EDBT 2026 Demo / reviewers in the wild / expert
Changlai Du
dblp:02/6435
· DBLP profile ↗
12ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0001-8888-7440ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 3 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | TriSAS: Toward Dependable Inter-SAS Coordination with AuditabilityabstractTo facilitate dynamic spectrum sharing, the FCC has designated certified SAS administrators to implement their own spectrum access systems (SASs) that manage the shared spectrum usage in the novel CBRS band. As a premise, different SAS servers must conduct periodic inter-SAS coordination to synchronize service states and avoid allocation conflicts. However, SAS servers may inevitably stop service for regular upgrades, crash down, or even perform maliciously that deviate from the normal routines, posing a fundamental operation security problem --- the system shall be robust against these faults to guarantee secure and efficient spectrum sharing service. Unfortunately, the incumbent inter-SAS coordination mechanism, CPAS, is prone to SAS failures and does not support real-time allocation. Recent proposals that rely on blockchain smart contracts or state machine replication mechanisms to realize fault-tolerant inter-SAS coordination require all SASs to follow a unified allocation algorithm. They however face performance bottlenecks and cannot accommodate the current fact that different SASs hold their own proprietary allocation algorithms. Shanghao Shi, Yang Xiao 0010, Changlai Du, Yi Shi 0001, Chonggang Wang, Robert Gazda, Y. Thomas Hou 0001, Eric William Burger, Luiz A. DaSilva, Wenjing Lou |
AsiaCCS | 3 |
| 2024 | SoK: Public Blockchain ShardingabstractBlockchain’s decentralization, transparency, and tamper-resistance properties have facilitated the system’s use in various application fields. However, the low throughput and high confirmation latency hinder the widespread adoption of Blockchain. Many solutions have been proposed to address these issues, including first-layer solutions (or on-chain solutions) and second-layer solutions (or off-chain solutions). Among the proposed solutions, the blockchain sharding system is the most scalable one, where the nodes in the network are divided into several groups. The nodes in different shards work in parallel to validate the transactions and add them to the blocks, and in such a way, the throughput increases significantly. However, previous works have not adequately summarized the latest achievements in blockchain sharding, nor have they fully showcased its state-of-the-art. Our study provides a systemization of knowledge of public blockchain sharding, including the core components of sharding systems, challenges, limitations, and mechanisms of the latest sharding protocols. We also compare their performance and discuss current constraints and future research directions. Md Mohaimin Al Barat, Shaoyu Li, Changlai Du, Y. Thomas Hou 0001, Wenjing Lou |
ICBC | 3 |
| 2024 | AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous Credentials
Hexuan Yu, Changlai Du, Yang Xiao 0010, Angelos D. Keromytis, Chonggang Wang, Robert Gazda, Y. Thomas Hou 0001, Wenjing Lou |
NDSS | 2 |
| 2024 | EchoSensor: Fine-grained Ultrasonic Sensing for Smart Home Intrusion DetectionabstractThis article presents the design and implementation of a novel intrusion detection system, called EchoSensor, which leverages speakers and microphones in smart home devices to capture human gait patterns for individual identification. EchoSensor harnesses the speaker to send inaudible acoustic signals (around 20 kHz) and utilizes the microphone to capture the reflected signals. As the reflected signals have unique variations in the Doppler shift respective to the gaits of different people, EchoSensor is able to profile human gait patterns from the generated spectrograms. To mine the gait information, we first propose a two-stage interference cancellation scheme to remove the background noise and environmental interference, followed by a new method to detect the starting point of walking and estimate the gait cycle time. We then perform the fine-grained analysis of the spectrograms to extract a series of features. In the end, machine learning is employed to construct an identifier for individual recognition. We implement the EchoSensor system and deploy it under different household environments to conduct intrusion detection tasks. Extensive experimental results have demonstrated that EchoSensor can achieve the averaged Intruder Gait Detection Rate (IDR) and True Family Member Gait Detection Rate (TFR) of 92.7% and 91.9%, respectively. Changlai Du, Jiadong Lou, Li Chen 0019, Xu Yuan 0001 |
ACM Trans. Sens. Networks | 2 |
| 2023 | UCBlocker: Unwanted Call Blocking Using Anonymous Authentication
Changlai Du, Hexuan Yu, Yang Xiao 0010, Y. Thomas Hou 0001, Angelos D. Keromytis, Wenjing Lou |
USENIX Security Symposium | 1 |
| 2023 | MS-PTP: Protecting Network Timing from Byzantine AttacksabstractTime-sensitive applications, such as 5G and IoT, are imposing increasingly stringent security and reliability requirements on network time synchronization. Precision time protocol (PTP) is a de facto solution to achieve high precision time synchronization. It is widely adopted by many industries. Existing efforts in securing the PTP focus on the protection of communication channels, but little attention has been given to the threat of malicious insiders. In this paper, we first present the security vulnerabilities of PTP and discuss why the current defense mechanisms are unable to counter Byzantine insiders. We demonstrate how a malicious insider can spoof a time source to arbitrarily shift the system time of a victim node on an IoT testbed. We further demonstrate the harmful consequence of the attack on a real Turtlebot3 robotic platform as the robot fails to locate itself and follows a false trajectory. As a countermeasure, we propose multi-source PTP, in short, MS-PTP, a Byzantine-resilient network time synchronization mechanism that relies on time crowdsourcing. MS-PTP changes the current PTP's single source hierarchy to a multi-source client-server architecture, in which PTP clients take responses from multiple time servers and apply a novel secure aggregation scheme to eliminate the effect of malicious responses from unreliable sources. MS-PTP is able to counter f Byzantine failures when the total number of time sources n used by a client satisfies n>=3f+1. We provide rigorous proof for its non-parametric accuracy guarantee---achieving bounded error regardless of the Byzantine population. We implemented a prototype of MS-PTP on our IoT testbed and the results show its resilience against Byzantine insiders while maintaining high synchronization accuracy. Shanghao Shi, Yang Xiao 0010, Changlai Du, Md Hasan Shahriar, Ao Li 0006, Ning Zhang 0017, Y. Thomas Hou 0001, Wenjing Lou |
WISEC | 3 |
| 2018 | Context-Free Fine-Grained Motion Sensing Using WiFiabstractWiFi-based motion sensing has received a lot of research attention in recent years. Taking advantage of Channel State Information(CSI) collected from physical layer, previous techniques are able to extract useful information from CSI values to infer human movements. However, these works concentrate either on coarse-grained motion sensing or on fine-grained but context-related motion sensing. In this paper, we propose WiTalk, a new fine-grained human motion sensing technique with the distinct context-free character. To profile human motion using CSI, WiTalk generates CSI spectrograms using signal processing techniques and extracts features by calculating the contours of the CSI spectrograms. We verify the proposed technique in the application scenario of lip reading, where the fine-grained motion is the mouth movements. We implement WiTalk on a commercial laptop. Experiment results show that WiTalk can achieve over 92.3% recognition accuracy to discern a set of 12 syllables and 74.3% accuracy to discern a set of short sentences up to six words. Changlai Du, Xiaoqun Yuan, Wenjing Lou, Y. Thomas Hou 0001 |
SECON | 1 |
| 2017 | AugAuth: Shoulder-surfing resistant authentication for augmented realityabstractAs computing system continues to play an increasing role in daily life, user authentication is now an important component. One of the most widely accepted methods for user authentication is through proof of knowledge of a piece of secret information, such as password. However, entering this non-mutable secret for authentication in public space often allows attackers to steal the secret by shoulder surfing or video recording. We observe that it is possible to block attacker's access to user input using augmented reality (AR) display, which is only available to the user. Based on this intuition, we present AugAuth, an authentication scheme in AR using commercial off-the-shelf(COTS) gesture control sensors as an input device. AugAuth can resist against shoulder surfing by presenting user input interface that is only visible to the user and is unique every time. To enable user input with finger movement using the gesture control armband, Myo, we have solved several challenges in electromyogram signal processing, such as annotating the start of signal and finger classification. The experiment results for our input system of a group of volunteers show that our finger classification function has high accuracy and AugAuth is practical for use in real life authentication scenarios. Ruide Zhang, Ning Zhang 0017, Changlai Du, Wenjing Lou, Y. Thomas Hou 0001, Yuichi Kawamoto |
ICC | 3 |
| 2017 | From Electromyogram to Password: Exploring the Privacy Impact of Wearables in Augmented RealityabstractWith the increasing popularity of augmented reality (AR) services, providing seamless human-computer interactions in the AR setting has received notable attention in the industry. Gesture control devices have recently emerged to be the next great gadgets for AR due to their unique ability to enable computer interaction with day-to-day gestures. While these AR devices are bringing revolutions to our interaction with the cyber world, it is also important to consider potential privacy leakages from these always-on wearable devices. Specifically, the coarse access control on current AR systems could lead to possible abuse of sensor data. Although the always-on gesture sensors are frequently quoted as a privacy concern, there has not been any study on information leakage of these devices. In this article, we present our study on side-channel information leakage of the most popular gesture control device, Myo. Using signals recorded from the electromyography (EMG) sensor and accelerometers on Myo, we can recover sensitive information such as passwords typed on a keyboard and PIN sequence entered through a touchscreen. EMG signal records subtle electric currents of muscle contractions. We design novel algorithms based on dynamic cumulative sum and wavelet transform to determine the exact time of finger movements. Furthermore, we adopt the Hudgins feature set in a support vector machine to classify recorded signal segments into individual fingers or numbers. We also apply coordinate transformation techniques to recover fine-grained spatial information with low-fidelity outputs from the sensor in keystroke recovery. We evaluated the information leakage using data collected from a group of volunteers. Our results show that there is severe privacy leakage from these commodity wearable sensors. Our system recovers complex passwords constructed with lowercase letters, uppercase letters, numbers, and symbols with a mean success rate of 91%. Ruide Zhang, Ning Zhang 0017, Changlai Du, Wenjing Lou, Y. Thomas Hou 0001, Yuichi Kawamoto |
ACM Trans. Intell. Syst. Technol. | 3 |
| 2016 | MobTrack: Locating indoor interfering radios with a single deviceabstractIn this paper, we present MobTrack, a single device system which aims to locate interfering radios on unlicensed ISM band in indoor environments. Compared with existing techniques which require a deployment of dense access points (APs), MobTrack only demands a single device equipped with multiple antennas. The location of an interfering signal source are estimated by computing the angle of arrival (AoA) of Line of Sight (LoS) component using an antenna array. Taking advantage of cyclostationary property, MobTrack differentiates interfering signals from working signals. By moving the device around for a short distance within one meter, it depresses multipath effects and determines the LoS component. Simultaneously, the AoAs on the moving trace are recorded to estimate the location of the interfering radio by triangulation. We evaluate the performance of MobTrack by setting up a prototype experimental system. Compared with recent interference localization schemes, MobTrack has much lower hardware complexity and gets better localization accuracy with a median of 0.55 meters. Changlai Du, Ruide Zhang, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 1 |
| 2015 | On cyclostationary analysis of WiFi signals for direction estimationabstractCyclostationary analysis is a powerful tool to study the Signal-Selective Direction Estimation (SSDE) problem as different types of wireless signals have different cyclostationary patterns. Generally speaking, each type of wireless signal has unique cyclic frequencies with the frequency-selective property, which distinguishes itself from other types of signals. The cyclostationary property of a signal may be induced by its modulation method, its carrier frequency, and/or its frame structure. In this paper, we study the cyclostationary property of IEEE 802.11 (WiFi) signals induced by their underlying OFDM frame structure, which includes pilots, cyclic prefix (CP), and preambles. We first analyze the pilot-induced, CP-induced, and preamble-induced cyclostationary properties of WiFi signals, respectively. We then derive their spectral correlation function (SCF) and investigate their applicability to solving the SSDE problem. Simulation results show that the pilot-induced cyclostationary property of WiFi signals is a promising feature that can be used to solve the SSDE problem. Changlai Du, Huacheng Zeng, Wenjing Lou, Y. Thomas Hou 0001 |
ICC | 1 |
| 2008 | VCNF: A Secure Video Conferencing System Based on P2P TechnologyabstractThe goal of a video conferencing system is to deliver multimedia data to the conference participants efficiently and securely. To meet the requirement of a video conferencing system over the internet, many issues have to be addressed, such as security, scalability and heterogeneity. In this paper, we propose a secure and scalable video conferencing system named VCNF (Video Conference Network Foundation), to support large number of conferencing groups simultaneously with each group has limited members. We use a P2PSIP overlay to store and lookup the user and group contact information. SIP protocol is used to setup media sessions and a new kind of session-- VPN session. We adopt a layered data transfer mechanism which traits different kinds of media-streams as of different importance level. We have implemented the system and analyzed its performance and security. An Internet video-based game based on our platform has also been deployed over the Internet. Changlai Du, Chuang Lin 0002, Yada Hu |
HPCC | 1 |