EDBT 2026 Demo / reviewers in the wild / expert
Xiali Hei 0001
dblp:07/8968 · also Xiali Sharon Hei
· DBLP profile ↗
29ranked-venue papers
9as first author
12since 2021 · last 2026
0000-0002-2438-5430ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 8 first-authorSecurity and privacy · 12 · 9 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Purified Distillation Slimming (PDS) for Robust Backdoor DefenseabstractBackdoor attacks pose significant risks to applications based on deep neural networks (DNNs). Current defenses fail to achieve good performance with lightweight (compact) models, limited defense data, and low poisoning rates. To address these challenges, we propose Purified Distillation Slimming (PDS), a novel knowledge distillation approach equipped with iterative pruning. Specifically, we initialize the student model from the backdoored teacher model and iteratively prune the student's neurons until the trigger pattern is deactivated. Such an approach leverages the efficacy of knowledge distillation to transfer purified knowledge from a potentially compromised teacher model to a student model, thereby filtering out backdoor triggers embedded within the training data. Concurrently, we employ network slimming to prune backdoored neurons, enhancing the model's resilience to backdoor attacks by reducing the neurons that adversaries can exploit. Through comprehensive experiments against 17 SOTA backdoor attacks, we demonstrate that our proposed method not only effectively mitigates the impact of backdoor attacks but also preserves, and in some cases even enhances, the model's performance on benign tasks. The effectiveness of PDS has been verified on multiple datasets (Cifar-10, GTSRB, and ImageNet) across several network architectures (ResNet, VGG, MobileNet, EfficientNet, and GoogLeNet). Liqun Shan, Kaiying Han, Yazhou Tu, Insup Lee 0001, Xiali Hei 0001 |
AsiaCCS | 5 |
| 2026 | An Attention-Gated Graph Spiking Neural Membrane System for Structure-Activity Relationship PredictionabstractSpiking Neural P (SNP) systems have attracted increasing attention due to their biologically inspired, event-driven computation and inherent capability for temporal modeling. However, most existing SNP variants rely on fixed or purely local information propagation mechanisms, which limits their ability to capture long-range dependencies and contextual interactions in complex structured data. To address this limitation, we propose an Attention-Gated Spiking Neural membrane system (AGSNP), which incorporates an attention-guided gating mechanism directly into the spiking neuron dynamics. Unlike prior SNP models that treat attention as an external aggregation operation, AGSNP embeds attention signals into the nonlinear spiking update and memory regulation process. This design enables adaptive information propagation across distant structural components while preserving biologically inspired spiking behavior. To evaluate the effectiveness of the proposed architecture, AGSNP is instantiated within a graph-based learning framework and applied to Structure Activity Relationship (SAR) prediction. Experiments on three publicly available benchmark datasets demonstrate that AGSNP consistently outperforms representative baseline methods. Notably, under limited data availability and severe class imbalance, the proposed model achieves improvements of approximately 2.0-5.7% in AUC and related metrics on the Tox21 dataset, and 3.5-17.0% on the MUV dataset. Hong Peng 0001, Kaiying Han, Xiali Hei 0001 |
Int. J. Neural Syst. | 6 |
| 2025 | AdvOSD: Adversarial One-Step Diffusion for Generalizable and Efficient Fake Image DetectionabstractDetecting synthetic images generated by more ad-vanced generative models, such as Generative Adversarial Net-works (GANs) and Diffusion Models (DMs), is still a significant challenge. The images generated by these models are very vi-sually realistic and tend to evade current detection techniques, especially those struggling with generalization and efficiency. The present study suggests AdvOSD (Adversarial One-Step Diffusion), a generalizable and efficient approach to detecting fake images. AdvOSD operates by examining the comparative robustness of real and synthetic images to an adversarial-driven, specially crafted one-step diffusion transformation. The method begins by generating an oracle prompt for an input image through a BLIP model. The prompt is further manipu-lated through targeted noun substitution with NLP techniques to craft an effective adversarial prompt for interfering with the image's reconstruction process. AdvOSD's strength lies in its one-step transformation module: the input image's latent representation and adversarial prompt embedding are fed into a LoRA-adapted UNet, which, along with a diffusion model scheduler, performs one efficient transformation step to produce a reconstructed image. Authenticity is then assessed by calculating the similarity between original and transformed images. Experimental results on several benchmark datasets demonstrate that AdvOSD achieves competitive detection ac-curacy, particularly for editted images. For efficiency, the inversion-based baseline ZeroFake reports 30.2 s/image on a DGX A100, whereas AdvOSD runs ~ 1.5 s/image on a con-sumer RTX 3060- 20 x faster despite far weaker hardware (A100: 640 GB HBM2e; 3060: 12 GB GDDR6), making it a practical solution for real-world applications. Liqun Shan, Kaiying Han, Yazhou Tu, Xiali Hei 0001 |
ACSAC | 4 |
| 2025 | LiveGuard: Voice Liveness Detection via Wavelet Scattering Transform and Mel Spectrogram ScalingabstractVoice-controlled interfaces are essential in modern smart devices, but they remain vulnerable to replay attacks that compromise voice authentication systems. Existing voice liveness detection methods often struggle to distinguish human speech from replayed audio. This paper introduces a novel approach, LiveGuard, utilizing wavelet scattering transform (WST) and Mel spectrogram scaling with a lightweight ResNet architecture to enhance voice liveness detection. WST captures robust hierarchical features, while Mel spectrogram scaling extracts fine-grained acoustic details, which the lightweight ResNet efficiently processes to identify live voice. Experimental results demonstrate accuracy improvements of 6% with WST and Mel spectrogram scaling, achieving a top accuracy of 97.17% on POCO dataset. Meanwhile, LiveGuard demonstrates superior performance on ASVspoof2019 and ASVspoof2021 benchmarks. It achieves the lowest equal error rate (EER) of 0.13%, and a min t-DCF of 0.00126 on ASVspoof2019, and an EER of 0.42% on ASVspoof2021, surpassing state-of-the-art methods. Liqun Shan, Xingli Zhang 0004, Md. Imran Hossen, Xiali Hei 0001 |
DSN | 4 |
| 2024 | IdentityKD: Identity-wise Cross-modal Knowledge Distillation for Person Recognition via mmWave Radar SensorsabstractRecent advancements in person recognition have raised concerns about identity privacy leaks.Gait recognition through millimeterwave radar provides a privacy-centric method.However, it is challenged by lower accuracy due to the sparse data these sensors capture.We are the first to investigate a cross-modal method, Iden-tityKD, to enhance gait-based person recognition with the assistance of facial data.IdentityKD involves a training process using both gait and facial data, while the inference stage is conducted exclusively with gait data.To effectively transfer facial knowledge to the gait model, we create a composite feature representation using contrastive learning.This method integrates facial and gait features into a unified embedding that captures the unique identityspecific information from both modalities.We employ two distinct contrastive learning losses.One minimizes the distance between embeddings of data pairs from the same person, enhancing intraclass compactness, while the other maximizes the distance between embeddings of data pairs from different individuals, improving inter-class separability.Additionally, we use an identity-wise distillation strategy, which tailors the training process for each individual, ensuring that the model learns to distinguish between different identities more effectively.Our experiments on a dataset of 36 subjects, each providing over 5000 face-gait pairs, demonstrate that IdentityKD improves identity recognition accuracy by 6.5% compared to baseline methods. Liqun Shan, Rujun Zhang, Sai Venkatesh Chilukoti, Xingli Zhang 0004, Insup Lee 0001, Xiali Hei 0001 |
MMAsia | 6 |
| 2024 | Can't Say Cant? Measuring and Reasoning of Dark Jargons in Large Language Models
Ziyin Zhou, Zhangchi Zhao, Qianqian Qiao, Kaiying Han, Md. Imran Hossen, Xiali Hei 0001 |
SecureComm (4) | 8 |
| 2024 | From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverabstractThis paper studies vulnerabilities at the intersection of wearable devices and automated control systems. Particularly, we focus on exploiting smart glasses as an entry point and unveil the threats of taking over security-critical automated control chains without user verification or interaction. These vulnerabilities can be especially pertinent in scenarios where security mechanisms only depend on entry point security with minimal user verification (relying on complete trust over previous nodes in automated control chains). We have validated the effects of our attacks on real-world systems (e.g., Tesla vehicles) that are controlled by software and automation tools such as Apple Shortcuts or IFTTT. We show how our contactless, speaker-independent, and electromagnetic interference based attacks can control functionalities such as unlocking doors and initiating remote start of Tesla vehicles, even though the victim’s phone is in a lock-screen status. Our findings not only demonstrate the potential for unauthorized control over automated, connected systems but also highlight the urgent need for more robust security measures in the integration of wearable technology with broader automation frameworks. Xingli Zhang 0004, Yazhou Tu, Yan Long 0002, Liqun Shan, Mohamed A Elsaadani, Kevin Fu, Zhiqiang Lin 0001, Xiali Hei 0001 |
SP | 8 |
| 2024 | Paa-Tee: A Practical Adversarial Attack on Thermal Infrared Detectors with Temperature and Pose AdaptabilityabstractThermal infrared object detectors play an important role in security-related tasks, necessitating feasible adversarial attacks to evaluate their robustness. In many cases, implementing attacks in the physical space by a patch demands intricate and specialized perturbations. However, state-of-the-art adversarial attacks are often impractical, as they require fixed perturbation location and are susceptible to environmental temperature, leading to attack effects overfitting to specific poses and environments. To address this, we propose a practical adversarial attack method named Paa-Tee, with two input transformation strategies. For poses, we continuously alter the patch’s position to mitigate the impact of different poses on the patch’s location. For temperature, leveraging the principles of thermal imaging, we apply various transformations to a single input image to simulate different attack environments. Meanwhile, we utilize hot and cold pastes as low-resolution patches to implement attacks in the physical world. Extensive experiments validate the efficacy of our approach in both the digital and physical worlds. In the digital world, our attacks reduce the average precision of mainstream detectors by 65.44%. In the physical world, we achieve an average attack success rate of 63.77% under various distances, poses, angles, and environmental conditions. Zhangchi Zhao, Liqun Shan, Ziyin Zhou, Kaiying Han, Xiali Hei 0001 |
TrustCom | 6 |
| 2023 | A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs PermissionsabstractAs a new format of mobile application, mini-programs, which function within a larger app and are built with HTML, CSS, and JavaScript web technology, have become the way to do almost everything in China. Many researchers have done the ecosystem or developing study, while the permission problem has not been investigated yet. In this paper, we present our studies on the permission management of mini-programs and conduct a systematic study on 9 popular mobile host app ecosystems that host over 7 million mini-programs. After testing over 2,580 APIs, we extracted a common abstract model for mini-programs’ permission control and revealed six categories of potential security vulnerabilities due to improper permission management. It is alarming that the current popular mobile app ecosystems (i.e., host apps) under study have at least one security vulnerability due to the mini-programs’ improper permission management. We present the corresponding attack methods to dissect these potential weaknesses further to exploit the discovered vulnerabilities. To prove that the revealed vulnerabilities may cause severe consequences in real-world use, we show three kinds of attacks without privileges or cracking the host apps. We have responsibly disclosed the newly discovered vulnerabilities, and two CVEs were issued. Finally, we put forward systematic suggestions to strengthen the standardization of mini-programs. Leixin Yang, Zixiao Xiang, Xiali Hei 0001 |
COMPSAC | 5 |
| 2023 | Auditory Eyesight: Demystifying μs-Precision Keystroke Tracking Attacks on Unconstrained Keyboard Inputs
Yazhou Tu, Liqun Shan, Md. Imran Hossen, Sara Rampazzi, Kevin R. B. Butler, Xiali Hei 0001 |
USENIX Security Symposium | 6 |
| 2022 | aaeCAPTCHA: The Design and Implementation of Audio Adversarial CAPTCHAabstractCAPTCHAs are designed to prevent malicious bot programs from abusing websites. Most online service providers deploy audio CAPTCHAs as an alternative to text and image CAPTCHAs for visually impaired users. However, prior research investigating the security of audio CAPTCHAs found them highly vulnerable to automated attacks using Automatic Speech Recognition (ASR) systems. To improve the robustness of audio CAPTCHAs against automated abuses, we present the design and implementation of an audio adversarial CAPTCHA (aaeCAPTCHA) system in this paper. The aaeCAPTCHA system exploits audio adversarial examples as CAPTCHAs to prevent the ASR systems from automatically solving them. Furthermore, we conducted a rigorous security evaluation of our new audio CAPTCHA design against five state-of-the-art DNN-based ASR systems and three commercial Speech-to-Text (STT) services. Our experimental evaluations demonstrate that aaeCAPTCHA is highly secure against these speech recognition technologies, even when the attacker has complete knowledge of the current attacks against audio adversarial examples. We also conducted a usability evaluation of the proof-of-concept implementation of the aaeCAPTCHA scheme. Our results show that it achieves high robustness at a moderate usability cost compared to normal audio CAPTCHAs. Finally, our extensive analysis highlights that aaeCAPTCHA can significantly enhance the security and robustness of traditional audio CAPTCHA systems while maintaining similar usability. Md. Imran Hossen, Xiali Hei 0001 |
EuroS&P | 2 |
| 2021 | Transduction Shield: A Low-Complexity Method to Detect and Correct the Effects of EMI Injection Attacks on SensorsabstractThe reliability of control systems often relies on the trustworthiness of sensors. As process automation and robotics keep evolving, sensing methods such as pressure sensing are extensively used in both conventional systems and rapidly emerging applications. The goal of this paper is to investigate the threats and design a low-complexity defense method against EMI injection attacks on sensors. Yazhou Tu, Vijay Srinivas Tida, Zhongqi Pan, Xiali Hei 0001 |
AsiaCCS | 4 |
| 2020 | An Object Detection based Solver for Google's Image reCAPTCHA v2
Md. Imran Hossen, Yazhou Tu, Md Fazle Rabby, Md. Nazmul Islam, Hui Cao 0003, Xiali Hei 0001 |
RAID | 6 |
| 2019 | Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksabstractTemperature sensing and control systems are widely used in the closed-loop control of critical processes such as maintaining the thermal stability of patients, or in alarm systems for detecting temperature-related hazards. However, the security of these systems has yet to be completely explored, leaving potential attack surfaces that can be exploited to take control over critical systems. Yazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez, Kevin Fu, Xiali Hei 0001 |
CCS | 6 |
| 2018 | Enabling Fair Spectrum Sharing between Wi-Fi and LTE-UnlicensedabstractDue to the fast increase of mobile traffic, most mobile network operators face the congestion issue in licensed spectrum bands. Several telecommunication vendors and operators propose to expand LTE service to the unlicensed spectrum bands to relieve the traffic congestion. However, LTE in unlicensed spectrum may interfere with Wi-Fi communications in the same bands and cause significant decrease in the quality of service of Wi-Fi. In this paper, we propose a novel mechanism that enables negotiations between two different wireless technologies (Wi-Fi and LTE), which ensures fair spectrum sharing between Wi-Fi and LTE-Unlicensed (LTE-U) in the same bands. We formulate the co-existence of Wi-Fi and LTE-U as a constrained optimization problem, and we solve the problem. We evaluate the performance of the proposed scheme via NS-3 simulations. The simulation results show that our approach can effectively improve the overall channel utilization and reduce the interference between Wi-Fi and LTE-U. Longfei Wu, Xiaojiang Du, Guisheng Yin, Jie Wu 0001, Bo Ji 0001, Xiali Hei 0001 |
ICC | 7 |
| 2018 | A Visible Light Channel Based Access Control Scheme for Wireless Insulin Pump SystemsabstractSmart personal insulin pumps have been widely adopted by type 1 diabetes. However, many wireless insulin pump systems lack security mechanisms to protect them from malicious attacks. In previous works, the read-write attacks over RF channels can be launched stealthily and could jeopardize patients' lives. Protecting patients from such attacks is urgent. To address this issue, we propose a novel visible light channel based access control scheme for wireless infusion insulin pumps. This scheme employs an infrared photodiode sensor as a receiver in an insulin pump, and an infrared LED as an emitter in a doctor's reader (USB) to transmit a PIN/shared key to authenticate the doctor's USB. The evaluation results demonstrate that our scheme can reliably pass the authentication process with a low false accept rate (0.05% at a distance of 5cm). Kam Kong, Xiali Hei 0001, Yazhou Tu, Xiaojiang Du |
ICC | 3 |
| 2018 | Voiceprint-Based Access Control for Wireless Insulin Pump SystemsabstractInsulin pumps have been widely used by patients with diabetes. Insulin pump systems adopt wireless channel with few cryptographic mechanisms, which makes them vulnerable to many attacks. In this paper, we focus on the wireless channel between Carelink USB and insulin pump on which the attackers can launch message eavesdropping and/or therapy manipulation attacks, which may put the patient in a life-threatening situation. Some prior solutions such as certificate-based or token-based schemes need either complicated key management or additional devices. We propose a novel voiceprint-based access control scheme comprising anti-replay speaker verification and voiceprint-based key agreement to secure the channel between the Carelink USB and insulin pump. Our scheme does not need permanent key sharing or additional devices. The anti-replay speaker verification adopts cascaded fusion of speaker verification and anti-replay countermeasure to ensure the insulin pump can be accessed by Carelink USB only after the legitimate user passes the identity verification. The evaluation on ASVspoof 2017 datasets shows that our scheme achieves a 4.02% Equal Error Rate (EER) with the existence of replay impostors. Besides, our scheme uses energy-difference-based voiceprint extraction and secure multi-party computing to generate a common cryptography (temporary) key between the Carelink USB and insulin pump, which can be used to encrypt the subsequent communication, and protect the insulin pump from eavesdropping and therapy manipulation attacks. By appropriately setting the similarity threshold of voiceprints, our key agreement scheme allows the insulin pump to establish a secure channel only with the device in its close proximity. Bin Hao, Xiali Hei 0001, Yazhou Tu, Xiaojiang Du, Jie Wu 0001 |
MASS | 2 |
| 2018 | Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial Sensors
Yazhou Tu, Zhiqiang Lin 0001, Insup Lee 0001, Xiali Hei 0001 |
USENIX Security Symposium | 4 |
| 2018 | Sequential Outlier Criterion for Sparsification of Online Adaptive FilteringabstractIn this paper, we deal with the learning problem when using an adaptive filtering method. For the learning system in filtering, the knowledge is obtained and updated based on the newly acquired information that is extracted and learned from the sequential samples over time. Effective measurement on the informativeness of a sample and reasonable subsequent treatment on the sample will improve the learning performance. This paper proposes a sequential outlier criterion for sparsification of online adaptive filtering. The method is proposed to achieve effective informativeness measurement of online filtering to obtain a more accurate and more compact network in the learning process. In the proposed method, the measurement on the samples' informativeness is established based on the historical sequentially adjacent samples, and then the informative-measured samples are treated individually by the learning system based on whether the sample is informative, redundant, or abnormal. With our method, a more sensible learning process can be achieved with valid knowledge extracted, and the optimal network in the learning system can be obtained. Simulations based on static function estimation, Mackey-Glass time series prediction, and Lorenz chaotic time series prediction demonstrate that the proposed method can provide more effective classification on samples and more accurate networks in online adaptive filtering. Shiliang Zhang, Hui Cao 0003, Xiali Hei 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2017 | SHIPHER: A new family of light-weight block ciphers based on dynamic operatorsabstractIn this paper, we describe a family of block ciphers named SHIPHER. We present a symmetric encryption framework based on a cryptographic hash function and dynamic operators controlled by small random numbers. This dynamic operator mixes operations from different algebraic groups like IDEA [1]. However, unlike IDEA and extended IDEA ([2], [3]), modular addition is the only calculation in this framework and this makes SHIPHER highly efficient. The round function was chosen to provide confusion and diffusion to facilitate hardware implementations. This framework can provide families of secure, flexible, and variable-key-length block ciphers. Anny block size can be achieved. We have extensively investigated our encryption framework. We can easily control the computational cost by selecting block size, implementation method, and a hash function. Also, this framework offers excellent performance and it is flexible and generic enough to admit a variety of implementations on different dynamic operators. In this paper, we provide one implementation, show its performance, and discuss possible extensions of similar dynamic operators. Xiali Hei 0001, Binheng Song, Caijin Ling |
ICC | 1 |
| 2016 | You Cannot Sense My PINs: A Side-Channel Attack Deterrent Solution Based on Haptic Feedback on Touch-Enabled DevicesabstractIn this paper, we introduce a novel and secure solution to mitigate side-channel attacks to capture the PINs like touchID and other credentials of touch-enabled devices. Our approach can protect haptic feedback enabled devices from potential direct observation techniques such as cameras and motion sense techniques including such as accelerometers in smart-watch. Both attacks use the concept of shoulder surfing in social engineering and were published recently (CCS'14 and CCS'15). Hand-held devices universally employ small vibration motors as an inexpensive way to provide haptic feedback. The strength of the haptic feedback depends on the brand and the device manufacturer. They are usually strong enough to produce sliding movement and make audible noises if the device is resting on the top of a desk when the vibration motor turns. However, when the device is held in the hand the vibration can only be sensed by the holder; it is usually impossible or uncertain for an observer to know when the vibration motor turns. Our proposed solution uses the haptic feedback to inform the internal state of the keypad to the user and takes advantage of the fact that the effect of haptic feedback can be easily cloaked in such a way that direct observation techniques and indirect sensing techniques will fail. We develop an application on Android cell phones to demonstrate it and invite users to test the code. Moreover, we use real smart-watch to sense the vibration of Android cell phones. Our experimental results show that our approach can mitigate the probability of sensing a 4-digit or 6-digit PINs using smart-watch to below practical value. Our approach also can mitigate the probability of recognizing a 4-digit or 6-digit PINs using a camera within 1 meter to below practical value because the user does not need to move his or her hand during the internal states to input different PINs. Caijin Ling, Xiali Hei 0001, Kam Kong, Michael Peays, Mohsen Guizani |
GLOBECOM | 2 |
| 2015 | Patient Infusion Pattern based Access Control Schemes for Wireless Insulin Pump SystemabstractWireless insulin pumps have been widely deployed in hospitals and home healthcare systems. Most of them have limited security mechanisms embedded to protect them from malicious attacks. In this paper, two attacks against insulin pump systems via wireless links are investigated: a single acute overdose with a significant amount of medication and a chronic overdose with a small amount of extra medication over a long time period. They can be launched unobtrusively and may jeopardize patients' lives. It is very urgent to protect patients from these attacks. We propose a novel personalized patient infusion pattern based access control scheme (PIPAC) for wireless insulin pumps. This scheme employs supervised learning approaches to learn normal patient infusion patterns in terms of the dosage amount, rate, and time of infusion, which are automatically recorded in insulin pump logs. The generated regression models are used to dynamically configure a safe infusion range for abnormal infusion identification. This model includes two sub models for bolus (one type of insulin) abnormal dosage detection and basal abnormal rate detection. The proposed algorithms are evaluated with real insulin pump. The evaluation results demonstrate that our scheme is able to detect the two attacks with a very high success rate. Xiali Hei 0001, Xiaojiang Du, Shan Lin 0001, Insup Lee 0001, Oleg Sokolsky |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2014 | Poster: near field communication based access control for wireless medical devicesabstractSecurity of wireless medical devices is critical for patient safety because security attacks may directly hurt patients' health. In this paper, we design a novel access control scheme based on bi-channel and multi-factor authentication for wireless medical devices. Our scheme utilizes near field communication (NFC) to perform device pairing, which supports key exchange between a device and a reader in short communication range (<= 6cm) with bounded response time. To further defend against attacks when a malicious reader is placed within the device's communication range in crowded situations, we design a crowd detection algorithm using WiFi and user's smart phone to assist the key exchange. Our analyses and experiments show that our security schemes are effective and efficient. Xiali Hei 0001, Xiaojiang Du, Shan Lin 0001 |
MobiHoc | 1 |
| 2013 | Two vulnerabilities in Android OS kernelabstractAndroid Honeycomb operating system is widely used for tablet devices, such as Samsung Galaxy Tab. The Android system programs are usually efficient and secure in memory management. However, there has been a few security issues reported that show Android's insufficient protection to the kernel. In this work, we reveal a new security pitfall in memory management that can cause severe errors and even system failures. Existing security software for android do not detect this pitfall, due to the private implementation of Android kernel. We then discuss two vulnerabilities introduced by this pitfall: 1) malicious programs can escalate the root-level privilege of a process, through which it can disable the security software, implant malicious codes and install rootkits in the kernel; 2) deny of service attacks can be launched. Experiments have been conducted to verify these two vulnerabilities on Samsung Galaxy Tab 10.1 with Tegra 2 CPU. To protect systems from these vulnerabilities, we proposed a patching solution, which has been adopted by Google. Xiali Hei 0001, Xiaojiang Du, Shan Lin 0001 |
ICC | 1 |
| 2013 | PIPAC: Patient infusion pattern based access control scheme for wireless insulin pump systemabstractWireless insulin pumps have been widely deployed in hospitals and home healthcare systems. Most of these insulin pump systems have limited security mechanisms embedded to protect them from malicious attacks. In this paper, two attacks against insulin pump systems via wireless links are investigated: a single acute overdose with a significant amount of medication, and chronic overdose with an insignificant amount of extra medication over a long time period, e.g., several months. These attacks can be launched unobtrusively and may jeopardize patients' lives. It is very important and urgent to protect patients from these attacks. To address this issue, we propose a novel patient infusion pattern based access control scheme (PIPAC) for wireless insulin pumps. This scheme employs a supervised learning approach to learn normal patient infusions pattern with the dosage amount, rate, and time of infusion, which are automatically recorded in insulin pump logs. The generated regression models are used to dynamically configure a safety infusion range for abnormal infusion identification. The proposed algorithm is evaluated with real insulin pump logs used by several patients for up to 6 months. The evaluation results demonstrate that our scheme can reliably detect the single overdose attack with a success rate up to 98% and defend against the chronic overdose attack with a very high success rate. Xiali Hei 0001, Xiaojiang Du, Shan Lin 0001, Insup Lee 0001 |
INFOCOM | 1 |
| 2012 | Two matrices for Blakley's secret sharing schemeabstractThe secret sharing scheme was invented by Adi Shamir and George Blakley independently in 1979. In a (k, n)-threshold linear secret sharing scheme, any k-out-of-n participants could recover the shared secret, and any less than k participants could not recover the secret. Shamir's secret sharing scheme is more popular than Blakley's even though the former is more complex than the latter. The reason is that Blakley's scheme lacks determined, general and suitable matrices. In this paper, we present two matrices that can be used for Blakley's secret sharing system. Compared with the Vandermonde matrix used by Shamir's scheme, the elements in these matrices increase slowly. Furthermore, we formulate the optimal matrix problem and find the lower bound of the minimal maximized element for k=2 and upper bound of the minimal maximized element of matrix for given k. Xiali Hei 0001, Xiaojiang Du, Binheng Song |
ICC | 1 |
| 2012 | A distributed login framework for semi-structured Peer-to-Peer networksabstractIn Peer-to-Peer (P2P) networks, security is a challenging issue due to decentralization. In this paper, we propose an effective distributed login framework for P2P networks. User profile availability is a critical issue in P2P networks. Within the distributed login framework, we propose a new Reed-Solomon erasure code scheme leveraging the Pascal matrix that can guarantee user profile availability. Our performance and security analyses show that: (1) the distributed login framework provides high availability and low redundancy rate; and (2) the new erasure code has low computation and memory overheads. Xiali Hei 0001, Xiaojiang Du, Binheng Song |
ICC | 1 |
| 2011 | Biometric-based two-level secure access control for Implantable Medical Devices during emergenciesabstractImplantable Medical Devices (IMDs) are widely used to treat chronic diseases. Nowadays, many IMDs can wirelessly communicate with an outside programmer (reader). However, the wireless access also introduces security concerns. An attacker may get an IMD reader and gain access to a patient's IMD. IMD security is an important issue since attacks on IMDs may directly harm the patient. A number of research groups have studied IMD security issues when the patient is in nonemergency situations. However, these security schemes usually require the patient's participation, and they may not work during emergencies (e.g., when the patient is in comma) for various reasons. In this paper, we propose a light-weight secure access control scheme for IMDs during emergencies. Our scheme utilizes patient's biometric information to prevent unauthorized access to IMDs. The scheme consists of two levels: level 1 employs some basic biometric information of the patient and it is lightweight; level 2 utilizes patients' iris data for authentication and it is very effective. In this research, we also make contributions in human iris verification: we discover that it is possible to perform iris verification by comparing partial iris data rather than the entire iris data. This significantly reduces the overhead of iris verification, which is critical for resource-limited IMDs. We evaluate the performance of our schemes by using real iris data sets. Our experimental results show that the secure access control scheme is very effective and has small overhead (hence feasible for IMDs). Specifically, the false acceptance rate (FAR) and false rejection rate (FRR) of our secure access control scheme are close to 0.000% with suitable threshold, and the memory and computation overheads are acceptable. Our analysis shows that the secure access control scheme reduces computation overhead by an average of 58%. Xiali Hei 0001, Xiaojiang Du |
INFOCOM | 1 |
| 2010 | Defending Resource Depletion Attacks on Implantable Medical DevicesabstractImplantable Medical Devices (IMDs) have been widely used to treat chronic diseases such as cardiac arrhythmia and diabetes. Many IMDs are enabled with wireless communication capabilities and can communicate with an outside programmer/reader wirelessly. With the rapid growth of IMDs, IMD security becomes a critical issue since attacks on IMDs may directly harm the patient. Typical IMDs have very limited resource in terms of energy, computation and storage. In this research, we identify a new kind of attacks on IMDs - Resource Depletion (RD) attacks that could deplete IMD resources (e.g., battery power) quickly. The RD attacks could reduce the lifetime of an IMD from several years to a few weeks. The attacks can be easily launched but can not be defended by traditional cryptographic approaches. In this paper, we propose to utilize the patient's IMD access pattern and we design a novel Support Vector Machine (SVM) based scheme to address the RD attacks. Our SVM-based scheme is very effective in defending the RD attacks. Our experimental results show that the average detection rate of the SVM-based scheme is above 90%. Xiali Hei 0001, Xiaojiang Du, Jie Wu 0001 |
GLOBECOM | 1 |