Jun Han 0001

dblp:02/3721-1 · DBLP profile ↗
← Back
42ranked-venue papers
4as first author
27since 2021 · last 2026
0000-0003-0798-704XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 27 · 2 first-author · 17 since 2021Security and privacy · 12 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Hide-and-Sweep: Detecting Concealed Cameras via LED Illumination Sweeps
abstract
Hidden cameras have increasingly infiltrated hotel and Airbnb rooms, posing serious privacy risks. Detecting such cameras is challenging because they are visually inconspicuous and often embedded inside everyday objects. Even worse, existing handheld detectors are manual and also rely on single-angle illumination and hence suffer from high false-positive rates. We present SweepLED (pronounced "sweepled")1, a practical hidden camera detection system that operates on a commodity smartphone augmented with an unobtrusive LED-embedded case. SweepLED performs LED sweeping - a controlled sequence of multi-angle illumination - while the user simply holds the phone still by hand, enabling the camera to capture how reflections evolve under changing lighting. This reveals stable, lens-specific cues that distinguish hidden camera lenses from ordinary reflective objects, enabling robust detection with low user effort. We implement SweepLED using a compact hardware add-on and evaluate it in realistic environments containing 12 hidden-camera objects and 18 commonly reflective non-camera items. Our results demonstrate that SweepLED provides accurate and reliable hidden-camera detection using only unobtrusive smartphone-compatible hardware, achieving approximately 94% detection accuracy with a sweep time of under 5 s and a core component cost of less than USD $7.
Jonghyuk Yun, Jaeyoung Moon, Yunseo Park, Sean Rui Xiang Tan, Rajesh Krishna Balan, Jun Han 0001
MobiSys7
2026 Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-Channel
Rui Xiao 0002, Sibo Feng, Soundarya Ramesh, Jun Han 0001, Jinsong Han
NDSS4
2026 WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation Attack
Bangjie Sun, Terence Sim, Jun Han 0001
SP5
2025 CAMPrints: Leveraging the "Fingerprints" of Digital Cameras to Combat Image Theft
abstract
Photo sharing is increasingly popular, driven by social media platforms like Instagram and services such as Flickr and Google Photos. However, this growth has been accompanied by significant issues, particularly image theft. To address this issue, we introduce CAMPrints, a robust system for detecting image theft. CAMPrints verifies whether edited images found online contain camera fingerprints matching those of user-provided reference images. The system overcomes the challenges of identifying images altered by diverse image processing operations. We select a small yet representative set of operations by categorizing them based on their impact on pixel values and locations. A deep-learning model is trained to recognize and compare camera noise patterns pre- and post-editing. We conduct real-world evaluations involving 36 cameras across eight make-and-model combinations, along with over 40 image processing operations applied to more than 4,000 images. CAMPrints achieves an average AUC of 0.92, significantly outperforming the state-of-the-art methods by up to 1.8 times.
Bangjie Sun, Mun Choon Chan, Jun Han 0001
MobiSys3
2025 Lend Me Your Beam: Privacy Implications of Plaintext Beamforming Feedback in WiFi
Rui Xiao 0002, Xiankai Chen, Yinghui He, Jun Han 0001, Jinsong Han
NDSS4
2025 UniKey: Enabling Surface-Based Typing with Commodity Smartwatches via Cross-Modal Learning
Sean Rui Xiang Tan, Mun Choon Chan, Jun Han 0001
UIST3
2024 Poster: Exploiting Keystroke Dynamics via mmWave Radar for Application Profiling
abstract
Even seemingly innocuous computer usage information often leads to targeted privacy attacks. In this poster, we present mmProfiler, a novel privacy attack that aims to remotely infer user's running application. mmProfiler leverages mmWave radar-based vibrometry to capture minute vibration induced by the victim's keystrokes. Captured data is then analyzed to extract keystroke patterns, or keystroke dynamics, used to profile the running application the user is engaged with. Our preliminary experiment demonstrates the potential of mmProfiler, with 84% accuracy in discerning between five user applications.
Changgeon Kang, Dongjin Seo, Sihun Yang, Jun Han 0001
MobiSys4
2024 Poster: Towards Acoustic-Based Tagless Object Tracking with Smartwatches
abstract
Locating and replacing lost items can be a time-consuming and demanding task, requiring a significant amount of resources. While tag-based object tracking systems like Apple's AirTags are suggested, attaching tags on objects can compromise their usability and become costly as the number of objects increases. To mitigate this challenge, we propose AcousTrack, a novel object-tracking system that eliminates the need for additional tags. AcousTrack instead leverages smartwatches to capture acoustic signals emitted when objects come into contact with surfaces. These acoustic signals contain unique physical characteristics of both objects and surfaces, facilitating the identification of object types and their respective locations. In our preliminary evaluation, we analyze the sounds emitted by three different objects positioned across three varying locations, achieving an accuracy of 92.2% in object classification and 98.3% in location classification.
Gyuyeon Kim, Jun Han 0001
MobiSys3
2024 PowDew: Detecting Counterfeit Powdered Food Products using a Commodity Smartphone
abstract
The prevalence of counterfeit infant formulas worldwide poses serious threats to infant health and safety, a concern highlighted by the notorious Melamine Milk Scandal that affected hundreds of thousands of children. The primary challenge in detecting counterfeit formulas lies in their sophisticated adulteration and substitution techniques. Such detection is feasible only in laboratory settings, making it nearly impossible for average consumers to test the formula before feeding their infants. To address this problem, we propose PowDew, a novel and practical system for detecting counterfeit infant formula that utilizes only a commodity smartphone. PowDew operates by capturing and analyzing the interaction of a water droplet with the powdered formula, focusing on the droplet motion, namely its spreading and penetration. Our insight is that the droplet motions are governed by powder-specific properties such as wettability and porosity. PowDew analyzes the subtle differences in droplet motions, and infers the formula's authenticity. To demonstrate PowDew's effectiveness, we implement PowDew and conduct comprehensive real-world experiments under varying conditions with different brands of powdered infant formula and adulterants. Our experiments result in a total of 12,000 minutes of video recordings of the droplet motions on various infant formulas, including authentic and altered. Our experiments demonstrate that PowDew yields an overall detection accuracy of up to 96.1%.
Jonghyuk Yun, Kyoosik Lee, Kichang Lee, Bangjie Sun, JeongGil Ko, Inseok Hwang 0001, Jun Han 0001
MobiSys8
2024 Poster: Towards Counterfeit Powdered Food Products Detection using a Commodity Smartphone
abstract
The rise of counterfeit powdered food products, exemplified by notorious incidents such as the Melamine Milk Scandal, poses significant risks to consumers. The primary challenge in identifying these counterfeit products comes from their intricate adulteration and substitution techniques. Currently, such identification methods are only viable in laboratory settings, making average consumers nearly impossible to authenticate their products. To address this limitation, we propose PowDew, a novel system that employs a smartphone to detect counterfeit powdered food products. PowDew utilizes the powder's physical property, namely droplet motion, as a basis for verification. Through real-world experiments, PowDew demonstrate a practicality with achieving an overall detection accuracy of up to 96.1%.
Jonghyuk Yun, Kyoosik Lee, Kichang Lee, Bangjie Sun, JeongGil Ko, Inseok Hwang 0001, Jun Han 0001
MobiSys8
2024 Don't Crosstalk to Me: Origami Structure-Augmented Sensing for Scalable Surface Pressure Monitoring
abstract
This paper presents OMSense, an intelligent surface solution that leverages origami-inspired metasurfaces to allow scalable and precise surface pressure sensing. People interact with various surfaces daily, and these interactions cause the surfaces to deform, a process that can be captured by sensors. This interaction can be utilized in various forms of human-computer interaction and human monitoring, enabling new use cases. However, existing surface sensing schemes are either expensive, difficult to scale, or low-precision due to signal leakage in multiplex design. To solve this problem, we propose OMSense, which adopts the multiplex matrix sensing design and incorporates a 3D metastructure to reduce the shared physical connection-induced signal leakage. In addition to this physical augmentation, OMSense adopts a circuit-guided CNN to mitigate the circuit connection-induced signal leakage (ghosting). We 3D print a circuit-integrated metastructure and evaluate the sensor unit accuracy. OMSense achieves up to 2× sensor unit activation detection F1 score compared to the baselines.
Shubham Rohal, Dong Yoon Lee, Joshua Zhang, Jonathon Fagert, Jun Han 0001, Shijia Pan
SenSys6
2024 Poster: Towards Privacy Preserving Patient State Classification in Psychiatric Seclusion Room using mmWave Radar
abstract
Continuous monitoring of patients in psychiatric seclusion rooms is essential yet challenging, particularly with staff shortages that can delay responses to sudden changes in patient conditions. To this end, we propose PsiMo, a remote patient state monitoring system using mmWave Frequency Modulated Continuous Wave (FMCW) radar. Unlike existing vision-based or wearable systems, PsiMo captures patient movements without compromising privacy or risking potential self-harm. Our system continuously monitors patient's state of motion to alert medical staff in the event of abnormal conditions, such as agitation. Our preliminary evaluation shows PsiMo achieves 97.0% accuracy in patient state classification, demonstrating its potential for effective, non-contact monitoring.
Dongjin Seo, Jonghyuk Yun, Seongjin Wang, Jaewoo Son, Jun Han 0001
SenSys5
2024 Can I Hear Your Face? Pervasive Attack on Voice Authentication Systems with a Single Face Image
Bangjie Sun, Terence Sim, Jun Han 0001
USENIX Security Symposium4
2023 MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage Signals
abstract
GPU cryptojacking is an attack that hijacks GPU resources of victims for cryptocurrency mining. Such attack is becoming an emerging threat to both local hosts and cloud platforms. These attacks result in huge economic losses for the victims due to significant power consumption by cryptomining applications. Unfortunately, there are no adequate solutions to detect such attacks. In this paper, we propose MagTracer, a novel GPU cryptojacking detection system that leverages magnetic leakage signals emanating from GPUs. We make a key observation that GPUs emanate a distinct magnetic signal while mining, which can be attributed to the core feature of all cryptomining algorithms (as they are compute-intensive as well as memory-bounded). We design and implement a proof-of-concept detection system to demonstrate MagTracer's feasibility. We evaluate MagTracer on 14 heterogeneous GPU models and achieve a high average true positive rate of over 98% and a low false positive rate below 0.7% in all cases. Furthermore, our comprehensive evaluation confirms that MagTracer is scalable across different mining applications and robust against several targeted attacks.
Rui Xiao 0002, Soundarya Ramesh, Jun Han 0001, Jinsong Han
MobiCom4
2023 Demo: Exploiting Indices for Man-in-the-Middle Attacks on Collaborative Unpooling Autoencoders
abstract
In this demonstration, we introduce the vulnerability of indices in unpooling autoencoders. We show that this small factor can be maliciously exploited by performing man-in-the-middle attacks to eavesdrop on the victim's data, resulting in reconstruction and adversarial attacks. Such attacks especially make systems that integrate collaborative inference operations vulnerable. This demo presentation will empirically show the feasibility of index-based attacks by launching reconstruction and adversarial attacks on embedded/mobile computing platforms.
Kichang Lee, Jonghyuk Yun, Jun Han 0001, JeongGil Ko
MobiSys3
2023 Characterizing and Mitigating Touchtone Eavesdropping in Smartphone Motion Sensors
abstract
Smartphone motion sensors provide cybersecurity attackers with a stealthy way to eavesdrop on nearby acoustic information. Eavesdropping on touchtones emitted by smartphone speakers when users input numbers into their phones exposes sensitive information such as credit card information, banking PINs, and social security card numbers to malicious applications with access to only motion sensor data. This work characterizes this new security threat of touchtone eavesdropping by providing an analysis based on physics and signal processing theory. We show that advanced adversaries who selectively integrate data from multiple motion sensors and multiple sensor axes can achieve over 99% accuracy on recognizing 12 unique touchtones. We further design, analyze, and evaluate several mitigations which could be implemented in a smartphone update. We found that some apparent mitigations such as low-pass filters can undesirably reduce the motion sensor data to benign applications by 83% but only reduce an advanced adversary’s accuracy by less than one percent. Other more informed designs such as anti-aliasing filters can fully preserve the motion sensor data to support benign application functionality while reducing attack accuracy by 50.1%.
Connor Bolton, Yan Long 0002, Jun Han 0001, Josiah D. Hester, Kevin Fu
RAID3
2023 Testing Masks and Air Filters With Your Smartphones
abstract
The demand for masks and air filters with effective filtration capabilities is skyrocketing as there are many applications that require protecting users from inhaling air pollutants or hazardous particles. Unfortunately, we are witnessing a surge in the number of counterfeit and substandard filters attributed to malicious and inept manufacturers. Hence, users are left vulnerable in not knowing which products are reliable. Exacerbating the problem, there are diverse filter standards, each with a unique expression for filtration efficiencies, adding to user confusion. Moreover, the average user lacks the necessary tools, techniques, and knowledge to independently verify the filtration efficiency. Specifically, state-of-the-art solutions are lab-based machines that are extremely expensive and difficult to access for the general public. To solve this problem, we propose FilterOp, a novel smartphone-based mask and filter testing system. FilterOp is a practical solution that allows a user to estimate the filtration efficiency of a mask or a filter using only a pair of commodity smartphones. The novelty of FilterOp comes from its use of light absorption and scattering effects, observed when light propagates through the filter. We evaluate FilterOp in comprehensive real-world experiments using 256 filter instances across 27 different make-and-model products with varying filtration efficiencies. Comparing our results to those obtained with a state-of-the-art government-certified testing machine, we observe that FilterOp yields comparable results with a low mean absolute error of 2.7%, and detects substandard products with an overall accuracy of 96%.
Bangjie Sun, Kanav Sabharwal, Gyuyeon Kim, Mun Choon Chan, Jun Han 0001
SenSys5
2022 TickTock: Detecting Microphone Status in Laptops Leveraging Electromagnetic Leakage of Clock Signals
abstract
We are witnessing a heightened surge in remote privacy attacks on laptop computers. These attacks often exploit malware to remotely gain access to webcams and microphones in order to spy on the victim users. While webcam attacks are somewhat defended with widely available commercial webcam privacy covers, unfortunately, there are no adequate solutions to thwart the attacks on mics despite recent industry efforts. As a first step towards defending against such attacks on laptop mics, we propose TickTock, a novel mic on/off status detection system. To achieve this, TickTock externally probes the electromagnetic (EM) emanations that stem from the connectors and cables of the laptop circuitry carrying mic clock signals. This is possible because the mic clock signals are only input during the mic recording state, causing resulting emanations. We design and implement a proof-of-concept system to demonstrate TickTock's feasibility. Furthermore, we comprehensively evaluate TickTock on a total of 30 popular laptops executing a variety of applications to successfully detect mic status in 27 laptops. Of these, TickTock consistently identifies mic recording with high true positive and negative rates.
Soundarya Ramesh, Ghozali Suhariyanto Hadi, Sihun Yang, Mun Choon Chan, Jun Han 0001
CCS5
2022 Shakespeer: Verifying the Co-presence of Smart Devices and Users via Vibration
abstract
Securely and unobtrusively authenticating a user is an important problem given the pervasiveness of smartphones. Existing approaches, such as password, fingerprints, or facial recognition, are vulnerable to various attacks, and/or degrade usability. To overcome this problem, we propose Shakespeer, which differentiates users based on uniqueness in the propagation of haptic vibrations through hand, forearm muscles and bones. These vibrations are generated by the user’s smartphone and sensed by their smartphone and smartwatch. The unobtrusive haptic vibrational response makes this biometric feature hard to be replicated. Meanwhile, it provides the co-presence detection function, which allows the devices to confirm the co-presence on the user’s body. We implement Shakespeer using smartphones and smartwatches and tested it across 32 subjects under real-world settings. From our preliminary exploratory evaluation, Shakespeer achieves an equal error rate (EER) of 0.59 %, demonstrating its feasibility.
Gucheng Wang, Jay Prakash, Terence Sim, Jun Han 0001
ICPR4
2022 EarChew: towards identifying chewing side preference using earables
abstract
Chewing Side Preference (CSP) is a dental habit that causes one to consistently and predominantly chew on only one side of the mouth, potentially causing jawbone joint disorders. Unfortunately, the state-of-the-art solutions are limited in continuously monitoring the CSP in potential patients. Hence, we present EarChew, which utilizes an earable worn on the patient's ear to be able to identify the chewing side - i.e., left or right. EarChew utilizes the microphone embedded in the earable to capture the minute but inherent vibrations caused by each chewing action to be able to identify the chewing side. We present a preliminary evaluation with a participant chewing on almonds and demonstrate a promising preliminary result of 96% average accuracy.
Sungtae Kim, Jun Han 0001
MobiSys3
2022 Detecting counterfeit liquid food products in a sealed bottle using a smartphone camera
abstract
We are witnessing a surge in the reported cases of counterfeit liquid products in the market including olive oil, honey, and alcohol. Counterfeiters often adulterate the liquid products by replacing a large portion of the authentic content with cheaper substitutes (e.g., mixing vodka with cheaper alcohol or potentially toxic methanol). Exacerbating the problem, the counterfeits are packaged and sealed to factory standards, rendering it extremely difficult for an average consumer to identify them. While solutions exist, they are often impractical for the general public as they require specialized and costly equipment. To overcome these limitations, we propose LiquidHash, a novel counterfeit liquid food product detection system. LiquidHash is a practical solution that only requires the use of a commodity smartphone to detect adulterated liquid products without opening the bottles. LiquidHash works by detecting and tracking the shape and movement of air bubbles that form inside the bottles. We implement LiquidHash and evaluate its feasibility with real-world experiments under varying conditions with a total of more than 500 minutes of video recording and observe an overall detection accuracy of up to 95%.
Bangjie Sun, Sean Rui Xiang Tan, Zhiwei Ren, Mun Choon Chan, Jun Han 0001
MobiSys5
2022 On utilizing smartphone cameras to detect counterfeit liquid food products
abstract
Counterfeit liquid food products, including olive oil, honey and alcohol, are continuing to pose severe threats to the general public as counterfeiters adulterate the authentic content with cheaper and potentially harmful substitutes, and package them in authentic bottles. Existing solutions are often impractical for the general public as they require specialized and costly equipment as well as taking liquid samples. We overcome these limitations by proposing LiquidHash, a novel detection system that only requires the use of a commodity smartphone to detect adulterated liquid products without opening the bottles. LiquidHash leverages computer vision and machine learning techniques to extract characteristics of air bubbles formed by flipping a bottle. We implement LiquidHash and evaluate its feasibility with real-world experiments and achieve an overall detection accuracy of up to 95%.
Bangjie Sun, Sean Rui Xiang Tan, Zhiwei Ren, Mun Choon Chan, Jun Han 0001
MobiSys5
2021 FastZIP: faster and more secure zero-interaction pairing
abstract
With the advent of the Internet of Things (IoT), establishing a secure channel between smart devices becomes crucial. Recent research proposes zero-interaction pairing (ZIP), which enables pairing without user assistance by utilizing devices' physical context (e.g., ambient audio) to obtain a shared secret key. The state-of-the-art ZIP schemes suffer from three limitations: (1) prolonged pairing time (i.e., minutes or hours), (2) vulnerability to brute-force offline attacks on a shared key, and (3) susceptibility to attacks caused by predictable context (e.g., replay attack) because they rely on limited entropy of physical context to protect a shared key. We address these limitations, proposing FastZIP, a novel ZIP scheme that significantly reduces pairing time while preventing offline and predictable context attacks. In particular, we adapt a recently introduced Fuzzy Password-Authenticated Key Exchange (fPAKE) protocol and utilize sensor fusion, maximizing their advantages. We instantiate FastZIP for intra-car device pairing to demonstrate its feasibility and show how the design of FastZIP can be adapted to other ZIP use cases. We implement FastZIP and evaluate it by driving four cars for a total of 800 km. We achieve up to three times shorter pairing time compared to the state-of-the-art ZIP schemes while assuring robust security with adversarial error rates below 0.5%.
Mikhail Fomichev, Julia Hesse, Lars Almon, Timm Lippert, Jun Han 0001, Matthias Hollick
MobiSys5
2021 LAPD: Hidden Spy Camera Detection using Smartphone Time-of-Flight Sensors
abstract
Tiny hidden spy cameras concealed in sensitive locations including hotels and bathrooms are becoming a significant threat worldwide. These hidden cameras are easily purchasable and are extremely difficult to find with the naked eye due to their small form factor. The state-of-the-art solutions that aim to detect these cameras are limited as they require specialized equipment and yield low detection rates. Recent academic works propose to analyze the wireless traffic that hidden cameras generate. These proposals, however, are also limited because they assume wireless video streaming, while only being able to detect the presence of the hidden cameras, and not their locations. To overcome these limitations, we present LAPD, a novel hidden camera detection and localization system that leverages the time-of-flight (ToF) sensor on commodity smartphones. We implement LAPD as a smartphone app that emits laser signals from the ToF sensor, and use computer vision and machine learning techniques to locate the unique reflections from hidden cameras. We evaluate LAPD through comprehensive real-world experiments by recruiting 379 participants and observe that LAPD achieves an 88.9% hidden camera detection rate, while using just the naked eye yields only a 46.0% hidden camera detection rate.
Sriram Sami, Sean Rui Xiang Tan, Bangjie Sun, Jun Han 0001
SenSys4
2021 On Utilizing Smartphone Time-of-Flight Sensors to Detect Hidden Spy Cameras
abstract
Tiny spy cameras hidden in everyday objects are continuing to pose severe privacy threats to the general public as these cameras are often placed in sensitive locations such as hotels and restroom stalls. Commercially available "hidden camera detectors" have high false positive rates, and existing academic works detect (but cannot localize) only a subset of hidden cameras with wireless capabilities. We overcome these limitations by proposing LAPD, a novel hidden camera detection and localization system that leverages time-of-flight (ToF) sensors on commodity smartphones. LAPD is a smartphone app that detects hidden cameras in real-time by transmitting laser signals from the ToF sensor and searching for unique signatures representing reflections from hidden camera lenses. Using computer vision and machine learning techniques, LAPD achieves significantly higher hidden camera detection rates compared to the naked eye and hidden camera detectors.
Sriram Sami, Sean Rui Xiang Tan, Bangjie Sun, Jun Han 0001
SenSys4
2021 A Stealthy Location Identification Attack Exploiting Carrier Aggregation in Cellular Networks
Nitya Lakshmanan, Nishant Budhdev, Min Suk Kang, Mun Choon Chan, Jun Han 0001
USENIX Security Symposium5
2021 Acoustics to the Rescue: Physical Key Inference Attack Revisited
Soundarya Ramesh, Rui Xiao 0002, Anindya Maiti, Jong Taek Lee, Harini Ramprasad, Ananda Kumar, Murtuza Jadliwala, Jun Han 0001
USENIX Security Symposium8
2020 Poster Abstract: Don't Wait For Weight: Towards Weight Inference of Passengers and Luggage using Smartphone Camera
abstract
Proposals on weighing passengers and their carry-on luggage prior to flights are gaining traction in the airline industry for fuel efficiency purposes. Adoption of such proposals are difficult in practice, however, as requiring passengers to step on weighing scales would incur significant overhead heavily affecting already busy airports. To solve this problem, we propose CamWeight, a novel vision-based weight inference system that takes video feed of off-the-shelf elastic mat (e.g., yoga mat) placed on the floor as the passenger walks over it while pulling his/her wheeled carry-on luggage. CamWeight makes use of inherent properties including amplitude and recovery time of strain, or mat deformation caused by footsteps and luggage wheels. Due to the inherent design of CamWeight, it incurs no additional time for weighing, while being cost effective. We present a preliminary proof-of-concept evaluation by varying weights in a luggage from 2.5 kg to 20 kg to achieve prediction mean absolute error of approximately 2 kg.
Jong Taek Lee, Yu Kai Lim, Jun Han 0001
IPSN3
2020 Spying with your robot vacuum cleaner: eavesdropping via lidar sensors
abstract
Eavesdropping on private conversations is one of the most common yet detrimental threats to privacy. A number of recent works have explored side-channels on smart devices for recording sounds without permission. This paper presents LidarPhone, a novel acoustic side-channel attack through the lidar sensors equipped in popular commodity robot vacuum cleaners. The core idea is to repurpose the lidar to a laser-based microphone that can sense sounds from subtle vibrations induced on nearby objects. LidarPhone carefully processes and extracts traces of sound signals from inherently noisy laser reflections to capture privacy sensitive information (such as speech emitted by a victim's computer speaker as the victim is engaged in a teleconferencing meeting; or known music clips from television shows emitted by a victim's TV set, potentially leaking the victim's political orientation or viewing preferences). We implement LidarPhone on a Xiaomi Roborock vacuum cleaning robot and evaluate the feasibility of the attack through comprehensive real-world experiments. We use the prototype to collect both spoken digits and music played by a computer speaker and a TV soundbar, of more than 30k utterances totaling over 19 hours of recorded audio. LidarPhone achieves approximately 91% and 90% average accuracies of digit and music classifications, respectively.
Sriram Sami, Yimin Dai, Sean Rui Xiang Tan, Nirupam Roy, Jun Han 0001
SenSys5
2020 LidarPhone: acoustic eavesdropping using a lidar sensor: poster abstract
abstract
Private conversations are an attractive target for malicious actors intending to conduct audio eavesdropping attacks. Previous works discovered unexpected vectors for these attacks, such as analyzing high-speed video of objects adjacent to sound sources, or using WiFi signal information. We propose LidarPhone, a novel side-channel attack that exploits the lidar sensors in commodity robot vacuum cleaners to perform acoustic eavesdropping attacks. LidarPhone is able to detect the minute vibrations induced on objects that are near audio sources, and extract meaningful signals from inherently noisy raw lidar returns. We evaluate a realistic scenario for potential victims: recovering privacy-sensitive digits (e.g., credit card numbers, social security numbers) emitted by computer speakers during teleconferencing calls. We implement LidarPhone on a Xiaomi Roborock vacuum cleaning robot and perform a comprehensive series of real-world experiments to determine its performance. LidarPhone achieves up to 91% accuracy for digit classification.
Sriram Sami, Sean Rui Xiang Tan, Yimin Dai, Nirupam Roy, Jun Han 0001
SenSys5
2020 PAS: Prediction-Based Actuation System for City-Scale Ridesharing Vehicular Mobile Crowdsensing
abstract
Vehicular mobile crowdsensing (MCS) enables many smart city applications. Ridesharing vehicle fleets provide promising solutions to MCS due to the advantages of low cost, easy maintenance, high mobility, and long operational time. However, as nondedicated mobile sensing platforms, the first priorities of these vehicles are delivering passengers, which may lead to poor sensing coverage quality. Therefore, to help MCS derive good (large and balanced) sensing coverage quality, an actuation system is required to dispatch vehicles with a limited amount of monetary budget. This article presents PAS, a prediction-based actuation system for city-wide ridesharing vehicular MCS to achieve optimal sensing coverage quality with a limited budget. In PAS, two prediction models forecast probabilities of potential near-future vehicle routes and ride requests across the city. Based on prediction results, a prediction-based actuation planning algorithm is proposed to decide which vehicles to actuate and the corresponding routes. Experiments on city-scale deployments and physical feature-based simulations show that our PAS achieves up to 40% more improvement in sensing coverage quality and up to 20% higher ride request matching rate than baselines. In addition, to achieve a similar level of sensing coverage quality as the baseline, our PAS only needs 10% budget.
Xinlei Chen, Susu Xu, Jun Han 0001, Haohao Fu, Xidong Pi, Carlee Joe-Wong, Yong Li 0008, Lin Zhang 0001, Hae Young Noh, Pei Zhang 0001
IEEE Internet Things J.3
2019 Secure pairing via video and IMU verification: demo abstract
abstract
Secure pairing is an important problem especially due to large number of IoT devices. In this paper, we propose PosePair++, to enable a camera to securely pair with IoT devices which are equipped with IMU sensors. Existing context-based pairing approaches do not adequately address this problem due to differing sensing modalities. To address this challenge, we propose to translate the signals from heterogeneous sensing modalities to a common space, namely 2D acceleration. In this demo, we present PosePair++'s robustness against different types of attackers (i.e., attackers that observe the user's motion, or attackers performing mimicking attack).
Carlos Ruiz Dominguez, Shijia Pan, Hae Young Noh, Pei Zhang 0001, Jun Han 0001
IPSN5
2019 SoundUAV: Fingerprinting Acoustic Emanations for Delivery Drone Authentication
abstract
Delivery drones may become potential targets for package theft. An adversary may launch a drone impersonation attack, where the adversary's drone purports to be a legitimate delivery drone. To protect against such attacks, authenticating drones is crucial. Existing authentication schemes based on digital certificates have been shown to be compromised by security breaches on certificate authorities. Thus, we propose SoundUAV as a second factor of authentication for drones that leverages uniqueness in acoustic emanations to fingerprint drones, even within the same make and model. This uniqueness is attributed to hardware defects in motors, making SoundUAV secure against impersonation and robust to large scale attacks. Further, SoundUAV requires no hardware modifications to drones as it utilizes the pervasive acoustic emanations. We perform preliminary evaluation on eleven drones and obtain a fingerprinting accuracy of 99.48%.
Soundarya Ramesh, Thomas Pathier, Jun Han 0001
MobiSys3
2019 Towards Precise Localization of E-Scooters Using Sidewalk Ramps
abstract
Electric scooters (e-scooters) are proliferating rapidly as an inexpensive mode of transportation. GPS equipped smartphones are used to guide riders from points A to B, but GPS is known to have hundreds of meters of error in areas where the line of sight to navigation satellites is fully or partially obscured. To address this problem, we present ScootLoc, which enables precise e-scooter localization, by leveraging physical characteristics of sidewalk ramps, to correct for GPS error. We show that e-scooters equipped with a gyroscope and an accelerometer are able to uniquely identify sidewalk ramps and match the ramp to its physical location, thereby augmenting noisy GPS based navigation systems. We implement ScootLoc and present a preliminary evaluation on a route containing ten ramps, achieving 97% classification accuracy.
Christian August Reksten-Monsen, Jun Han 0001
MobiSys2
2019 SurFi: detecting surveillance camera looping attacks with wi-fi channel state information
abstract
The proliferation of surveillance cameras has greatly improved the physical security of many security-critical properties including buildings, stores, and homes. However, recent surveillance camera looping attacks demonstrate new security threats --- adversaries can replay a seemingly benign video feed of a place of interest while trespassing or stealing valuables without getting caught. Unfortunately, such attacks are extremely difficult to detect in real-time due to cost and implementation constraints. In this paper, we propose SurFi to detect these attacks in real-time by utilizing commonly available Wi-Fi signals. In particular, we leverage that channel state information (CSI) from Wi-Fi signals also perceives human activities in the place of interest in addition to surveillance cameras. SurFi processes and correlates the live video feeds and the Wi-Fi CSI signals to detect any mismatches that would identify the presence of the surveillance camera looping attacks. SurFi does not require the deployment of additional infrastructure because Wi-Fi transceivers are easily found in the urban indoor environment. We design and implement the SurFi system and evaluate its effectiveness in detecting surveillance camera looping attacks. Our evaluation demonstrates that SurFi effectively identifies attacks with up to an attack detection accuracy of 98.8% and 0.1% false positive rate.
Nitya Lakshmanan, Inkyu Bang, Min Suk Kang, Jun Han 0001, Jong Taek Lee
WiSec4
2018 Do You Feel What I Hear? Enabling Autonomous IoT Device Pairing Using Different Sensor Types
abstract
Context-based pairing solutions increase the usability of IoT device pairing by eliminating any human involvement in the pairing process. This is possible by utilizing on-board sensors (with same sensing modalities) to capture a common physical context (e.g., ambient sound via each device's microphone). However, in a smart home scenario, it is impractical to assume that all devices will share a common sensing modality. For example, a motion detector is only equipped with an infrared sensor while Amazon Echo only has microphones. In this paper, we develop a new context-based pairing mechanism called Perceptio that uses time as the common factor across differing sensor types. By focusing on the event timing, rather than the specific event sensor data, Perceptio creates event fingerprints that can be matched across a variety of IoT devices. We propose Perceptio based on the idea that devices co-located within a physically secure boundary (e.g., single family house) can observe more events in common over time, as opposed to devices outside. Devices make use of the observed contextual information to provide entropy for Perceptio's pairing protocol. We design and implement Perceptio, and evaluate its effectiveness as an autonomous secure pairing solution. Our implementation demonstrates the ability to sufficiently distinguish between legitimate devices (placed within the boundary) and attacker devices (placed outside) by imposing a threshold on fingerprint similarity. Perceptio demonstrates an average fingerprint similarity of 94.9% between legitimate devices while even a hypothetical impossibly well-performing attacker yields only 68.9% between itself and a valid device.
Jun Han 0001, Albert Jin Chung, Manal Kumar Sinha, Madhumitha Harishankar, Shijia Pan, Hae Young Noh, Pei Zhang 0001, Patrick Tague
IEEE Symposium on Security and Privacy1
2018 Smart Home Occupant Identification via Sensor Fusion Across On-Object Devices
abstract
Occupant identification proves crucial in many smart home applications such as automated home control and activity recognition. Previous solutions are limited in terms of deployment costs, identification accuracy, or usability. We propose SenseTribute , a novel occupant identification solution that makes use of existing and prevalent on-object sensors that are originally designed to monitor the status of objects to which they are attached. SenseTribute extracts richer information content from such on-object sensors and analyzes the data to accurately identify the person interacting with the objects. This approach is based on the physical phenomenon that different occupants interact with objects in different ways. Moreover, SenseTribute may not rely on users’ true identities, so the approach works even without labeled training data. However, resolution of information from a single on-object sensor may not be sufficient to differentiate occupants, which may lead to errors in identification. To overcome this problem, SenseTribute operates over a sequence of events within a user activity, leveraging recent work on activity segmentation. We evaluate SenseTribute using real-world experiments by deploying sensors on five distinct objects in a kitchen and inviting participants to interact with the objects. We demonstrate that SenseTribute can correctly identify occupants in 96% of trials without labeled training data, while per-sensor identification yields only 74% accuracy even with training data.
Jun Han 0001, Shijia Pan, Manal Kumar Sinha, Hae Young Noh, Pei Zhang 0001, Patrick Tague
ACM Trans. Sens. Networks1
2017 Pitchln: eavesdropping via intelligible speech reconstruction using non-acoustic sensor fusion
abstract
Despite the advent of numerous Internet-of-Things (IoT) applications, recent research demonstrates potential side-channel vulnerabilities exploiting sensors which are used for event and environment monitoring. In this paper, we propose a new side-channel attack, where a network of distributed non-acoustic sensors can be exploited by an attacker to launch an eavesdropping attack by reconstructing intelligible speech signals. Specifically, we present PitchIn to demonstrate the feasibility of speech reconstruction from non-acoustic sensor data collected offline across networked devices. Unlike speech reconstruction which requires a high sampling frequency (e.g., > 5 KHz), typical applications using non-acoustic sensors do not rely on richly sampled data, presenting a challenge to the speech reconstruction attack. Hence, PitchIn leverages a distributed form of Time Interleaved Analog-Digital-Conversion (TIADC) to approximate a high sampling frequency, while maintaining low per-node sampling frequency. We demonstrate how distributed TI-ADC can be used to achieve intelligibility by processing an interleaved signal composed of different sensors across networked devices. We implement PitchIn and evaluate reconstructed speech signal intelligibility via user studies. PitchIn has word recognition accuracy as high as 79%. Though some additional work is required to improve accuracy, our results suggest that eavesdropping using a fusion of non-acoustic sensors is a real and practical threat.
Jun Han 0001, Albert Jin Chung, Patrick Tague
IPSN1
2017 Design Experiences in Minimalistic Flying Sensor Node Platform through SensorFly
abstract
Indoor emergency response situations, such as urban fire, are characterized by dangerous constantly changing operating environments with little access to situational information for first responders. In situ information about the conditions, such as the extent and evolution of an indoor fire, can augment rescue efforts and reduce risk to emergency personnel. Static sensor networks that are pre-deployed or manually deployed have been proposed but are less practical due to need for large infrastructure, lack of adaptivity, and limited coverage. Controlled-mobility in sensor networks, that is, the capability of nodes to move as per network needs can provide the desired autonomy to overcome these limitations. In this article, we present SensorFly, a controlled-mobile aerial sensor network platform for indoor emergency response application. The miniature, low-cost sensor platform has capabilities to self deploy, achieve three-dimensional sensing, and adapt to node and network disruptions in harsh environments. We describe hardware design trade-offs, the software architecture, and the implementation that enables limited-capability nodes to collectively achieve application goals. Through the indoor fire monitoring application scenario, we validate that the platform can achieve coverage and sensing accuracy that matches or exceeds static sensor networks and provide higher adaptability and autonomy.
Xinlei Chen, Aveek Purohit, Shijia Pan, Carlos Ruiz Dominguez, Jun Han 0001, Zheng Sun 0003, Frank Mokaya, Patrick Tague, Pei Zhang 0001
ACM Trans. Sens. Networks5
2014 Short paper: MVSec: secure and easy-to-use pairing of mobile devices with vehicles
abstract
With the increasing popularity of mobile devices, drivers and passengers will naturally want to connect their devices to their cars. Malicious entities can and likely will try to attack such systems in order to compromise other vehicular components or eavesdrop on privacy-sensitive information. It is imperative, therefore, to address security concerns from the onset of these technologies. While guaranteeing secure wireless vehicle-to-mobile communication is crucial to the successful integration of mobile devices in vehicular environments, usability is of equally critical importance. With MVSec, we propose novel approaches to secure vehicle-to-mobile communication tailored specifically for vehicular environments. We present novel security protocols and provide complete implementation and user study results.
Jun Han 0001, Yue-Hsun Lin, Adrian Perrig, Fan Bai 0002
WISEC1
2012 OTO: online trust oracle for user-centric trust establishment
abstract
Malware continues to thrive on the Internet. Besides automated mechanisms for detecting malware, we provide users with trust evidence information to enable them to make informed trust decisions. To scope the problem, we study the challenge of assisting users with judging the trustworthiness of software downloaded from the Internet.
Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han 0001, Emmanuel Owusu, Jason I. Hong, Adrian Perrig, Debin Gao
CCS3
2012 Cloud Terminal: Secure Access to Sensitive Applications from Untrusted Systems
Lorenzo Martignoni, Pongsin Poosankam, Matei Zaharia, Jun Han 0001, Stephen McCamant, Dawn Song, Vern Paxson, Adrian Perrig, Scott Shenker, Ion Stoica
USENIX ATC4