EDBT 2026 Demo / reviewers in the wild / expert
Ziwei Liu 0007
dblp:05/6300-7
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0003-2311-4193ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MagShadow: Physical Adversarial Example Attacks via Electromagnetic InjectionabstractPhysical adversarial examples (AEs) have become an increasing threat to deploying deep neural network (DNN) models in the real world. Popular approaches adopt sticking-based or projecting-based strategies that stick the printed adversarial patches to objects or directly project the AE onto objects. Although effective, these methods require access to target objects and generate visible artifacts, which reduces the attack's stealthiness. In this article, we propose MagShadow, a new attack vector that leverages imperceptible electromagnetic (EM) signals to realize physical AEs. MagShadow utilizes the CCD camera sensor's susceptibility to EM injection attacks and induces fine-grained adversarial perturbations on the camera's captured image by injecting carefully-crafted signals with a low-cost portable device. As MagShadow directly manipulates the image sensor's output with EM signals, the attack requires no access to the target object and can keep stealthy. We study the feasibility of MagShadow in two typical DNN application scenarios (image classification and object detection) and design a framework to implement four different types of attacks, i.e., untargeted, targeted, hiding, and appearing attacks. Extensive real-world experiments on five different cameras are conducted, which demonstrate MagShadow's effectiveness against different popular DNN models (Inception v3, ResNet101, YOLO v3/v4). Ziwei Liu 0007, Feng Lin 0004, Zhongjie Ba, Li Lu 0008, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | EMTrig: Physical Adversarial Examples Triggered by Electromagnetic Injection towards LiDAR PerceptionabstractLiDAR sensors measure the environment by emitting lasers and, when combined with deep neural networks (DNNs), can effectively identify surrounding obstacles such as vehicles and pedestrians. Given its crucial role in autonomous driving perception, the security of LiDAR is closely tied to driving safety. Some studies have explored its vulnerabilities to physical-world attacks, such as laser-based attacks or adversarial objects. However, these methods are either extremely difficult to execute or lack stealth and flexibility. In this paper, we propose a novel attack method called EMTrig, which leverages common roadside objects combined with controlled intentional electromagnetic interference (IEMI) targeting specific LiDARs to create flexible and covert adversarial attacks against designated vehicles. This causes the victim vehicle to misidentify roadside objects as obstacles, such as other vehicles, leading to dangerous driving behaviors like sudden stops and lane changes. Unlike conventional adversarial examples, our deployed objects are common items (e.g., signboards) that are harmless without the IEMI trigger but pose a threat only under IEMI attacks, providing better stealthiness and flexibility. Extensive experiments in both digital and physical domains validate the effectiveness of EMTrig, demonstrating its significant threat to LiDAR perception. Ziwei Liu 0007, Feng Lin 0004, Teshi Meng, Benaouda Chouaib Baha-eddine, Li Lu 0008, Kui Ren 0001 |
SenSys | 1 |
| 2024 | High-Quality Speech Recovery Through Soundproof Protections via mmWave SensingabstractOnline voice communications are widely used nowadays. To protect speech from leakage, people tend to initiate the talk in sound-isolated environments. In this paper, we reveal a novel attack that recovers high-quality speech from outside soundproof zones. The rationale of the attack is to leverage sound-sensitive characteristics of piezoelectric materials, i.e., a piezo film that can change the phase of reflected mmWaves when placed in a sound field. If the attacker transmits mmWaves and analyzes reflected signals from the piezo film, the speech information can be compromised. More importantly, the piezo film is paper-like and works without a power supply. We propose a new speech recovery methodology to transform sound waves into wireless signals and build an end-to-end eavesdropping system working as a through-wall “microphone” to recover high-quality speech stealthily. To combat signal attenuation and improve speech quality, we develop a speech-enhancement scheme based on generative adversarial networks and propose to use multi-antenna information for intelligible speech reconstruction. We conduct extensive experiments to evaluate the system. The results indicate that the system achieves over 98% accuracy for digit recognition and works well over 5m away through the wall. We also test the system under complex scenarios and give countermeasures. Feng Lin 0004, Chao Wang 0097, Tiantian Liu 0002, Ziwei Liu 0007, Yijie Shen, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | PhaDe: Practical Phantom Spoofing Attack Detection for Autonomous VehiclesabstractDespite their prevalence and indispensability in the perception modules of autonomous vehicles, cameras have shown susceptibility to numerous attacks. Among them, the phantom spoofing attack is of significant concern. In such attacks, malefactors employ electronic display devices like projectors and display monitors to generate deceptive objects, thereby duping the object detectors in autonomous vehicles. However, existing detection methodologies are narrowly focused on a single device category, ignoring the multitude of devices that could be leveraged for attacks. Furthermore, the artificial modality-based solution presently in use lacks efficacious fusion mechanisms. In response to these limitations, we propose PhaDe, a practical deep learning-based system adept at detecting phantom spoofing attacks from a variety of and even unfamiliar attack devices. Our approach introduces two image processing techniques to construct artificial modalities and further advances a multi-head self-attention MSA-based fusion module for more versatile integration of disparate modalities. To boost the generalization capacity of our system against novel, unseen attacks, we incorporate two representation-level losses to align feature distributions from various domains. Evaluations conducted on our own dataset, encompassing fake objects from several device types, attest to the efficacy of our system. Our results indicate an accuracy of 98.80% on familiar domains and a detection success rate of 94.03% on unfamiliar domains. Additionally, PhaDe demonstrates a swift response time, fulfilling the practicality requisites. Feng Lin 0004, Jin Li 0033, Ziwei Liu 0007, Li Lu 0008, Zhongjie Ba, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | mmPhone: Acoustic Eavesdropping on Loudspeakers via mmWave-characterized Piezoelectric EffectabstractMore and more people turn to online voice communication with loudspeaker-equipped devices due to its convenience. To prevent speech leakage, soundproof rooms are often adopted. This paper presents mmPhone, a novel acoustic eavesdropping system that recovers loudspeaker speech protected by soundproof environments. The key idea is that properties of piezoelectric films in mmWave band can change with sound pressure due to the piezoelectric effect. If the property changes are acquired by an adversary (i.e., characterizing the piezoelectric effect with mmWaves), speech leakage can happen. More importantly, the piezoelectric film can work without a power supply. Base on this, we proposed a methodology using mmWaves to sense the film and decoding the speech from mmWaves, which turns the film into a passive "microphone". To recover intelligible speech, we further develop an enhancement scheme based on a denoising neural network, multi-channel augmentation, and speech synthesis, to compensate for the propagation and penetration loss of mmWaves. We perform extensive experiments to evaluate mmPhone and conduct digit recognition with over 93% accuracy. The results indicate mmPhone can recover high-quality and intelligible speech from a distance over 5m and is resilient to incident angles of sound waves (within 55 degrees) and different types of loudspeakers. Chao Wang 0097, Feng Lin 0004, Tiantian Liu 0002, Ziwei Liu 0007, Yijie Shen, Zhongjie Ba, Li Lu 0008, Wenyao Xu, Kui Ren 0001 |
INFOCOM | 4 |