu, Yuezhong Wu
Ad Hoc Networks5
2025 SLwF: A Split Learning Without Forgetting Framework for Internet of Things
abstract
Split learning (SL) is widely regarded as a promising distributed machine learning framework with superior privacy-preserving properties, lower communication and computation costs. However, in real Internet of Things (IoT) scenarios, existing SL may not perform well because the local data of IoT devices often do not follow the same distribution. This leads to the model continuously adapting to the current data distribution in each training epoch, resulting in a catastrophic forgetting phenomenon. Existing methods typically attempt to add raw or generated data from previous devices in the current training epoch to review knowledge, but direct access to the local data of other devices carries serious privacy risks. Data augmentation techniques based on generative networks often have poor robustness and increase the computation cost on the device side. To address these challenges, we propose a new SL framework called SL without Forgetting (SLwF). To mitigate catastrophic forgetting without accessing any previous data, we propose a contrastive learning-based training method that leverages current training data to review previous knowledge, and learn new knowledge better. Furthermore, we adopt an exponential moving average (EMA)-based model update strategy to preserve lost knowledge, further alleviating the forgetting problem. We implement the SLwF framework in real IoT scenarios and extensively evaluated its performance using four publicly available datasets. Compared to other related research (e.g., IoTSL), SLwF performs better in terms of final accuracy and robustness while avoiding excessive device energy consumption.
Xingyu Feng 0001, Renqi Jia, Chengwen Luo 0001, Victor C. M. Leung, Weitao Xu
IEEE Internet Things J.5
2025 Multi-Modal Autonomous Ultrasound Scanning for Efficient Human-Machine Fusion Interaction
abstract
Robotic autonomous ultrasound imaging is a challenging task as robots require strong analytical capabilities to make sound decisions in complex spatial relationships. In this paper, we integrate visual and tactile information into the ultrasound robotic system drawing inspiration from the process of human doctors conducting ultrasound scans, and explore the impact of different modalities of information on our task. The proposed multimodal deep reinforcement learning (DRL) framework can integrate real-time visual feedback and tactile perception, and directly output 6D pose decisions to control the ultrasound probe, thereby achieving fully autonomous ultrasound imaging of soft, movable, and unmarked targets. We demonstrate the feasibility of our method on a simulation platform and propose an effective model transfer learning method. Subsequently, we conducted further evaluations of the approach in a real-world environment. The results indicate that our approach effectively enhances the performance of autonomous ultrasound scanning and manual adjustments further optimize the outcomes.Note to Practitioners—This work is motivated by the increasing demand for intelligent human-machine interaction in medical applications. By improving the automation of traditional medical scanning procedures such as ultrasound scanning, the efficiency of medical scanning can be greatly improved. In this work, we propose a multi-modal autonomous ultrasound scanning system based on DRL, which can be applied to improve the efficiency of human-machine interaction in medical environments to execute daily health screening or used in emergency situations.
Chengwen Luo 0001, Haozheng Cao, Mustafa A. Al Sibahee, Weitao Xu, Jin Zhang 0013
IEEE Trans Autom. Sci. Eng.5
2025 LLM-CoSen: Revisiting Collaborative Sensing With Large Language Models (LLMs)
abstract
Collaborative sensing has emerged as a novel sensing paradigm, entailing multi-sensor data sharing and multimodal modeling to collaboratively understand sensing behaviors. However, current solutions, i.e., data-level and decision-level fusion methods, fall short of generality, expert knowledge, and holistic/chronic perspective. In this paper, we proposeLLMCoSento revisit collaborative sensing with Large Language Models (LLMs). Specifically,LLM-CoSendesigns a semantic-level fusion approach for inference results for collaborative sensing. Such an approach is characterized by its generality, making it applicable to any heterogeneous devices, and its expert knowledge incorporation, which provides chronic, holistic, and insightful perspectives on the inference results. Regarding inference absence challenges, we propose a personalized model design method to constrain inference time, and a voting-based two-pass prompt engineering strategy for token completion. Regarding inference error challenges, we propose an accuracy restoration strategy for personalized models, and a two-level error estimator coupled with self-correction. Experimental results of human digital system use case on four corresponding benchmark datasets showLLM-CoSencan decrease inference absence by 72.83% and inference errors by 7.65% on average.
Xingyu Feng 0001, Zehua Sun, Zhuangzhuang Chen, Chengwen Luo 0001, Zhangbing Zhou, Victor C. M. Leung, Weitao Xu
IEEE Trans. Mob. Comput.7
2025 LaserKey: Eavesdropping Keyboard Typing Leveraging Vibrational Emanations via Laser Sensing
abstract
Reconstructing keyboard input through side-channel attacks has posed significant threats to user security. While conventional keystroke eavesdropping attacks have demonstrated effectiveness using side channels such as acoustic signals, they are usually shorter in range and can be significantly affected by environmental noises. In this paper, we proposeLaserKey, a novel keystroke eavesdropping technique that leverages the long-range and noise-resistant nature of lasers to achieve a more stealthy side-channel attack. We utilize laser sensors to accurately capture the subtle vibrations induced on laptop screens by keystrokes, and innovatively design a laser-driven deep learning-based keystroke recognition model with the inputs being the Mel-frequency Cepstral Coefficien (MFCC), Time Difference of Arrival (TDoA), and amplitude features extracted from such vibration signals. Through systematic experiments, we demonstrate thatLaserKeyachieves a 92.2% single-key recognition accuracy. By combining multiple single-key recognition capabilities based on this, we then realize the end-to-end word-level recognition. Moreover, to mitigate the recognition errors caused by the changes in keystroke positions, we introduce a meta-learning based domain generalization approach for achieving robust laser position calibration. Results show thatLaserKeyachieves as low as 3% character error rate (CER) for word-level recognition, proving its effectiveness for long-range and high-accuracy keystroke eavesdropping, and highlighting the necessity for countermeasures in the future.
Chengwen Luo 0001, Zhuoqing Xie, Gecheng Chen, Haiyi Yao, Jin Zhang 0013, Long Cheng 0005, Weitao Xu, Jianqiang Li 0001
IEEE Trans. Mob. Comput.8
2025 When Good Becomes Evil: Exploring Crosstalk Attack Surfaces on Multi-Port USB Chargers
abstract
Multi-port chargers, designed to simultaneously charge multiple mobile devices such as smartphones, have gained significant popularity, with millions of units sold in recent years. However, this multi-device charging feature introduces security and privacy risks. If not properly designed and implemented, these chargers can enable communication between connected devices because they are inherently interconnected, which leads to crosstalk voltage leakages. Despite their widespread use, these risks have not been thoroughly investigated. We have identified novel attack surfaces in the circuit design of multi-port chargers that allow an adversary who shares the multi-port charger with the target victim in close proximity to exploit one port to (i) recognize fine-grained user activities of other devices being charged, (ii) eavesdrop on secret audio transmission from USB-C audio pins, and (iii) inject malicious audio commands into built-in voice assistants of charging devices (e.g., Siri, Google Assistant). In this paper, we design and implement XPORTHEFT, a novel system to analyze and demonstrate the uncovered security and privacy threats in multi-port chargers. Specifically, it leverages changes in voltage signals in one neighbor port to monitor voltage changes in the charging port induced by user activities in various user interfaces, such as recognizing running apps and detecting keystrokes. Moreover, XPORTHEFT can also achieve audio transmission eavesdropping and launch inaudible audio injection attacks from the neighbor port to the charging mobile device via the USB-C interface. We extensively evaluate the effectiveness of XPORTHEFT using five commercial multi-port chargers and five mobile devices. The evaluation results show its high effectiveness in recognizing the launch of 20 mobile apps (88.7%) and revealing unlocking passcodes (98.8%), as well as eavesdropping on the audios of numeric digits (97.1%) and alphabetic characters (98.0%). Furthermore, XPORTHEFT achieves 100% success rates in inaudible audio injection attacks on three commercial voice assistants. In addition, our study also shows that XPORTHEFT is resilient to various impact factors and presents the potential to attack multiple victims.
Tao Ni 0003, Zehua Sun, Yihe Zhou, Jiayimei Wang, Weitao Xu, Qingchuan Zhao, Cong Wang 0001
IEEE Trans. Mob. Comput.6
2024 Optimal Power Control for Over-the-Air Federated Learning with Gradient Compression
abstract
Federated Learning (FL) has emerged as a transformative approach in distributed machine learning, enabling the collaborative training of models using decentralized datasets from diverse sources such as mobile edge devices. This paradigm not only enhances data privacy but also significantly reduces the communication burden typically associated with centralized data aggregation. In wireless networks, Over-the-air Federated Learning (OTA-FL) has been developed as a communication-efficient solution, allowing for the simultaneous transmission and aggregation of model updates from numerous edge devices across the available bandwidth. Gradient compression techniques are necessary to further enhance the communication efficiency of FL, particularly in bandwidth-constrained wireless environments. Despite these advancements, OTA-FL with gradient compression encounters substantial challenges, including learning performance degradation due to compression errors, non-uniform channel fading, and noise interference. Existing power control strategies have yet to fully address these issues, leaving a significant gap in optimizing OTA-FL performance under gradient compression. This paper introduces a novel power control strategy that coordinately integrates gradient compression to optimize OTAFL performance by minimizing the impact of channel fading and noise. Our approach employs linear approximations to complex terms, ensuring the stability and effectiveness of each gradient descent iteration. Numerical results demonstrate that our strategy significantly enhances convergence rates compared to traditional methods like channel inversion and uniform power transmission. This research advances the OTA-FL field and opens new avenues for performance tuning in communication-efficient federated learning systems.
Mengzhe Ruan, Weizhou Zhang, Linqi Song, Weitao Xu
ICPADS5
2024 Poster Abstract: Uncovering Mobile User Gait Patterns Through Contactless RF Channels
abstract
Gait-based authentication has risen to prominence for its distinctive advantages, becoming an essential security mechanism for mobile devices. These devices typically employ Inertial Measurement Units (IMUs) to capture intricate gait patterns for confirming the identity of users. However, our research highlights a vulnerability: the user’s gait data on mobile devices is susceptible to interception through a radio frequency (RF) side-channel, potentially allowing unauthorized access. We introduce Gait-Snoop as aproof-of-concept for this novel side-channel attack. Gait-Snoop utilizes the RF signals reflected during a user’s walk to extract gait information. It then correlates these RF signal patterns with IMU-derived gait data and employs a robotic arm to replicate the gait, aiming to deceive and unlock the targeted mobile devices. Our comprehensive evaluation of Gait-Snoop on smartphones demonstrates its capability to mimic IMU gait signals, underscoring the effectiveness and potential risks of such side-channel attacks.
Huanqi Yang, Jiahuan Chen, Mingda Han, Weitao Xu
IPSN5
2024 RF-Egg: An RF Solution for Fine-Grained Multi-Target and Multi-Task Egg Incubation Sensing
abstract
Eggs and chickens serve as crucial animal-source proteins in our diets, making large-scale breeding egg incubation an essential undertaking. However, current solutions, i.e., vision-based and sensor-based methods, are primarily designed for egg fertility detection tasks under single-egg settings, which have not yet satisfied the goal of multi-target and multi-task sensing. In this paper, we propose RF-Egg, the first RF-based fine-grained multi-target and multi-task egg incubation sensing system with respect to sensing fertility, incubation status, and early mortality of chicken embryos. RF-Egg leverages the weak coupling effects of RFID tags when interacting with eggs, which induces different impedance changes of RFID tags with the incubation levels of eggs, thereby resulting in a variation of low-level phase readings of the backscatter signals. Regarding the challenge of multi-target profiling interference, we propose a multipath combating algorithm to extract the target-induced signal component based on the built signal model, and address non-uniformity issues across multiple tags. Moreover, we devise three unique feature maps tailored to each task, and then design an Multi-Task Triplet (MTT) network for multitasking. Our evaluation results based on 189 eggs show that RF-Egg achieves an accuracy of 94.4%, 96.1%, and 90.1% for the aforementioned three tasks when supporting 16 targets. Additionally, our extensive field study in a local egg hatchery suggests that RF-Egg presents the potential to be widely deployed in the modern poultry industry.
Zehua Sun, Tao Ni 0003, Di Duan, Kai Liu 0008, Weitao Xu
MobiCom6
2024 TransCompressor: LLM-Powered Multimodal Data Compression for Smart Transportation
abstract
The incorporation of Large Language Models (LLMs) into smart transportation systems has paved the way for improving data management and operational efficiency. This study introduces TransCompressor, a novel framework that leverages LLMs for efficient compression and decompression of multimodal transportation sensor data. TransCompressor has undergone thorough evaluation with diverse sensor data types, including barometer, speed, and altitude measurements, across various transportation modes like buses, taxis, and Mass Transit Railways (MTRs). Comprehensive evaluation illustrates the effectiveness of TransCompressor in reconstructing transportation sensor data at different compression ratios. The results highlight that, with well-crafted prompts, LLMs can utilize their vast knowledge base to contribute to data compression processes, enhancing data storage, analysis, and retrieval in smart transportation settings.
Huanqi Yang, Rucheng Wu, Weitao Xu
MobiCom3
2024 REHSense: Towards Battery-Free Wireless Sensing via Radio Frequency Energy Harvesting
abstract
Diverse Wi-Fi-based wireless applications have been proposed, ranging from daily activity recognition to vital sign monitoring. Despite their remarkable sensing accuracy, the high energy consumption and the requirement for customized hardware modification hinder the wide deployment of the existing sensing solutions. In this paper, we propose REHSense, an energy-efficient wireless sensing solution based on Radio-Frequency (RF) energy harvesting. Instead of relying on a power-hungry Wi-Fi receiver, REHSense leverages an RF energy harvester as the sensor and utilizes the voltage signals harvested from the ambient Wi-Fi signals to enable simultaneous context sensing and energy harvesting. We design and implement REHSense using a commercial-off-the-shelf (COTS) RF energy harvester. Extensive evaluation of three fine-grained wireless sensing tasks (i.e., respiration monitoring, human activity recognition, and hand gesture recognition) shows that REHSense can achieve comparable sensing accuracy with conventional Wi-Fi-based solutions while adapting to different sensing environments, reducing the power consumption of sensing by 98.7% and harvesting up to 4.5 mW of power from RF energy.
Tao Ni 0003, Zehua Sun, Mingda Han, Yaxiong Xie, Guohao Lan, Zhenjiang Li 0001, Tao Gu 0001, Weitao Xu
MobiHoc8
2024 F2Key: Dynamically Converting Your Face into a Private Key Based on COTS Headphones for Reliable Voice Interaction
abstract
In this paper, we proposed F2Key, the first earable physical security system based on commercial off-the-shelf headphones. F2Key enables impactful applications, such as enhancing voiceprint-based authentication systems, reliable voice assistants, audio deepfake defense, and the legal validity of artifacts. The key idea of F2Key is to establish a stable acoustic sensing field across the user's face and embed the user's facial structures and articulatory habits into a user-specific generative model that serves as a private key. The private key can decrypt the Channel Impulse Response (CIR) profiles provided by the acoustic sensing field into an inferred spectrogram that can match the real one calculated from the corresponding speech, provided that the user's CIR-spectrogram mapping relationship is consistent with the one embedded in the generative model. Extensive experiments demonstrate that F2Key resists 99.9%, 96.4%, and 95.3% of speech replay attacks, mimicry attacks, and hybrid attacks, respectively. We discussed and evaluated F2Key from different perspectives, such as the health consideration and identical twins study, to show the practicality and reliability.
Di Duan, Zehua Sun, Tao Ni 0003, Shuaicheng Li 0001, Xiaohua Jia, Weitao Xu, Tianxing Li 0001
MobiSys6
2024 Hygiea+: Toward Energy-Efficient and Highly Accurate Toothbrushing Monitoring via Wrist-Worn Gesture Sensing
abstract
Proper and effective toothbrushing technique is crucial for maintaining oral health. However, there are often limited opportunities for individuals to receive specific training in toothbrushing posture in their daily lives. In this article, we propose Hygiea+, a convenient, energy-efficient, and highly accurate toothbrushing monitoring system based on wrist-worn wearables. By leveraging inertial measurement units (IMUs) in wrist-worn devices for gesture sensing, Hygiea+ enables users to accurately and efficiently monitor their toothbrushing activities without any modifications to the toothbrush. We propose a number of novel techniques to achieve the goal of high sensing accuracy and energy efficiency. To reduce the energy consumption of continuous IMU sampling, we model the sensing problem as a Markov process and design a partially observable Markov decision process (POMDP)-based adaptive sampling strategy to dynamically adjust the sampling frequency. To achieve high sensing accuracy, we first propose a novel signal preprocessing method to mitigate variations resulting from different toothbrush types and user habits. Then, we propose a deep reinforcement learning-based data distillation mechanism to extract key segments from continuous toothbrushing actions, thus reducing the impact of redundant data and noise. In the classification stage, we design an attention-based long short-term memory (AT-LSTM) network for fine-grained toothbrushing posture recognition. In addition, to address the accuracy degradation of new users, we adopt the common but effective fine-tuning method to alleviate the data collection burden on new users. Finally, we connect advanced large language models (LLMs) to provide users with necessary feedback on toothbrushing behavior and health recommendations. Extensive experiments using both manual and electric toothbrushes demonstrate Hygiea+ achieves up to 98.8% accuracy in toothbrushing posture recognition while maintaining superior energy efficiency.
Xingyu Feng 0001, Chengwen Luo 0001, Junliang Chen 0002, Jianqiang Li 0001, Zahir Tari, Weitao Xu
IEEE Internet Things J.7
2024 VibMilk: Nonintrusive Milk Spoilage Detection via Smartphone Vibration
abstract
Quantifying the chemical process of milk spoilage is challenging due to the need for bulky, expensive equipment that is not user-friendly for milk producers or customers. This lack of a convenient and accurate milk spoilage detection system can cause two significant issues. First, people who consume spoiled milk may experience serious health problems. Secondly, milk manufacturers typically provide a “best before” date to indicate freshness, but this date only shows the highest quality of the milk, not the last day it can be safely consumed, leading to significant milk waste. A practical and efficient solution to this problem is proposed in this paper: a vibration-based milk spoilage detection method called VibMilk that utilizes the ubiquitous vibration motor and Inertial Measurement Unit (IMU) of off-the-shelf smartphones. The method detects spoilage based on the fact that the milk’s physical properties change, inducing different vibration responses at various stages of degradation. Using the InceptionTime deep learning model, VibMilk achieves 98.35% accuracy in detecting milk spoilage across 23 different stages, from fresh (pH = 6.6) to fully spoiled (pH = 4.4).
Yuezhong Wu, Dong Ma 0001, Weitao Xu, Mahbub Hassan, Wen Hu 0001
IEEE Internet Things J.5
2024 Medusa3D: The Watchful Eye Freezing Illegitimate Users in Virtual Reality Interactions
abstract
The remarkable growth of Virtual Reality (VR) in recent years has extended its applications beyond entertainment to sectors including education, e-commerce, and remote communication. Since VR devices contain user's private information, user authentication becomes increasingly important. Current authentication systems in VR, such as password-based or static biometric-based methods, are either cumbersome to use or vulnerable to attacks such as shoulder surfing. To address these limitations, we propose Medusa3D, a challenge-response authentication system for VR based on reflexive eye responses. Unlike existing methods, reflexive eye responses are involuntary and effortless, offering a secure and user-friendly credential for authentication. We implement Medusa3D on an off-the-shelf VR and conduct evaluations with 25 participants. The evaluation results show that Medusa3D achieves 0.21% FAR and 0.13% FRR, demonstrating high security under various ocular conditions and resilience against attacks such as zero-effort attack, replay attack, and mimicry attack. A user study indicates that Medusa3D is user-friendly and well-adopted among participants.
Aochen Jiao, Di Duan, Weitao Xu
Proc. ACM Hum. Comput. Interact.3
2024 Seeing the Invisible: Recovering Surveillance Video With COTS mmWave Radar
abstract
Video surveillance systems play a crucial role in ensuring public safety and security by capturing and monitoring critical events in various areas. However, traditional surveillance cameras face limitations when it comes to malicious physical damage or obscuring by offenders. To overcome this limitation, we proposem$^{2}$2Vision, which is the first millimeter-wave (mmWave)-based video reconstruction system designed to enhance existing video surveillance cameras.m$^{2}$2Visionutilizes mmWave to sense the profile and motion signature of the target, integrating it with previously acquired visual data about the environment and the target's appearance, thereby facilitating the reconstruction of surveillance video. Specifically, our proposed system incorporates a dual-stage mmWave signal denoising algorithm to efficiently eliminate the noise and multiple-input multiple-output virtual antenna enhanced heatmap generation (MVAE-HG) method to obtain fine-grained mmWave heatmaps responsive to the target's profile and motion information. Moreover, we design the mm2Video generative network that first employs a multi-modal fusion module to fuse the mmWave and pre-acquired visual data, then use a conditional generative adversarial network (cGAN)-based video reconstruction module for surveillance video reconstruction. We conducted comprehensive experiments onm$^{2}$2Visionusing a commercial mmWave radar and four surveillance cameras across various environments, with the participation of seven individuals. Evaluation results show thatm$^{2}$2Visioncan achieve an average structural similarity index measure (SSIM) of 0.93, demonstrating its effectiveness and potential.
Mingda Han, Huanqi Yang, Mingda Jia, Weitao Xu, Yanni Yang 0003, Zhijian Huang 0002, Jun Luo 0001, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Mob. Comput.4
2024 Enhancing the Applicability of Sign Language Translation
abstract
This paper addresses a significant problem in American Sign Language (ASL) translation systems that has been overlooked. Current designs collect excessive sensing data for each word and treat every sentence as new, requiring the collection of sensing data from scratch. This approach is time-consuming, taking hours to half a day to complete the data collection process for each user. As a result, it creates an unnecessary burden on end-users and hinders the widespread adoption of ASL systems. In this study, we identify the root cause of this issue and proposeGASLA–a wearable sensor-based solution that automatically generates sentence-level sensing data from word-level data. An acceleration approach is further proposed to optimize the data generation speed. Moreover, due to the gap between the generated sentence data and directly collected sentence data, a template strategy is proposed to make the generated sentences more similar to the collected sentence. The generated data can be used to train ASL systems effectively while reducing overhead costs significantly.GASLAoffers several benefits over current approaches: it reduces initial setup time and future new-sentence addition overhead; it requires only two samples per sentence compared to around ten samples in current systems; and it improves overall performance significantly.
Jiao Li 0002, Jiakai Xu, Yang Liu 0101, Weitao Xu, Zhenjiang Li 0001
IEEE Trans. Mob. Comput.4
2024 FaceFinger: Embracing Variance for Heartbeat Based Symmetric Key Generation System
abstract
Symmetric key generation methods are recently designed for wireless communication based on similar and unique observations of sensor measurements, such as wireless radio channels, inaudible sound channels, etc. Heartbeats, as unique biometrics, have been used for symmetric key generation. However, current solutions are designed for wearable devices with the integration of the same types of touchable heartbeat measurement equipment and fail because of the significant difference from different devices or the same devices with different deployment locations, which limits its large scale of deployment and application. To solve this problem, we propose a general heartbeat-based symmetric key generation solution by embracing observation variance from different devices, i.e., using an optical heart sensor on one finger and facing the camera of the second device to the user's face. We propose a novel data processing method to mitigate the significant difference and exploit key reconciliation to generate symmetric keys for paring devices and securing wireless communication. We have conducted extensive evaluations and shown our proposed method has good key matching rates up to 100% as well as good randomness. Security analysis has also been conducted to ensure the robustness of the proposed method.
Bo Wei 0003, Weitao Xu, Chengwen Luo 0001, Jin Zhang 0013
IEEE Trans. Mob. Comput.2
2024 WashRing: An Energy-Efficient and Highly Accurate Handwashing Monitoring System via Smart Ring
abstract
The outbreak of COVID-19 has greatly changed everyone's lifestyle all over the world. One of the best ways to prevent the spread of infections is by washing hands properly. Although a number of hand hygiene monitoring systems have been proposed, they either cannot achieve high accuracy in practice or work only in limited environments such as hospitals. Therefore, a ubiquitous, energy-efficient and highly accurate hand hygiene monitoring system is still lacking. In this paper, we presentWashRing—the first smart ring-based handwashing monitoring system. In WashRing, we design a Partially Observable Markov Decision Process (POMDP) based adaptive sampling approach to achieve high energy efficiency. Then, we design an automatic feature extraction scheme based on wavelet scattering and a CNN-LSTM neural network to achieve fine-grained gesture recognition. Finally, we model the handwashing gesture classification as a few-shot learning problem to mitigate the burden of collecting extensive data from five fingers. We collect data from 25 subjects over 2 months and evaluate the system performance on both commercial OURA ring and customized ring. Evaluation results show that WashRing achieves 97.8% accuracy which is 10.2%–15.9% higher than state-of-the-arts. Our adaptive sampling approach reduces energy consumption by 64.2% compared to fixed duty cycle sampling strategies.
Weitao Xu, Huanqi Yang, Jiongzhang Chen, Chengwen Luo 0001, Jia Zhang 0028, Yuliang Zhao, Wen Jung Li
IEEE Trans. Mob. Comput.1
2024 Scenario-Adaptive Key Establishment Scheme for LoRa-Enabled IoV Communications
abstract
In recent years, the Internet of Vehicles (IoV) has experienced significant growth, but the lack of effective secret key establishment remains a security concern due to the dynamic and ad-hoc nature of IoV communications. Physical layer key generation has emerged as a promising solution for establishing a pair of cryptographic keys in a lightweight and information-theoretic secure manner. However, previous works have primarily focused on legacy communication technologies, such as Wi-Fi, ZigBee, and 5 G, which are limited to short-range IoV communications. With the emergence of Long-range (LoRa) communication technology, which features long-range, low power, and extremely low data rates, new challenges arise for key generation in long-range IoV scenarios. This paper presentsVehicle-Key, a secret key generation system designed to secure LoRa-enabled IoV communications.Vehicle-Keypresents an innovative scenario adaptive deep learning model that performs channel prediction and quantization concurrently while reducing the training cost through a data augmentation pipeline and enhancing the model's generalization using a domain-adaption method. Additionally, we propose a bloom filter-assisted autoencoder-based reconciliation method to significantly improve the key agreement rate. Comprehensive real-world experiments show thatVehicle-Keysurpasses the State-of-the-Art, achieving a 15.26%–50.35% improvement in key agreement rate and a 9–15× increase in key generation rate. Moreover, the proposed method attains a 4.37--9.33% improvement when adapted to new scenarios with limited data sizes. A security analysis demonstrates thatVehicle-Keyis resilient against several common attacks. Furthermore, we implementVehicle-Keyon a Raspberry Pi and demonstrate its ability to execute within 3.5 ms.
Huanqi Yang, Di Duan, Hongbo Liu 0002, Chengwen Luo 0001, Yuezhong Wu, Wei Li 0058, Albert Y. Zomaya, Linqi Song, Weitao Xu
IEEE Trans. Mob. Comput.9
2024 InaudibleKey2.0: Deep Learning-Empowered Mobile Device Pairing Protocol Based on Inaudible Acoustic Signals
abstract
The increasing proliferation of Internet-of-Things (IoT) devices in daily life has rendered secure Device-to-Device (D2D) communication increasingly crucial. Achieving secure D2D communication necessitates key agreement between various IoT devices without prior knowledge. Despite existing literature proposing numerous approaches, they exhibit limitations such as low key generation rates and short pairing distances. In this paper, we present InaudibleKey2.0, an inaudible acoustic signal based key generation protocol for mobile devices. Based on acoustic channel reciprocity, InaudibleKey2.0 exploits the acoustic channel frequency response of two legitimate devices as a shared secret for key generation. To significantly enhance performance, InaudibleKey2.0 incorporates novel technologies, including a deep learning-enabled channel prediction model for improved channel reciprocity, a quantization model for increased key generation rates, and a transformer-based reconciliation method for augmented key agreement rates. We conduct comprehensive experiments to evaluate InaudibleKey2.0 in diverse real-world environments. In comparison to state-of-the-art solutions, InaudibleKey2.0 achieves 1.3–9.1 times improvement in key generation rates, 3.2–44 times extension in pairing distances, and 1.2–16 times reduction in information reconciliation counts. Security analysis substantiates that InaudibleKey2.0 is resilient to numerous malicious attacks. Furthermore, we implement InaudibleKey2.0 on modern smartphones and resource-limited IoT devices. The results indicate that it is energy-efficient and can operate on both powerful and resource-limited IoT devices without causing excessive resource consumption.
Huanqi Yang, Zhenjiang Li 0001, Chengwen Luo 0001, Bo Wei 0003, Weitao Xu
IEEE/ACM Trans. Netw.5
2024 mmSign: mmWave-based Few-Shot Online Handwritten Signature Verification
abstract
Handwritten signature verification has become one of the most important document authentication methods that are widely used in the financial, legal, and administrative sectors. Compared with offline methods based on static signature images, online handwritten signature verification methods are more reliable because of the temporary dynamic information (e.g., signing velocity, writing force, stroke order) that alleviates the risk of being forged. However, most existing online handwritten signature verification solutions are reliant on specific signing devices (e.g., customized pens or writing pads) and require extensive data collection during the registration phase, resulting in poor adaptability and applicability for new users. In this article, we propose mmSign, a millimeter wave (mmWave)–based online handwritten signature verification system, which enables accurate sensing of the user’s hand movements when signing through the superior sensing capability of mmWave. mmSign extracts the time-velocity feature maps from the captured mmWave signals by the carefully designed signal processing algorithms and then exploits a transformer-based verification model for signature verification. In addition, a novel meta-learning strategy with proposed task generation and data augmentation methods is introduced in mmSign to teach the verification model to learn effectively with limited samples, allowing our model to quickly adapt to new users. Extensive experiments show that mmSign is a robust, efficient, and secure handwritten signature verification system, achieving 84.07%, 87.31%, 91.12%, and 96.54% verification accuracy when 1, 3, 5, and 10 labeled signatures are available, respectively, while being resistant to common forgery attacks.
Mingda Han, Huanqi Yang, Tao Ni 0003, Di Duan, Mengzhe Ruan, Jia Zhang 0028, Weitao Xu
ACM Trans. Sens. Networks8
2024 FLoRa+: Energy-efficient, Reliable, Beamforming-assisted, and Secure Over-the-air Firmware Update in LoRa Networks
abstract
The widespread deployment of unattended LoRa networks poses a growing need to perform Firmware Updates Over-The-Air (FUOTA). However, the FUOTA specifications dedicated by LoRa Alliance fall short of several deficiencies with respect to energy efficiency, transmission reliability, multicast fairness, and security. This article proposes FLoRa+ , energy-efficient, reliable, beamforming-assisted, and secure FUOTA for LoRa networks, which is featured with several techniques, including delta scripting, channel coding, beamforming, and securing mechanisms. Specifically, we first propose a joint differencing and compression algorithm to generate the delta script for processing gain, which unlocks the potential of incremental FUOTA in LoRa networks. Then, we design a concatenated channel coding scheme with outer rateless code and inner error detection to enable reliable transmission for coding gain. Afterward, we develop a beamforming strategy to avoid biased multicast and compromised throughput for power gain. Finally, we present a securing mechanism incorporating progressive hash chain and packet arrival time pattern verification to countermeasure firmware integrity and availability attacks for security gain. Experimental results on a 20-node testbed demonstrate that FLoRa+ improves transmission reliability and energy efficiency by up to 1.51× and 2.65× compared with LoRaWAN. Additionally, FLoRa+ can defend against 100% and 85.4% of spoofing and Denial-of-Service (DoS) attacks.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
ACM Trans. Sens. Networks7
2024 SolarKey: Battery-free Key Generation Using Solar Cells
abstract
Solar cells have been widely used for offering energy for Internet of Things (IoT) devices. Recently, solar cells have also been used as sensors for context awareness sensing due to their sensitivity to varying lighting conditions. In this article, we are the first to use solar cells for symmetric key generation. To generate symmetric keys, we take advantage of photovoltage measurements generated from solar cells equipped with a pair of IoT devices. Symmetric keys are essential for pairing IoT devices and further securing wireless communication. Despite the sensitivity to varying lighting conditions, challenges still remain for the use of solar cells for key generation, such as time unsynchronisation and noisy measurements. To solve these challenges, we design a novel key generation framework, SolarKey, which includes the starting point detection and a compressed sensing-based two-tier key reconciliation method. Extensive experiments have been conducted to evaluate the performance of our proposed key generation method in various environments, which shows the proposed method can improve the key matching rate by up to 25%. We also conduct security analysis and the randomness test, which shows that SolarKey is resilient to common attacks such as the eavesdropping attack and the imitating attack and sufficiently random.
Bo Wei 0003, Weitao Xu, Mingcen Gao, Guohao Lan, Kai Li 0002, Chengwen Luo 0001, Jin Zhang 0013
ACM Trans. Sens. Networks2
2023 Covert Communications Assisted by Reconfigurable Intelligent Surfaces with Discrete Phase Shifts
abstract
This work examines the covert communication performance gain achieved by deploying a reconfigurable intelligent surface (RIS) with discrete phase shifts. To this end, we first analyze the average receive signal power at a legitimate receiver Bob and a warden Willie as a function of the number of RIS reflecting elements$N$and the number of bits$d$for its discrete phase shift levels. Our analysis reveals that Bob's average power is proportional to$N^{2}$and highly depends on$d$, while Willie's average power is proportional to$N$and does not depend on$d$. This leads to the potential of enhancing the system performance via increasing$N$or$d$in the considered covert communications scenario. Specifically, the performance gain is explicitly examined by tackling the transmission outage probability from a transmitter Alice to Bob subject to a covertness constraint based on Willie's detection performance. After analyzing the transmission outage probability and Willie's total detection error rate, we determine Alice's optimal transmit power. Our explicit examination confirms the performance enhancement achieved via increasing$N$or$d$. Furthermore, our analysis shows that the covert communication performance achieved with$d=3$is already sufficiently close to that achieved with$d\rightarrow\infty$. This shows that the major benefits of deploying RIS in covert communications can be achieved by an RIS with low-resolution phase shifts.
Peilin Ren, Jia Zhang 0028, Shihao Yan, Weitao Xu, Jiande Sun 0001, Naofal Al-Dhahir
GLOBECOM4
2023 Adaptive Top- K in SGD for Communication-Efficient Distributed Learning
abstract
Distributed stochastic gradient descent (SGD) with gradient compression has become a popular communication-efficient solution for accelerating distributed learning. One commonly used method for gradient compression is Top-K sparsification, which sparsifies the gradients by a fixed degree during model training. However, there has been a lack of an adaptive approach to adjust the sparsification degree to maximize the potential of the model's performance or training speed. This paper proposes a novel adaptive Top-K in SGD framework that enables an adaptive degree of sparsification for each gradient descent step to optimize the convergence performance by balancing the tradeoff between communication cost and convergence error. Firstly, an upper bound of convergence error is derived for the adaptive sparsification scheme and the loss function. Secondly, an algorithm is designed to minimize the convergence error under the communication cost constraints. Finally, numerical results on the MNIST and CIFAR-10 datasets demonstrate that the proposed adaptive Top-K algorithm in SGD achieves a significantly better convergence rate compared to state-of-the-art methods, even after considering error compensation.
Mengzhe Ruan, Guangfeng Yan, Yuanzhang Xiao, Linqi Song, Weitao Xu
GLOBECOM5
2023 ChirpKey: A Chirp-level Information-based Key Generation Scheme for LoRa Networks via Perturbed Compressed Sensing
abstract
Physical-layer key generation is promising in establishing a pair of cryptographic keys for emerging LoRa networks. However, existing key generation systems may perform poorly since the channel reciprocity is critically impaired due to low data rate and long range in LoRa networks. To bridge this gap, this paper proposes a novel key generation system for LoRa networks, named ChirpKey. We reveal that the underlying limitations are coarse-grained channel measurement and inefficient quantization process. To enable fine-grained channel information, we propose a novel LoRa-specific channel measurement method that essentially analyzes the chirp-level changes in LoRa packets. Additionally, we propose a LoRa channel state estimation algorithm to eliminate the effect of asynchronous channel sampling. Instead of using quantization process, we propose a novel perturbed compressed sensing based key delivery method to achieve a high level of robustness and security. Evaluation in different real-world environments shows that ChirpKey improves the key matching rate by 11.03–26.58% and key generation rate by 27–49× compared with the state-of-the-arts. Security analysis demonstrates that ChirpKey is secure against several common attacks. Moreover, we implement a ChirpKey prototype and demonstrate that it can be executed in 0.2 s.
Huanqi Yang, Zehua Sun, Hongbo Liu 0002, Xianjin Xia, Yu Zhang 0093, Tao Gu 0001, Gerhard P. Hancke 0002, Weitao Xu
INFOCOM8
2023 FLoRa: Energy-Efficient, Reliable, and Beamforming-Assisted Over-The-Air Firmware Update in LoRa Networks
abstract
LoRa has emerged as one of the promising long-range and low-power wireless communication technologies for Internet of Things (IoT). With the massive deployment of LoRa networks, the ability to perform Firmware Update Over-The-Air (FUOTA) is becoming a necessity for unattended LoRa devices. LoRa Alliance has recently dedicated the specification for FUOTA, but the existing solution has several drawbacks, such as low energy efficiency, poor transmission reliability, and biased multicast grouping. In this paper, we propose a novel energy-efficient, reliable, and beamforming-assisted FUOTA system for LoRa networks named FLoRa, which is featured with several techniques, including delta scripting, channel coding, and beamforming. In particular, we first propose a novel joint differencing and compression algorithm to generate the delta script for processing gain, which unlocks the potential of incremental FUOTA in LoRa networks. Afterward, we design a concatenated channel coding scheme to enable reliable transmission against dynamic link quality. The proposed scheme uses a rateless code as outer code and an error detection code as inner code to achieve coding gain. Finally, we design a beamforming strategy to avoid biased multicast and compromised throughput for power gain. Experimental results on a 20-node testbed demonstrate that FLoRa improves network transmission reliability by up to 1.51 × and energy efficiency by up to 2.65 × compared with the existing solution in LoRaWAN.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
IPSN7
2023 Demo Abstract: A Novel Firmware Update Over-The-Air System for LoRa Networks
abstract
LoRa has emerged as a novel Internet of Things (IoT) communication paradigm, featuring with long-range and low-power transmission capabilities. With the widespread deployment of LoRa networks, the demand to perform Firmware Update Over-The-Air (FUOTA) tasks has become increasingly critical for unattended LoRa devices. However, in practice, three fundamental problems that hinder the performance of FUOTA tasks are revealed, including low energy efficiency, poor transmission reliability, and biased multicast grouping. In this demo, we present a novel FUOTA system, the first work that offers an effective and sustainable solution to achieve energy-efficient and reliable over-the-air firmware updates in LoRa networks. In particular, this system incorporates threefold key modules: delta scripting, channel coding, and beamforming. The delta scripting algorithm unlocks the capability of incremental update, the channel coding scheme ensures the reliability and robustness of large-scale firmware image distribution, and the beamforming strategy as an optional module can further serve the unicast user. Thus, this demo presents a working example of functionality customization to show the efficacy and feasibility of our FUOTA system in LoRa networks.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
IPSN7
2023 XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice Injection
abstract
Multi-port chargers, capable of simultaneously charging multiple mobile devices such as smartphones, have gained immense popularity and sold millions of units in recent years. However, this charging-targeted feature can also pose security and privacy risks by allowing one of the simultaneously charging devices to communicate with another one if not properly designed and implemented as these devices are actually interconnected. Unfortunately, such risks have not been thoroughly investigated and we have identified a novel attack surface in the circuit design of multi-port chargers, which allows an adversary to exploit one port to (i) eavesdrop on the activities of other devices being charged and (ii) inaudibly inject malicious audio commands if the charging device supports voice assistants and USB-C interface.
Tao Ni 0003, Weitao Xu, Lei Xue 0001, Qingchuan Zhao
MobiCom3
2023 Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot Learning
abstract
Recently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning.
Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
MobiCom6
2023 Wave-for-Safe: Multisensor-based Mutual Authentication for Unmanned Delivery Vehicle Services
abstract
In recent years, the deployment of unmanned vehicle delivery services has increased unprecedentedly, leading to a need for enhanced security due to the risk of leaving high-value packages to an unauthorized third party during pickup or delivery. Existing authentication methods such as QR code and one-time password are inadequate, as they are susceptible to attacks and provide only one-way authentication. This paper, for the first time to our best knowledge, proposes Wave-for-Safe (W4S) --- a novel mutual authentication system that utilizes multi-modal sensors on both the user's smartphone and the unmanned vehicle. W4S uses random hand-waving by the legitimate user to achieve robust authentication by obtaining highly correlated sensory data measured by the Inertial Measurement Unit (IMU) in the smartphone and sensors in the unmanned vehicle (e.g., mmWave radar and camera). We propose several novel methods to overcome challenges such as heterogeneous data processing, asynchronization, and imitating attacks. The prototype is implemented on an unmanned vehicle and various smartphones, and evaluation in different real-world scenarios shows that W4S achieves an equal error rate below 0.013 against various attacks.
Huanqi Yang, Mingda Han, Shuyao Shi, Zhenyu Yan 0002, Guoliang Xing, Jianping Wang 0001, Weitao Xu
MobiHoc7
2023 EMGSense: A Low-Effort Self-Supervised Domain Adaptation Framework for EMG Sensing
abstract
This paper presents EMGSense, a low-effort self-supervised domain adaptation framework for sensing applications based on Electromyography (EMG). EMGSense addresses one of the fundamental challenges in EMG cross-user sensing—the significant performance degradation caused by time-varying biological heterogeneity—in a low-effort (data-efficient and label-free) manner. To alleviate the burden of data collection and avoid labor-intensive data annotation, we propose two EMG-specific data augmentation methods to simulate the EMG signals generated in various conditions and scope the exploration in label-free scenarios. We model combating biological heterogeneity-caused performance degradation as a multi-source domain adaptation problem that can learn from the diversity among source users to eliminate EMG heterogeneous biological features. To relearn the target-user-specific biological features from the unlabeled data, we integrate advanced self-supervised techniques into a carefully designed deep neural network (DNN) structure. The DNN structure can seamlessly perform two training stages that complement each other to adapt to a new user with satisfactory performance. Comprehensive evaluations on two sizable datasets collected from 13 participants indicate that EMGSense achieves an average accuracy of 91.9% and 81.2% in gesture recognition and activity recognition, respectively. EMGSense outperforms the state-of-the-art EMG-oriented domain adaptation approaches by 12.5%-17.4% and achieves a comparable performance with the one trained in a supervised learning manner.
Di Duan, Huanqi Yang, Guohao Lan, Tianxing Li 0001, Xiaohua Jia, Weitao Xu
PERCOM6
2023 XGait: Cross-Modal Translation via Deep Generative Sensing for RF-based Gait Recognition
abstract
Radio Frequency (RF)-based gait recognition has emerged as a promising technology to authenticate individuals in a pervasive and unobtrusive way. However, a fundamental challenge remains in collecting extensive data of the same user in the same environment. To address this challenge, this paper introduces XGait, a cross-modal gait recognition framework that does not require the prior deployment of RF devices or explicit data collection. The key idea is to leverage the signals of the Inertial Measurement Unit (IMU), which is widely available in modern mobile devices, to simulate the RF signals that would be generated if the same person walked near RF devices. Despite the straightforward idea, several technical challenges need to be addressed due to the diversity of RF devices, the intrinsic difference between IMU signals and RF signals, and the complexity of gait. First, we propose an RF spectrogram generation method to consistently extract essential RF gait data features across different RF signals. Secondly, we propose a generative network-enabled IMU-to-RF translation approach that accurately converts IMU data to RF data. Finally, we design an RF gait spectrogram-specific transformer model to further improve the recognition performance. We conduct a comprehensive evaluation of XGait, involving thirty subjects in three different environments, utilizing three RF devices and seven mobile devices. Experimental results show that XGait consistently achieves over 99% Top-3 accuracy in various scenarios.
Huanqi Yang, Mingda Han, Mingda Jia, Zehua Sun, Pengfei Hu 0001, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
SenSys8
2023 Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side Channels
abstract
Today, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors.
Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
SP7
2023 Eavesdropping Mobile App Activity via Radio-Frequency Energy Harvesting
Tao Ni 0003, Guohao Lan, Jia Wang 0008, Qingchuan Zhao, Weitao Xu
USENIX Security Symposium5
2023 IoTSL: Toward Efficient Distributed Learning for Resource-Constrained Internet of Things
abstract
Recently proposed split learning (SL) is a promising distributed machine learning paradigm that enables machine learning without accessing the raw data of the clients. SL can be viewed as one specific type of serial federation learning. However, deploying SL on resource-constrained Internet of Things (IoT) devices still has some limitations, including high communication costs and catastrophic forgetting problems caused by imbalanced data distribution of devices. In this article, we design and implement IoTSL, which is an efficient distributed learning framework for efficient cloud-edge collaboration in IoT systems. IoTSL combines generative adversarial networks (GANs) and differential privacy techniques to train local data-based generators on participating devices, and generate data with privacy protection. On the one hand, IoTSL pretrains the global model using the generative data, and then fine-tunes the model using the local data to lower the communication cost. On the other hand, the generated data is used to impute the missing classes of devices to alleviate the commonly seen catastrophic forgetting phenomenon. We use three common data sets to verify the proposed framework. Extensive experimental results show that compared to the conventional SL, IoTSL significantly reduces communication costs, and efficiently alleviates the catastrophic forgetting phenomenon.
Xingyu Feng 0001, Chengwen Luo 0001, Jiongzhang Chen, Jin Zhang 0013, Weitao Xu, Jianqiang Li 0001, Victor C. M. Leung
IEEE Internet Things J.6
2023 CoBC: A Blockchain-Based Collaborative Inference System for Internet of Things
abstract
The capability of local smart sensing based on Internet of Things (IoT) devices is typically limited due to due to the inherent limitations of computational and storage capabilities. Recently, collaborative inference among multiple devices has been considered as an effective way to improve the sensing capabilities of individual IoT devices. However, the collaborative inference process still faces the challenges of data privacy leakage and inefficient collaboration. To alleviate the above issues, we design a blockchain-based collaborative inference system in this article, called CoBC, which allows each heterogeneous device node on the blockchain to customize a personalized local machine learning model according to its own hardware constraint and performance, thus improving the efficiency of resource utilization of the whole system. Meanwhile, each device node only needs to complete training locally, which significantly reduces the risk of privacy leakage due to the remote transmission of local data. CoBC improves the sensing capability of single device nodes by using collaborative inference that can obtain a more robust global inference. In addition, CoBC employs a Bayesian approximation training approach to evaluate the output uncertainty of each device node to further improve the efficiency of collaborative inference. To evaluate the performance, we deploy CoBC in a real environment and conduct a large number of simulations to evaluate the efficiency of CoBC. The simulation results demonstrate that CoBC exhibits good performance and good practicality in various criteria.
Xingyu Feng 0001, Tenglong Wang, Weitao Xu, Jin Zhang 0013, Bo Wei 0003, Chengwen Luo 0001
IEEE Internet Things J.4
2023 Time-Constrained Ensemble Sensing With Heterogeneous IoT Devices in Intelligent Transportation Systems
abstract
Recently we have witnessed the rise of Artificial Intelligence of Things (AIoT) and the shift of sensing paradigm from cloud-centric to the edge-centric, which effectively improves the sensing capability of intelligence transportation systems. To improve the real-time sensing performance, in this work we propose an ensemble sensing based scheme to solve the time-constraint synchronized inference problem and achieve robust inference with heterogeneous IoT devices in intelligence transportation systems. We design and implement Ensen, which incorporates various novel techniques such as customized DNN model design, KD-based model training, and dynamic deep ensemble management, etc., to achieve improved accuracy and maximize the computational resource usage of the whole sensing group. Extensive evaluations on different types of common IoT devices have shown that Ensen achieves a robust performance and can be easily extended to different types of convolutional neural networks.
Xingyu Feng 0001, Chengwen Luo 0001, Bo Wei 0003, Jin Zhang 0013, Jianqiang Li 0001, Huihui Wang 0001, Weitao Xu, Mun Choon Chan, Victor C. M. Leung
IEEE Trans. Intell. Transp. Syst.7
2023 H2K: A Heartbeat-Based Key Generation Framework for ECG and PPG Signals
abstract
Wireless body area network is a key enabler for connected healthcare but recent cyberattacks have compromised its security and trustworthiness. This paper investigates heartbeat-based key generation to secure body area networks. The interpulse intervals (IPIs) between any two adjacent peaks of heartbeat signals are random and state-of-the-art literature has demonstrated that IPI is a good random source to be extracted as cryptographic keys. Heartbeat signals can be measured by electrocardiography (ECG) and photoplethysmography (PPG) sensors. A general heartbeat-based key generation framework applicable to both ECG and PPG signals is proposed. A robust peak detection algorithm is designed to capture noisy peaks and a simple yet efficient IPI alignment algorithm to align the common IPIs. A key establishment protocol is used to convert analog IPIs to digital binaries and reconcile them between legitimate devices. We evaluate the performance for both ECG signals from an online public database, MIT PhysioBank, and PPG signals collected from our testbed. The results demonstrate that our algorithm is robust and heartbeat-based key generation can be completed for both ECG and PPG signals. We finally create a PPG-based prototype and a demonstration video to show the practicality of our framework.
Junqing Zhang, Yushi Zheng, Weitao Xu, Yingying Chen 0001
IEEE Trans. Mob. Comput.3
2022 Vehicle-Key: A Secret Key Establishment Scheme for LoRa-enabled IoV Communications
abstract
Recent years have witnessed the remarkable growth of the Internet of Vehicles (IoV). Due to the high dynamics and ad-hoc nature of IoV communication, the lack of effective secret key establishment in IoV remains a security bottleneck. Physical layer key generation has emerged as a promising technology to establish a pair of cryptographic keys in a lightweight and information-theoretic secure way. However, prior works mainly focus on legacy communication technologies such as Wi-Fi, ZigBee, and 5G which can only achieve short range IoV communications. The emergence of Long-range (LoRa) communication technology that features long-range, low power, and extremely low data rate, brings new challenges for key generation in long range IoV scenarios. In this paper, we present Vehicle-Key, which is a secret key generation system to secure LoRa-enabled IoV communications. In Vehicle-Key, we design a novel deep learning model that can achieve channel prediction and quantization simultaneously. Additionally, we propose an autoencoder-based reconciliation method that improves the key agreement rate significantly. Extensive real-world experiments show that Vehicle-Key improves the key agreement rate by 15.10%–49.81% and key generation rate by 9–14× compared with the state-of-the-art. Security analysis demonstrates that Vehicle-Key is secure against several common attacks. Moreover, we implement Vehicle-Key on a Raspberry Pi and show that it can be executed in 3.4 ms.
Huanqi Yang, Hongbo Liu 0002, Chengwen Luo 0001, Yuezhong Wu, Wei Li 0058, Albert Y. Zomaya, Linqi Song, Weitao Xu
ICDCS8
2022 GASLA: Enhancing the Applicability of Sign Language Translation
abstract
This paper studies an important yet overlooked applicability issue in existing American sign language (ASL) translation systems. With excessive sensing data collected for each ASL word already, current designs treat every to-be-recognized sentence as new and collect their sensing data from scratch, while the amounts of sentences and the data samples per sentence are large usually. It takes a long time to complete the data collection for each single user, e.g., hours to a half day, which brings non-trivial burden to the end users inevitably and prevents the broader adoption of the ASL systems in practice. In this paper, we figure out the reason causing this issue. We present GASLA atop the wearable sensors to instrument our design. With GASLA, the sentence-level sensing data can be generated from the word-level data automatically, which can be then applied to train ASL systems. Moreover, GASLA has a clear interface to be integrated to existing ASL systems for overhead reduction directly. With this ability, sign language translation could become highly lightweight in both initial setup and future new-sentence addition. Compared with around 10 per-sentence data samples in current systems, GASLA requires 2–3 samples to achieve a similar performance.
Jiao Li 0002, Yang Liu 0101, Weitao Xu, Zhenjiang Li 0001
INFOCOM3
2022 i2 Key: A Cross-sensor Symmetric Key Generation System Using Inertial Measurements and Inaudible Sound
abstract
Networked devices, such as wearable devices, laptops, smart home appliances, etc., are ubiquitous nowadays. To secure communication among those devices, symmetric keys are widely used because of their feasibility in resource-constrained networked devices. The ob-servations of sensors from independent devices have been adopted for symmetric key generation. The identical biometrics information or environment interference has been observed by sensors, and their corresponding patterns are used for key generation. Pop-ular signals from networked devices are inertial measurements, sound, wireless signals, etc. The existing sensor-based key gen-eration solutions use the same type of sensors for both devices. Different from the existing solutions, we are the first to propose a cross-sensor symmetric key generation system i2Key, where two devices collect inertial measurements from a motion sensor and inaudible sound from a microphone, respectively. A new coding framework is designed for general key generation. We also pro-pose an efficient and accurate time synchronisation method for key generation. Additionally, a multi-tier key reconciliation method is suggested to improve key generation performance. By using the proposed architecture, the key generation rate is improved by up to approximately 40% compared with the situation without using it. We also perform security analysis and randomness analysis over the proposed method.
Bo Wei 0003, Weitao Xu, Kai Li 0002, Chengwen Luo 0001, Jin Zhang 0013
IPSN2
2022 A differential privacy-based classification system for edge computing in IoT
Wanli Xue, Yiran Shen 0001, Chengwen Luo 0001, Weitao Xu, Wen Hu 0001, Aruna Seneviratne
Comput. Commun.4
2022 PrivGait: An Energy-Harvesting-Based Privacy-Preserving User-Identification System by Gait Analysis
abstract
Smart space has emerged as a new paradigm that combines sensing, communication, and artificial intelligence technologies to offer various customized services. A fundamental requirement of these services is person identification. Although a variety of person-identification approaches has been proposed, they suffer from several limitations in practical applications, such as low energy efficiency, accuracy degradation, and privacy issue. This article proposes an energy-harvesting-based privacy-preserving gait recognition scheme for smart space, which is named PrivGait. In PrivGait, we extract discriminative features from 1-D gait signal and design an attention-based long short-term memory (LSTM) network to classify different people. Moreover, we leverage a novel Bloom filter-based privacy-preserving technique to address the privacy leakage problem. To demonstrate the feasibility of PrivGait, we design a proof-of-concept prototype using off-the-shelf energy-harvesting hardware. Extensive evaluation results show that the proposed scheme outperforms state of the art by 6%–10% and incurs low system cost while preserving user’s privacy.
Weitao Xu, Wanli Xue, Guohao Lan, Xingyu Feng 0001, Bo Wei 0003, Chengwen Luo 0001, Wei Li 0058, Albert Y. Zomaya
IEEE Internet Things J.1
2022 Simultaneous Energy Harvesting and Gait Recognition Using Piezoelectric Energy Harvester
abstract
Piezoelectric energy harvester (PEH), which generates electricity from stress or vibrations, is attracting tremendous attention as a viable solution to extend battery life of wearable devices. More interestingly, besides the energy harvesting capability, recent research has demonstrated the feasibility of leveraging PEH as an power-free sensor for gait recognition as its stress or vibration patters are significantly influenced by the gait. However, as PEHs are not designed for precise motion sensing, the gait recognition accuracy remains low with conventional classification algorithms. The accuracy deteriorates further when the generated electricity is stored simultaneously. In this work, to achieve high performance gait recognition and efficient energy harvesting at the same time, we make two distinct contributions. First, we propose a preprocessing algorithm to filter out the effect of energy storage on PEH electricity signals. Second, we propose long short-term memory (LSTM) network-based classifiers to accurately capture temporal information in gait-induced electricity generation. We prototype the proposed gait recognition architecture in the form factor of an insole and evaluate its gait recognition as well as energy harvesting performance with 20 subjects. Our results show that the proposed architecture detects human gait with 12 percent higher recall and harvests up to 127 percent more energy while consuming 38 percent less power compared to the state-of-the-art.
Dong Ma 0001, Guohao Lan, Weitao Xu, Mahbub Hassan, Wen Hu 0001
IEEE Trans. Mob. Comput.3
2022 Recent Advances in LoRa: A Comprehensive Survey
abstract
The vast demand for diverse applications raises new networking challenges, which have encouraged the development of a new paradigm of Internet of Things (IoT), e.g., LoRa. LoRa is a proprietary spread spectrum modulation technique that provides a solution for long-range and ultra-low power-consumption transmission. Due to promising prospects of LoRa, significant effort has been made on this compelling technology since its emergence. In this article, we provide a comprehensive survey of LoRa from a systematic perspective: LoRa analysis, communication, security, and its enabled applications. First, we summarize works focusing on analyzing the performance of LoRa networks. Then, we review studies enhancing the performance of LoRa networks in communication. Afterward, we analyze the security vulnerabilities and countermeasures. Finally, we survey the various LoRa-enabled applications. We also present comparisons of existing methods, together with insightful observations and inspiring future research directions.
Zehua Sun, Huanqi Yang, Kai Liu 0008, Zhimeng Yin 0001, Zhenjiang Li 0001, Weitao Xu
ACM Trans. Sens. Networks6
2021 A Novel Model-Based Security Scheme for LoRa Key Generation
abstract
Physical layer key generation has attracted considerable attention in the past decade since it provides an alternative solution for the key establishment in wireless networks using channel reciprocity. In this paper we explore the possibility of physical layer key generation for emerging Low Power Wide Area Networks (LPWAN) such as LoRa (Long Range). However, due to the lower transmission rates of LPWANs compared to Wi-Fi and Zigbee, the channel reciprocity is relatively low, which makes timely key generation challenging. To address this problem, we propose a novel information-theoretic key generation scheme that can operate at all data rate settings, featuring a model-based key generation method. Furthermore, we derive an optimal window size to calculate the parameters of the channel model based on a random waypoint model to balance the channel reciprocity and entropy. Extensive evaluations on a campus testbed show that our method can achieve up to 13.8 bps key generation rate. Compared to state-of-the-art methods, the proposed method improves key generation rate by 3x to 5x. We also analyzed the security of the proposed approach and demonstrated it to be resilient to eavesdropping attacks.
Jiayao Gao, Weitao Xu, Salil S. Kanhere, Sanjay K. Jha, Jun Young Kim, Walter Huang, Wen Hu 0001
IPSN2
2021 InaudibleKey: Generic Inaudible Acoustic Signal based Key Agreement Protocol for Mobile Devices
abstract
Secure Device-to-Device (D2D) communication is becoming increasingly important with the ever-growing number of Internet-of-Things (IoT) devices in our daily life. To achieve secure D2D communication, the key agreement between different IoT devices without any prior knowledge is becoming desirable. Although various approaches have been proposed in the literature, they suffer from a number of limitations, such as low key generation rate and short pairing distance. In this paper, we present InaudibleKey, an inaudible acoustic signal based key generation protocol for mobile devices. Based on acoustic channel reciprocity, InaudibleKey exploits the acoustic channel frequency response of two legitimate devices as a common secret to generating keys. InaudibleKey employs several novel technologies to significantly improve its performance. We conduct extensive experiments to evaluate the proposed system in different real environments. Compared to state-of-the-art works, InaudibleKey improves key generation rate by 3 times, extends pairing distance by 3.2 times, and reduces information reconciliation counts by 2.5 times. Security analysis demonstrates that InaudibleKey is resilient to a number of malicious attacks. We also implement InaudibleKey on modern smartphones and resource-limited IoT devices. Results show that it is energy-efficient and can run on both powerful and resource-limited IoT devices without incurring excessive resource consumption.
Weitao Xu, Zhenjiang Li 0001, Wanli Xue, Xiaotong Yu, Bo Wei 0003, Jia Wang 0008, Chengwen Luo 0001, Wei Li 0058, Albert Y. Zomaya
IPSN1
2021 No Need of Data Pre-processing: A General Framework for Radio-based Device-free Context Awareness
abstract
Device-free context awareness is important to many applications. There are two broadly used approaches for device-free context awareness, i.e., video-based and radio-based. Video-based approaches can deliver good performance, but privacy is a serious concern. Radio-based context awareness applications have drawn researchers' attention instead, because it does not violate privacy and radio signal can penetrate obstacles. The existing works design explicit methods for each radio-based application. Furthermore, they use one additional step to extract features before conducting classification and exploit deep learning as a classification tool. Although this feature extraction step helps explore patterns of raw signals, it generates unnecessary noise and information loss. The use of raw CSI signal without initial data processing was, however, considered as no usable patterns. In this article, we are the first to propose an innovative deep learning–based general framework for both signal processing and classification. The key novelty of this article is that the framework can be generalised for all the radio-based context awareness applications with the use of raw CSI. We also eliminate the extra work to extract features from raw radio signals. We conduct extensive evaluations to show the superior performance of our proposed method and its generalisation.
Bo Wei 0003, Kai Li 0002, Chengwen Luo 0001, Weitao Xu, Jin Zhang 0013, Kuan Zhang 0001
ACM Trans. Internet Things4
2020 Poster Abstract: A Novel Modeling Involved Security Approach for LoRa Key Generation
abstract
Taking the advantages of reciprocity and randomness of wireless fading channels, key generation via physical layer is attracting more attention. It becomes a remarkable solution for wireless communication in recent years. However, the feasibility under long-range and low data rate scenarios of narrow band low power wide area network (LPWAN) lacks proper studies. In this poster, we introduce a novel modeling method for Long Range Wide Area Network (LoRaWAN) key generation. The approach combines several signal processing techniques and using measured real-time Received Signal Strength Indicator (RSSI) to improve the applicability of key generation as well as increasing key generation rate (KGR) significantly.
Jiayao Gao, Weitao Xu, Salil S. Kanhere, Sanjay K. Jha, Wen Hu 0001
IPSN2
2020 SolarSLAM: Battery-free Loop Closure for Indoor Localisation
abstract
In this paper, we propose SolarSLAM, a batteryfree loop closure method for indoor localisation. Inertial Measurement Unit (IMU) based indoor localisation method has been widely used due to its ubiquity in mobile devices, such as mobile phones, smartwatches and wearable bands. However, it suffers from the unavoidable long term drift. To mitigate the localisation error, many loop closure solutions have been proposed using sophisticated sensors, such as cameras, laser, etc. Despite achieving high-precision localisation performance, these sensors consume a huge amount of energy. Different from those solutions, the proposed SolarSLAM takes advantage of an energy harvesting solar cell as a sensor and achieves effective battery-free loop closure method. The proposed method suggests the key-point dynamic time warping for detecting loops and uses robust simultaneous localisation and mapping (SLAM) as the optimiser to remove falsely recognised loop closures. Extensive evaluations in the real environments have been conducted to demonstrate the advantageous photocurrent characteristics for indoor localisation and good localisation accuracy of the proposed method.
Bo Wei 0003, Weitao Xu, Chengwen Luo 0001, Guillaume Zoppi, Dong Ma 0001, Sen Wang 0002
IROS2
2020 Nephalai: towards LPWAN C-RAN with physical layer compression
abstract
We propose Nephelai, a Compressive Sensing-based Cloud Radio Access Network (C-RAN), to reduce the uplink bit rate of the physical layer (PHY) between the gateways and the cloud server for multi-channel LPWANs. Recent research shows that single-channel LPWANs suffer from scalability issues. While multiple channels improve these issues, data transmission is expensive. Furthermore, recent research has shown that jointly decoding raw physical layers that are offloaded by LPWAN gateways in the cloud can improve the signal-to-noise ratio (SNR) of week radio signals. However, when it comes to multiple channels, this approach requires high bandwidth of network infrastructure to transport a large amount of PHY samples from gateways to the cloud server, which results in network congestion and high cost due to Internet data usage. In order to reduce the operation's bandwidth, we propose a novel LPWAN packet acquisition mechanism based on Compressive Sensing with a custom design dictionary that exploits the structure of LPWAN packets, reduces the bit rate of samples on each gateway, and demodulates PHY in the cloud with (joint) sparse approximation. Moreover, we propose an adaptive compression method that takes the Spreading Factor (SF) and SNR into account. Our empirical evaluation shows that up to 93.7% PHY samples can be reduced by Nephelai when SF = 9 and SNR is high without degradation in the packet reception rate (PRR). With four gateways, 1.7x PRR can be achieved with 87.5% PHY samples compressed, which can extend the battery lifetime of embedded IoT devices to 1.7.
Jun Liu 0074, Weitao Xu, Sanjay K. Jha, Wen Hu 0001
MobiCom2
2020 Inaudible acoustic signal based key agreement system for IoT devices: poster abstract
abstract
Secure Device-to-Device (D2D) communication is becoming increasingly important with the ever-growing number of Internet-of-Things (IoT) devices in our daily life. To achieve secure D2D communication, the key agreement between different IoT devices without any prior knowledge is becoming desirable. Although various approaches have been proposed in the literature, they suffer from a number of limitations, such as low key generation rate and short pairing distance. In this paper, we present an inaudible acoustic signal based key generation protocol for mobile devices. Based on acoustic channel reciprocity, our system exploits channel frequency response of two legitimate devices as a common secret to generate keys. Extensive experiments are conducted to evaluate the proposed system in different real environments. Evaluation results show that the proposed system can generate the same secret key for two mobile devices with high probability.
Weitao Xu, Zhenjiang Li 0001, Wanli Xue, Xiaotong Yu, Jia Wang 0008, Chengwen Luo 0001, Wei Li 0058, Albert Y. Zomaya
SenSys1
2020 Gait-Watch: A Gait-based context-aware authentication system for smart watch via sparse coding
Weitao Xu, Yiran Shen 0001, Chengwen Luo 0001, Jianqiang Li 0001, Wei Li 0058, Albert Y. Zomaya
Ad Hoc Networks1
2020 A multi-view CNN-based acoustic classification system for automatic animal species identification
Weitao Xu, Xiang Zhang 0012, Lina Yao 0001, Wanli Xue, Bo Wei 0003
Ad Hoc Networks1
2020 Measurement, Characterization, and Modeling of LoRa Technology in Multifloor Buildings
abstract
In recent years, we have witnessed the rapid development of the long range (LoRa) technology, together with extensive studies trying to understand its performance in various application settings. In contrast to measurements performed in large outdoor areas, a limited number of attempts have been made to understand the characterization and performance of the LoRa technology in indoor environments. In this article, we present a comprehensive study of the LoRa technology in multifloor buildings. Specifically, we investigate the large-scale fading characteristic, temporal fading characteristic, coverage, and energy consumption of the LoRa technology in four different types of buildings. Moreover, we find that the energy consumption using different parameter settings can vary up to 145 times. These results indicate the importance of parameter selection and enabling the LoRa adaptive data rate feature in energy-limited applications. We hope the results in this article can help both academia and industry understand the performance of the LoRa technology in multifloor buildings to facilitate developing practical indoor applications.
Weitao Xu, Jun Young Kim, Walter Huang, Salil S. Kanhere, Sanjay K. Jha, Wen Hu 0001
IEEE Internet Things J.1
2020 Capacitor-based Activity Sensing for Kinetic-powered Wearable IoTs
abstract
We propose the use of the conventional energy storage component, i.e., capacitor, in the kinetic-powered wearable IoTs as the sensor to detect human activities. Since activities accumulate energy in the capacitor at different rates, the charging rate of the capacitor can be used to detect the activities. The key advantage of the proposed capacitor-based activity sensing mechanism, called CapSense, is that it obviates the need for sampling the motion signal at a high rate, and thus, significantly reduces power consumption of the wearable device. The challenge we face is that capacitors are inherently non-linear energy accumulators, which leads to significant variations in the charging rates. We solve this problem by jointly configuring the parameters of the capacitor and the associated energy harvesting circuits, which allows us to operate in the charging cycles that are approximately linear. We design and implement a kinetic-powered shoe and conduct experiments with 10 subjects. Our results show that CapSense can classify five different daily activities with 95% accuracy while consuming 57% less system power compared to conventional motion-sensor-based approaches.
Guohao Lan, Dong Ma 0001, Weitao Xu, Mahbub Hassan, Wen Hu 0001
ACM Trans. Internet Things3
2020 EnTrans: Leveraging Kinetic Energy Harvesting Signal for Transportation Mode Detection
abstract
Monitoring the daily transportation modes of an individual provides useful information in many application domains, such as urban design, real-time journey recommendation, and providing location-based services. In existing systems, accelerometer and GPS are the dominantly used signal sources for transportation context monitoring which drain out the limited battery life of the wearable devices very quickly. To resolve the high energy consumption issue, in this paper, we present EnTrans, which enables transportation mode detection by using only the kinetic energy harvester as an energy-efficient signal source. The proposed idea is based on the intuition that the vibrations experienced by the passenger during traveling with different transportation modes are distinctive. Thus, voltage signal generated by the energy harvesting devices should contain sufficient features to distinguish different transportation modes. We evaluate our system using over 28 h of data, which is collected by eight individuals using a practical energy harvesting prototype. The evaluation results demonstrate that EnTrans is able to achieve an overall accuracy over 92% in classifying five different modes while saving more than 34% of the system power compared to conventional accelerometer-based approaches.
Guohao Lan, Weitao Xu, Dong Ma 0001, Sara Khalifa, Mahbub Hassan, Wen Hu 0001
IEEE Trans. Intell. Transp. Syst.2
2020 Securing Cyber-Physical Social Interactions on Wrist-Worn Devices
abstract
Since ancient Greece, handshaking has been commonly practiced between two people as a friendly gesture to express trust and respect, or form a mutual agreement. In this article, we show that such physical contact can be used to bootstrap secure cyber contact between the smart devices worn by users. The key observation is that during handshaking, although belonged to two different users, the two hands involved in the shaking events are often rigidly connected, and therefore exhibit very similar motion patterns. We propose a novel key generation system, which harvests motion data during user handshaking from the wrist-worn smart devices such as smartwatches or fitness bands, and exploits the matching motion patterns to generate symmetric keys on both parties. The generated keys can be then used to establish a secure communication channel for exchanging data between devices. This provides a much more natural and user-friendly alternative for many applications, e.g., exchanging/sharing contact details, friending on social networks, or even making payments, since it doesn’t involve extra bespoke hardware, nor require the users to perform pre-defined gestures. We implement the proposed key generation system on off-the-shelf smartwatches, and extensive evaluation shows that it can reliably generate 128-bit symmetric keys just after around 1s of handshaking (with success rate >99%), and is resilient to different types of attacks including impersonate mimicking attacks, impersonate passive attacks, or eavesdropping attacks. Specifically, for real-time impersonate mimicking attacks, in our experiments, the Equal Error Rate (EER) is only 1.6% on average. We also show that the proposed key generation system can be extremely lightweight and is able to run in-situ on the resource-constrained smartwatches without incurring excessive resource consumption.
Yiran Shen 0001, Bowen Du 0002, Weitao Xu, Chengwen Luo 0001, Bo Wei 0003, Li-Zhen Cui 0001, Hongkai Wen 0001
ACM Trans. Sens. Networks3
2019 Brush like a Dentist: Accurate Monitoring of Toothbrushing via Wrist-Worn Gesture Sensing
abstract
Oral health has significant impact on people’s over-all well-being. While many activity recognition systems exist in the literature, accurately sensing toothbrushing activities remains an unsolved challenging problem due to the diversity of tooth-brushing habits among different users and subtle distinctions between different brushing actions. In this work, we propose Hygiea, an energy-efficient and highly-accurate toothbrushing monitoring system which exploits IMU-based wrist-worn gesture sensing using unmodified toothbrushes. To address toothbrushing variety, Hygiea incorporates a number of novel signal preprocessing techniques to automatically transform the sensory input during arbitrary toothbrushing activities to the consistent user coordinate system. To distinguish different brushing actions, Hygiea leverages an emerging deep learning model (e.g., AT-LSTM) to achieve fine-grained activity recognitions. Moreover, a POMDP model is incorporated for sampling control to balance activity detection and energy efficiency. Extensive real-world experiments show that the Hygiea system achieves a 11.7% accuracy gain compared to the state-of-the-art while maintaining energy-efficiency and zero modification on the toothbrushes.
Chengwen Luo 0001, Xingyu Feng 0001, Junliang Chen 0002, Jianqiang Li 0001, Weitao Xu, Wei Li 0058, Zahir Tari, Albert Y. Zomaya
INFOCOM5
2019 H2B: heartbeat-based secret key generation using piezo vibration sensors
abstract
We present Heartbeats-2-Bits (H2B), which is a system for securely pairing wearable devices by generating a shared secret key from the skin vibrations caused by heartbeat. This work is motivated by potential power saving opportunity arising from the fact that heartbeat intervals can be detected energy-efficiently using inexpensive and power-efficient piezo sensors, which obviates the need to employ complex heartbeat monitors such as Electrocardiogram or Photoplethysmogram. Indeed, our experiments show that piezo sensors can measure heartbeat intervals on many different body locations including chest, wrist, waist, neck and ankle. Unfortunately, we also discover that the heartbeat interval signal captured by piezo vibration sensors has low Signal-to-Noise Ratio (SNR) because they are not designed as precision heartbeat monitors, which becomes the key challenge for H2B. To overcome this problem, we first apply a quantile function-based quantization method to fully extract the useful entropy from the noisy piezo measurements. We then propose a novel Compressive Sensing-based reconciliation method to correct the high bit mismatch rates between the two independently generated keys caused by low SNR. We prototype H2B using off-the-shelf piezo sensors and evaluate its performance on a dataset collected from different body positions of 23 participants. Our results show that H2B has a pairing success rate of 95.6%. We also analyze and demonstrate H2B's robustness against three types of attacks. Finally, our power measurements show that H2B is very power-efficient.
Weitao Xu, Jun Liu 0074, Abdelwahed Khamis, Wen Hu 0001, Mahbub Hassan, Aruna Seneviratne
IPSN2
2019 WiEnhance: Towards Data Augmentation in Human Activity Recognition Using WiFi Signal
abstract
Recent research have devoted significant efforts on the utilization of WiFi signals to recognize various human activities. An individual's limb motions in the WiFi spectrum could interfere wireless signal propagation which manifested as unique patterns for activities recognition. Existing approaches though yielding reasonable performance in certain cases, are ignorant of a major challenge. The performed activities of the individual normally have inconsistent speed in different situations and time. Besides that the wireless signal reflected by human bodies normally carry substantial information that is specific to that subject. The activity recognition model trained on a certain individual may not work well when being applied to predict another individual's activities. To address this challenge, we propose WiEnhance, a WiFi based activity recognition system that synthesize variant activities data and mitigate the impact of activity inconsistency and subject-specific issues. We conduct extensive experiments and show an average 15.6% performance improvement on activity recognition.
Jin Zhang 0013, Fuxiang Wu, Wen Hu 0001, Qieshi Zhang, Weitao Xu, Jun Cheng 0002
MSN5
2019 LoRa-Key: Secure Key Generation System for LoRa-Based Network
abstract
Physical layer key generation that exploits reciprocity and randomness of wireless fading channels has attracted considerable attention in recent years. Despite much research efforts in this field, the problem of wireless key generation at long distance and low data rate remains unknown and has not been studied. In this paper, we conduct extensive experiments and analysis in real indoor and outdoor environments to explore the feasibility of wireless key generation for long range (LoRa)-based network. Our experimental results show that: 1) the low transmission rate will lead to low channel reciprocity which makes wireless key generation significantly challenging and 2) when the requirement of high reciprocity is fulfilled, two nodes can generate the same secret key even when they are far away from each other (a few kilometers). Building on the strengths of existing secret key extraction approaches, we present LoRa-Key, the first complete key establishment protocol for LoRa network by exploring the shared randomness extracted from measured received signal strength indicator. LoRa-Key employs a number of signal processing techniques to improve key generation rate significantly. Moreover, we propose a novel compressive sensing-based reconciliation framework to reduce mismatch rate. Experimental results show that LoRa-Key can achieve key establishment rates of 18 bit/s in stationary scenario and 31 bit/s in mobile scenario. To the best of our knowledge, this is the first work that studies key generation protocol for LoRa network.
Weitao Xu, Sanjay K. Jha, Wen Hu 0001
IEEE Internet Things J.1
2019 The Design, Implementation, and Deployment of a Smart Lighting System for Smart Buildings
abstract
There is an increasing interest in Internet of Things (IoT) enabled smart buildings over the past decades. However, the development of smart buildings is impeded by the high installation/maintenance cost and the difficulty of large-scale evaluation in the wild. In this paper, we report the design, implementation, and deployment of an emergency light-based smart building solution. The key advantage of the system is that it is built on the top of the existing facilities in the building (i.e., emergency light). As a case study, we have implemented and deployed our system in nine production smart buildings of different types including residential, commercial office, and warehouse of multiple level building complexes. Using real data from four typical buildings, we show the proposed system can achieve >97% average packet delivery rate. Evaluation results also demonstrate the stability and robustness of the system to environmental changes. The results of this paper provide practical insights to facilitate the development of smart building systems.
Weitao Xu, Jin Zhang 0013, Jun Young Kim, Walter Huang, Salil S. Kanhere, Sanjay K. Jha, Wen Hu 0001
IEEE Internet Things J.1
2019 GaitLock: Protect Virtual and Augmented Reality Headsets Using Gait
abstract
With the fast penetration of commercial Virtual Reality (VR) and Augmented Reality (AR) systems into our daily life, the security issues of those devices have attracted significant interests from both academia and industry. Modern VR/AR systems typically use head-mounted devices (i.e., headsets) to interact with users, and often store private user data, e.g., social network accounts, online transactions or even payment information. This poses significant security threats, since in practice the headset can be potentially obtained and accessed by unauthenticated parties, e.g., identity thieves, and thus cause catastrophic breach. In this paper, we propose a novel GaitLock system, which can reliably authenticate users using their gait signatures. Our system doesn't require extra hardware, e.g., fingerprint sensors or retina scanners, but only uses the on-board inertial measurement units (IMUs) equipped in almost all mainstream VR/AR headsets to authenticate the legitimate users from intruders, by simply asking them to walk a few steps. To achieve that, we propose a new gait recognition model Dynamic-SRC, which combines the strength of Dynamic Time Warping (DTW) and Sparse Representation Classifier (SRC), to extract unique gait patterns from the inertial signals during walking. We implement GaitLock on Google Glass (a typical AR headset), and extensive experiments show that GaitLock outperforms the state-of-the-art systems significantly in recognition accuracy (> 98 percent success in 5 steps), and is able to run in-situ on the resource-constrained VR/AR headsets without incurring high energy cost.
Yiran Shen 0001, Hongkai Wen 0001, Chengwen Luo 0001, Weitao Xu, Tao Zhang 0001, Wen Hu 0001, Daniela Rus
IEEE Trans. Dependable Secur. Comput.4
2019 KEH-Gait: Using Kinetic Energy Harvesting for Gait-based User Authentication Systems
abstract
With the rapid development of sensor networks and embedded computing technologies, miniaturized wearable healthcare monitoring devices have become practically feasible. For many of these devices, accelerometer-based user authentication systems by gait analysis are becoming a hot research topic. However, a major bottleneck of such system is it requires continuous sampling of accelerometer, which reduces battery life of wearable sensors. In this paper, we present KEH-Gait, which advocates use of output voltage signal from kinetic energy harvester (KEH) as the source for gait recognition. KEH-Gait is motivated by the prospect of significant power saving by not having to sample the accelerometer at all. Indeed, our measurements show that, compared to conventional accelerometer-based gait detection, KEH-Gait can reduce energy consumption by 82.15 percent. The feasibility of KEH-Gait is based on the fact that human gait has distinctive movement patterns for different individuals, which is expected to leave distinctive patterns for KEH as well. We evaluate the performance of KEH-Gait using two different types of KEH hardware on a data set of 20 subjects. Our experiments demonstrate that, although KEH-Gait yields slightly lower accuracy than accelerometer-based gait detection when single step is used, the accuracy problem can be overcome by the proposed Probability-based Multi-Step Sparse Representation Classification (PMSSRC). Moreover, the security analysis shows that the EER of KEH-Gait against an active spoofing attacker is 11.2 and 14.1 percent using two different types of KEH hardware, respectively.
Weitao Xu, Guohao Lan, Sara Khalifa, Mahbub Hassan, Neil W. Bergmann, Wen Hu 0001
IEEE Trans. Mob. Comput.1
2018 Shake-n-Shack: Enabling Secure Data Exchange Between Smart Wearables via Handshakes
abstract
Since ancient Greece, handshaking has been commonly practiced between two people as a friendly gesture to express trust and respect, or form a mutual agreement. In this paper, we show that such physical contact can be used to bootstrap secure cyber contact between the smart devices worn by users. The key observation is that during handshaking, although belonged to two different users, the two hands involved in the shaking events are often rigidly connected, and therefore exhibit very similar motion patterns. We propose a novel Shake-n-Shack system, which harvests motion data during user handshaking from the wrist worn smart devices such as smartwatches or fitness bands, and exploits the matching motion patterns to generate symmetric keys on both parties. The generated keys can be then used to establish a secure communication channel for exchanging data between devices. This provides a much more natural and user-friendly alternative for many applications, e.g., exchanging/sharing contact details, friending on social networks, or even making payments, since it doesn't involve extra bespoke hardware, nor require the users to perform pre-defined gestures. We implement the proposed Shake-n-Shack1system on off-the-shelf smartwatches, and extensive evaluation shows that it can reliably generate 128-bit symmetric keys just after around 1s of handshaking (with success rate >99%), and is resilient to real-time mimicking attacks: in our experiments the Equal Error Rate (EER) is only 1.6% on average. We also show that the proposed Shake-n-Shack system can be extremely lightweight, and is able to run in-situ on the resource-constrained smartwatches without incurring excessive resource consumption.
Yiran Shen 0001, Fengyuan Yang 0001, Bowen Du 0002, Weitao Xu, Chengwen Luo 0001, Hongkai Wen 0001
PerCom4
2018 Energy Efficient LPWAN Decoding via Joint Sparse Approximation
abstract
We propose a sparse approximation based joint-decoding system for LPWAN (LoRa) PHY-layer frame decoding. Recent research has shown that joint-decoding raw radio ADC samples in the Cloud offloaded from LPWAN gateways can decode weak radio signals by combining coherent frames. However, this approach requires high network bandwidth usage to collect a large amount of ADC samples from each gateway, which results in network congestion and high financial cost due to Internet data usage between the gateway and the Cloud server. In order to reduce the bandwidth usage of this data offloading operation, we propose a LPWAN packet acquisition mechanism based on joint sparse approximation.
Jun Liu 0074, Weitao Xu, Wen Hu 0001
SenSys2
2018 Sensor-Assisted Multi-View Face Recognition System on Smart Glass
abstract
Face recognition is a hot research topic with a variety of application possibilities, including video surveillance and mobile payment. It has been well researched in traditional computer vision community. However, new research issues arise when it comes to resource constrained devices, such as smart glasses, due to the overwhelming computation and energy requirements of the accurate face recognition methods. In this paper, we propose a robust and efficient sensor-assisted face recognition system on smart glasses by exploring the power of multimodal sensors including the camera and Inertial Measurement Unit (IMU) sensors. The system is based on a novel face recognition algorithm, namely Multi-view Sparse Representation Classification (MVSRC), by exploiting the prolific information among multi-view face images. To improve the efficiency of MVSRC on smart glasses, we propose two novel sampling optimization strategies using the less expensive inertial sensors. Our evaluations on public and private datasets show that the proposed method is up to 10 percent more accurate than the state-of-the-art multi-view face recognition methods while its computation cost is the same order as an efficient benchmark method (e.g., Eigenfaces). Finally, extensive real-world experiments show that our proposed system improves recognition accuracy by up to 15 percent while achieving the same level of system overhead compared to the existing face recognition system (OpenCV algorithms) on smart glasses.
Weitao Xu, Yiran Shen 0001, Neil W. Bergmann, Wen Hu 0001
IEEE Trans. Mob. Comput.1
2017 CapSense: Capacitor-based Activity Sensing for Kinetic Energy Harvesting Powered Wearable Devices
abstract
We propose a new activity sensing method, CapSense, which detects activities of daily living (ADL) by sampling the voltage of the kinetic energy harvesting (KEH) capacitor at an ultra low sampling rate. Unlike conventional sensors that generate only instantaneous motion information of the subject, KEH capacitors accumulate and store human generated energy over time. Given that humans produce kinetic energy at distinct rates for different ADL, the KEH capacitor can be sampled only once in a while to observe the energy generation rate and identify the current activity. Thus, with CapSense, it is possible to avoid collecting time series motion data at high frequency, which promises significant power saving for the sensing device. We prototype a shoe-mounted KEH-powered wearable device and conduct experiments with 10 subjects for detecting 5 different activities. Our results show that compared to the existing time-series-based activity recognition, CapSense reduces sampling-induced power consumption by 99% and the overall system power, after considering wireless transmissions, by 75%. CapSense recognizes activities with up to 90%.
Guohao Lan, Dong Ma 0001, Weitao Xu, Mahbub Hassan, Wen Hu 0001
MobiQuitous3
2017 Unobtrusive User Verification using Piezoelectric Energy Harvesting
abstract
With the capability to harvest energy from low frequency motions or vibrations, piezoelectric energy harvesting has become a promising solution to achieve self-powered wearable system. Apart from generating energy to power the wearable devices, the output electricity signal of the PEH can also be used as an information source as it reflects the activity or motion patterns of the user. In this paper, we have designed and built an insole-based user authentication system by leveraging the AC voltage generated by the PEH during human walking. Meanwhile, the generated power is also collected and stored, which could be later used as the power source of the mobile system. By using a dataset of 20 subjects, we have demonstrated that our system can achieve 89.76% of human recognition accuracy when using only one gait cycle signal, and the accuracy can be further increased to 95.86% when two gait cycles are utilized.
Dong Ma 0001, Guohao Lan, Weitao Xu, Mahbub Hassan, Wen Hu 0001
MobiQuitous3
2017 WiCare: Towards In-Situ Breath Monitoring
abstract
Respiratory conditions significantly impact the health of individuals in the modern society. Long-term breath monitoring is critical for diagnosing the onset of various chronic respiratory diseases. Traditional breathing monitoring methods rely on wearable devices (e.q. face masks or chest bands) which are intrusive and uncomfortable. Recent research has demonstrated that it is possible to use device-free WiFi sensing to monitor breathing. However, these approaches only work when the monitored individual is stationary, i.e., sleeping or sitting perfectly still. In this paper, we propose WiCare, a system that employs the off-the-shelf WiFi devices and is able to monitor in-situ breathing rate in a natural setting where the individual can perform actions such as reading, writing, using phone, etc, which we refer to as micro motions. WiCare exploits Channel State Information (CSI) of WiFi data and can effectively distinguish breathing from the micro motions performed by the monitored individuals. The key idea is that certain specific subcarriers carry strong imprints of breathing motions because of the multipath effect and frequency and spacial diversity of MIMO systems. We model breathing signals as periodical sinusoidal waves and use curve fitting realised by interior point non-linear optimisation to identify breath in time series of each subcarrier. The goodness of fit measured by Dynamic Time Warping is exploited to select subcarriers that effectively capture breathing. Independent component analysis is used to precisely isolate the breathing signals. We recruit five participants to perform 9 common micro motions. Our extensive experiments show WiCare can accurately distinguish breathing from the micro motions and estimate breath rate with an average accuracy of over 90%. WiCare also outperforms the state-of-the-art breath rate estimation methods by up to 80%. WiCare represents a first and important step towards in-situ breath monitoring in natural settings.
Jin Zhang 0013, Weitao Xu, Wen Hu 0001, Salil S. Kanhere
MobiQuitous2
2017 KEH-Gait: Towards a Mobile Healthcare User Authentication System by Kinetic Energy Harvesting
Weitao Xu, Guohao Lan, Sara Khalifa, Neil W. Bergmann, Mahbub Hassan, Wen Hu 0001
NDSS1
2017 VEH-COM: Demodulating vibration energy harvesting for short range communication
abstract
This paper investigates the possibility of using a vibration energy harvesting (VEH) device as a communication receiver. By modulating the ambient vibration energy using a transmitting speaker, and demodulating the harvested power at the receiving VEH, we aim to transmit small amounts of data at low rates between two proximate devices. The key advantage of using VEH as a receiver is that the modulated sound waves can be successfully demodulated directly from the harvested power without employing the power-consuming digital signal processing (DSP), which makes a VEH receiver significantly more power efficient than a conventional microphone-based decoder. To address the extremely narrow bandwidth of VEH, we design a simple ON-OFF keying modulation, but optimized for VEH hardware. Experiments with a real VEH device shows that, at a distance of 2 cm, a laptop speaker with the proposed modulation scheme can achieve 30 bps communication for a target bit error rate of less than 1%, which would enable many emerging short range applications, such as mobile payment. The communication range of a laptop can be extended to 80 cm for 5 bps, allowing a range of other audio-based device-to-device communications, such as a web advertisement on a laptop browser transferring tokens to a nearby smartphone. We also demonstrate that the proposed VEH-based sound decoding is resilient to background noise, thanks to its extremely narrow power harvesting bandwidth, which works as a natural noise filter.
Guohao Lan, Weitao Xu, Sara Khalifa, Mahbub Hassan, Wen Hu 0001
PerCom2
2017 Accelerometer and Fuzzy Vault-Based Secure Group Key Generation and Sharing Protocol for Smart Wearables
abstract
The increased usage of smart wearables in various applications, specifically in health-care, emphasizes the need for secure communication to transmit sensitive health-data. In a practical scenario, where multiple devices are carried by a person, a common secret key is essential for secure group communication. Group key generation and sharing among wearables have received very little attention in the literature due to the underlying challenges: 1) difficulty in obtaining a good source of randomness to generate strong cryptographic keys, and 2) finding a common feature among all the devices to share the key. In this paper, we present a novel solution to generate and distribute group secret keys by exploiting on-board accelerometer sensor and the unique walking style of the user, i.e., gait. We propose a method to identify the suitable samples of accelerometer data during all routine activities of a subject to generate the keys with high entropy. In our scheme, the smartphone placed on waist employs fuzzy vault, a cryptographic construct, and utilizes the acceleration due to gait, a common characteristic extracted on all wearable devices to share the secret key. We implement our solution on commercially available off-the-shelf smart wearables, measure the system performance, and conduct experiments with multiple subjects. Our results demonstrate that the proposed solution has a bit rate of 750 b/s, low system overhead, distributes the key securely and quickly to all legitimate devices, and is suitable for practical applications.
Girish Revadigar, Chitra Javali, Weitao Xu, Athanasios V. Vasilakos, Wen Hu 0001, Sanjay K. Jha
IEEE Trans. Inf. Forensics Secur.3
2017 Gait-Key: A Gait-Based Shared Secret Key Generation Protocol for Wearable Devices
abstract
Recent years have witnessed a remarkable growth in the number of smart wearable devices. For many of these devices, an important security issue is to establish an authenticated communication channel between legitimate devices to protect the subsequent communications. Due to the wireless nature of the communication and the extreme resource constraints of sensor devices, providing secure, efficient, and user-friendly device pairing is a challenging task. Traditional solutions for device pairing mostly depend on key predistribution, which is unsuitable for wearable devices in many ways. In this article, we design Gait-Key, a shared secret key generation scheme that allows two legitimate devices to establish a common cryptographic key by exploiting users’ walking characteristics (gait). The intuition is that the sensors on different locations on the same body experience similar accelerometer signals when the user is walking. However, one main challenge is that the accelerometer also captures motion signals produced by other body parts (e.g., swinging arms). We address this issue by using the blind source separation technique to extract the informative signal produced by the unique gait patterns. Our experimental results show that Gait-Key can generate a common 128-bit key for two legitimate devices with 98.3% probability. To demonstrate the feasibility, the proposed key generation scheme is implemented on modern smartphones. The evaluation results show that the proposed scheme can run in real time on modern mobile devices and incurs low system overhead.
Weitao Xu, Chitra Javali, Girish Revadigar, Chengwen Luo 0001, Neil W. Bergmann, Wen Hu 0001
ACM Trans. Sens. Networks1
2016 NaviGlass: Indoor Localisation Using Smart Glasses
Yongtuo Zhang, Wen Hu 0001, Weitao Xu, Hongkai Wen 0001, Chun Tung Chou
EWSN3
2016 Walkie-Talkie: Motion-Assisted Automatic Key Generation for Secure On-Body Device Communication
abstract
Ubiquity of wearable and implantable devices sparks a new set of mobile computing applications that leverage the prolific information of sensors. For many of these applications, to ensure the security of communication between legitimate devices is a crucial problem. In this paper, we design Walkie-Talkie, a shared secret key generation scheme that allows two legitimate devices to establish a common cryptographic key by exploiting users' walking characteristics (gait). The intuition is that the sensors on different locations of the same body experience similar accelerometer signal when the user is walking. However, the accelerometer also captures motion signal produced by other body parts (e.g., swinging arms). We address this issue by employing Blind Source Separation (BSS) technique to extract the informative signal produced by the unique gait pattern. Our experimental results show that the keys generated by two independent devices on the same body are able to achieve up to 100% bit agreement rate. To demonstrate the feasibility, we implement the proposed key generation scheme on modern smartphones. The evaluation results show that the proposed scheme can run in real-time on modern mobile devices and incurs low system overhead.
Weitao Xu, Girish Revadigar, Chengwen Luo 0001, Neil W. Bergmann, Wen Hu 0001
IPSN1
2016 Sensor-Assisted Face Recognition System on Smart Glass via Multi-View Sparse Representation Classification
abstract
Face recognition is one of the most popular research problems on various platforms. New research issues arise when it comes to resource constrained devices, such as smart glasses, due to the overwhelming computation and energy requirements of the accurate face recognition methods. In this paper, we propose a robust and efficient sensor-assisted face recognition system on smart glasses by exploring the power of multimodal sensors including the camera and Inertial Measurement Unit (IMU) sensors. The system is based on a novel face recognition algorithm, namely Multi-view Sparse Representation Classification (MVSRC), by exploiting the prolific information among multi-view face images. To improve the efficiency of MVSRC on smart glasses, we propose a novel sampling optimization strategy using the less expensive inertial sensors. Our evaluations on public and private datasets show that the proposed method is up to 10% more accurate than the state-of-the-art multi-view face recognition methods while its computation cost is in the same order as an efficient benchmark method (e.g., Eigenfaces). Finally, extensive real-world experiments show that our proposed system improves recognition accuracy by up to 15% while achieving the same level of system overhead compared to the existing face recognition system (OpenCV algorithms) on smart glasses.
Weitao Xu, Yiran Shen 0001, Neil W. Bergmann, Wen Hu 0001
IPSN1
2015 Poster: An Online Approach for Gait Recognition on Smart Glasses
abstract
With the fast development and increasing population of the wearable devices involves in our daily life, the security of the privacy information on those devices is attracting significant attentions. One of the possible solution is to enable the devices to recognise the real owner with authentication system. Biometrics recognition is popular used for authentication systems. The biometrics used including faces, fingerprints, gait cycles and etc. Using gait cycles as the criteria for identities recognition is superior than other biometrics as the gait information can be collected by the IMU sensors which are most popular embedded on portable devices and they cannot be reproduced by the invaders. We propose, Securitas, the continuous authentication system exploits the information from IMU sensors on the smart glasses to distinguish different wearers.
Yiran Shen 0001, Chengwen Luo 0001, Weitao Xu, Wen Hu 0001
SenSys3
2015 Mobile Applications Based on Smart Wearable Devices
abstract
Ubiquity of wearable devices sparked a new set of mobile computing applications that leverage the prolific information of sensors. I will focus on two main research questions: face recognition on smart glass and gait recognition on smart watch. Face recognition is one of the most popular research problems on various platforms. New research issues arise when it comes to resource constrained devices, such as smart glasses, due to the overwhelming computation and energy requirements of the accurate face recognition methods. Biometric gait recognition refers to verifying or identifying persons by their walking style, and it provides a unobtrusive way to authenticate the user and unlock the smart watches.
Weitao Xu
SenSys1
2015 Poster: Robust and Efficient Sensor-assisted Face Recognition System on Smart Glass
abstract
Face recognition is one of the most popular research problems on various platforms. New research issues arise when it comes to resource constrained devices, such as smart glasses, due to the overwhelming computation and energy requirements of the accurate face recognition methods. In this paper, we have prototyped a robust and efficient sensor-assisted face recognition system on smart glasses by exploring the power of multimodal sensors including the camera and Inertial Measurement Unit (IMU) sensors. Evaluation shows that the prototyped system is up to 10% more accurate than the state-of-the-art face recognition methods while its computational cost is in the same order as an efficient benchmark method (e.g., Eigenface).
Weitao Xu, Yiran Shen 0001, Neil W. Bergmann, Wen Hu 0001
SenSys1