EDBT 2026 Demo / reviewers in the wild / expert
Yuanqing Zheng
dblp:08/9937
· DBLP profile ↗
117ranked-venue papers
12as first author
73since 2021 · last 2026
0000-0003-3096-687XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 99 · 11 first-author · 59 since 2021Security and privacy · 9 · 9 since 2021Systems, architecture and hardware · 7 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RFpH: A Robust Water pH Assessment System Based on RFID Technology
Shiwei He, Yanwen Wang 0001, Junhua Situ, Zheng Wang 0054, Di Wu 0002, Yuanqing Zheng |
SECON | 6 |
| 2026 | Jailbreaking Embodied LLMs via Action-Level Manipulation
Qiang Yang 0018, Leming Shen, Zijing Ma, Yuanqing Zheng |
SenSys | 5 |
| 2026 | RANPilot: Making AI Functionalities Robust to Dynamic O-RAN ReconfigurationsabstractThe Open Radio Access Network (O-RAN) promises unprecedented flexibility through its reconfigurable architecture and AI-driven control. However, this agility exposes a critical fragility: AI models trained on one network configuration suffer significant performance degradation after an upgrade due to dramatic data drift. The standard solution, reactive retraining, is unacceptably slow, leaving the network in a suboptimal state for tens of minutes and undermining the core benefits of O-RAN's dynamism. This paper introduces RANPilot, the first framework to address this challenge through proactive AI adaptation. RANPilot constructs a lightweight "virtual O-RAN" (a trace-driven emulator) to synthesize high-fidelity training data representing the post-reconfiguration state before the physical change occurs, allowing AI models to be adapted in advance. Extensive experiments on a real-world 5G testbed demonstrate that RANPilot achieves near interruption-free AI services upon reconfiguration, reducing AI downtime by 85% to 94% against reactive baselines. By shifting the AI evolution paradigm from reactive redevelopment to proactive preparation, RANPilot explores a digital-leadoff approach to enable robust AI in reconfigurable O-RAN deployments. Shiming Yu, Leming Shen, Xianjin Xia, Yuanqing Zheng, Yaxiong Xie |
SIGCOMM | 6 |
| 2026 | Planet-Scale IoT Connectivity via LEO Satellites
Xianjin Xia, Jinhong Liu, Yuanqing Zheng, Linghe Kong, Mo Li 0001 |
SIGCOMM | 5 |
| 2026 | Anti-Spoofing and Mask-Supported Face Authentication Using mmWave Without On-Site RegistrationabstractFace authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and susceptible to masks and vulnerable to spoofing attacks. This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans faces by moving a commodity mmWave radar along a specific trajectory. The signals bounced off the face carry facial biometric and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well when users wear masks. To en- hance security, we develop a liveness detection method and an amplitude modulation-based method to defend against spoofing attacks and replay attacks. We enhance the basic version of mmFace [1] by improving its performance under mask occlusion and replay attack resilience. Besides, we explore a distance-resistant structure feature to suppress the impact of unstable face- to-device distance. To avoid on-site registration, we propose a novel virtual registration approach based on the cross-modal transformation from photos to mmWave. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments demonstrate mmFace's accuracy in FA and effectiveness in attack detection. Wenfan Song, Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Xinhuai Wang, Jinsong Han |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Toward Privacy-Preserving and Personalized Smart Homes via Tailored Small Language ModelsabstractLarge Language Models (LLMs) have showcased remarkable generalizability in language comprehension and hold significant potential to revolutionize human-computer interaction in smart homes. Existing LLM-based smart home assistants typically transmit user commands, along with user profiles and home configurations, to remote servers to obtain personalized services. However, users are increasingly concerned about the potential privacy leaks to the remote servers. To address this issue, we developHomeLLaMA, an on-device assistant for privacy-preserving and personalized smart home serving with a tailored small language model (SLM).HomeLLaMAlearns from cloud LLMs to deliver satisfactory responses and enable user-friendly interactions. Once deployed,HomeLLaMAfacilitates proactive interactions by continuously updating local SLMs and user profiles. To further enhance user interaction while protecting their privacy, we developPrivShieldto offer an optional, privacy-preserving LLM-based smart home service for users who are unsatisfied with local responses and are willing to send less-sensitive queries to remote servers. For evaluation, we develop a comprehensive benchmark,DevFinder, to assess service quality. Extensive experiments and user studies ($M=100$) demonstrate thatHomeLLaMAcan provide personalized services while significantly enhancing user privacy. Leming Shen, Zijing Ma, Yuanqing Zheng |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | Resolving Inter-Logical Channel Interference for Large-Scale LoRa Deployments
Shiming Yu, Xianjin Xia, Yuanqing Zheng, Jiliang Wang |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Poster: LLMalware: An LLM-Powered Robust and Efficient Android Malware Detection FrameworkabstractAndroid malware pose severe threats to the mobile application ecosystem. Although well-trained malware detection models can initially achieve satisfactory performance, they struggle with unseen Android apps constantly emerging over time, which is known as the concept drift problem. Previous methods frequently collect and label new apps to update the aging models. This process, however, necessitates domain knowledge and incurs prohibitive retraining overhead. To address this problem, this paper presents LLMalware, which integrates three novel technical components. First, we propose full-spectrum automated feature extraction, which automatically extracts diverse malware features from various detection models. Next, we develop cohesive feature fusion, which combines these features to build effective representations for robust malware detection. Lastly, we devise agile knowledge update to enable efficient online malware detection via an LLM-based automated agent and a dynamically maintained malware knowledge base. Extensive experiments demonstrate LLMalware can mitigate concept drift with an average improvement of approximately 10% in F1-score over state-of-the-art baselines. Zijing Ma, Leming Shen, Yuanqing Zheng |
CCS | 4 |
| 2025 | TEMPEST-LoRa: Cross-Technology Covert CommunicationabstractElectromagnetic (EM) covert channels pose significant threats to computer and communications security in air-gapped networks. Previous works exploit EM radiation from various components (e.g., video cables, memory buses, CPUs) to secretly send sensitive information. These approaches typically require the attacker to deploy highly specialized receivers near the victim, which limits their real-world impact. This paper reports a new EM covert channel, TEMPEST-LoRa, that builds on Cross-Technology Covert Communication (CTCC), which could allow attackers to covertly transmit EM-modulated secret data from air-gapped networks to widely deployed operational LoRa receivers from afar. We reveal the potential risk and demonstrate the feasibility of CTCC by tackling practical challenges involved in manipulating video cables to precisely generate the EM leakage that could readily be received by third-party commercial LoRa nodes/gateways. Experiment results show that attackers can reliably decode secret data modulated by the EM leakage from a video cable at a maximum distance of 87.5m or a rate of 21.6 kbps. We note that the secret data transmission can be performed with monitors turned off (therefore covertly). Xieyang Sun, Yuanqing Zheng, Wei Xi 0003, Zuhao Chen, Zhizhen Chen, Zhiping Jiang, Sheng Zhong 0002 |
CCS | 2 |
| 2025 | SlideLoRa: Reliable Channel Activity Monitoring across Massive Logical Channels in LoRa NetworksabstractLoRa technology has been extensively implemented in various IoT applications, offering widespread low-power connectivity for millions of nodes across thousands of logical channels. However, current LoRa networks lack an efficient mechanism for monitoring channel activity across these numerous channels, which prevents network operators from effectively detecting physical layer activities and implementing additional functionalities (e.g., channel access control). Existing solutions either involve complex iterations over each logical channel or fail to detect extremely weak packets in low SNR conditions. These limitations affect their scalability and robustness in monitoring the vast number of logical channels available in the LoRa spectrum. To address this issue, this paper introduces SlideLoRa, an innovative packet detection method that enables detection across all logical channels under various channel conditions. SlideLoRa consolidates the complete energy of LoRa symbols using an expanded demodulation window combined with a fine-grained sliding window, effectively reconstructing the distorted frequency-domain information of LoRa packets. To achieve this, SlideLoRa incorporates a series of novel solutions, including peak tracking in low SNR, peak sequence matching, peak extraction, and packet parameter retrieval. Experimental results demonstrate that SlideLoRa enhances packet detection capability by 1.7× compared to the state-of-the-art. Jiamin Jiang, Shiming Yu, Hao Wang 0213, Yuanqing Zheng, Lu Wang 0002 |
ICNP | 5 |
| 2025 | Satellite IoT in Practice: A First Measurement Study on Network Availability, Performance, and CostsabstractLow Earth Orbit (LEO) satellites have emerged as a space-based infrastructure to offer networking services anywhere on Earth. Satellite IoTs enable novel Direct-to-Satellite (DtS) connectivity, allowing IoT devices in remote areas to connect to the Internet via LEO satellites using existing terrestrial technologies like LoRa. This paper presents the first-of-its-kind measurement study on satellite IoTs, investigating the practical characteristics of DtS communications and their suitability for IoT applications. We deployed 27 low-cost ground stations across eight locations worldwide to passively measure the network availability of multiple constellations. Our findings reveal a significant gap between the effective durations of DtS connectivity and their theoretical durations, leading to intermittent connections for satellite IoTs. Additionally, we examine the performance of the Tianqi constellation in supporting real-world IoT traffic (agriculture application). We observed longer delays and higher power consumption in satellite IoTs compared to terrestrial IoTs. Our study identifies the bottlenecks and sheds light on potential optimizations for satellite IoTs. Wenchang Chai, Jinhong Liu, Xianjin Xia, Yuanqing Zheng, Ningning Hou, Qiang Yang 0018, Weiwei Chen 0004, Tao Gu 0001 |
IMC | 5 |
| 2025 | Push the Limit of Acoustic Indoor Fire MonitoringabstractIn indoor fire rescue, swift and precise fire source localization and fire severity assessment are pivotal for firefighting strategic planning and casualty evacuation. However, existing solutions primarily focus on detecting fire presence, which do not offer insights into fire's localization and severity. In this paper, we propose UltraFlame, an accurate, user-friendly, and timely system for pinpointing fire sources and assessing fire severity based on acoustic sensing, which bridges significant gaps in fire safety and response. UltraFlame consists of a collocated commodity speaker and microphone pair, sensing fire by emitting inaudible sound waves. We conduct an in-depth investigation of sound propagation impacted by fire combustion, providing physically interpretable data for deep learning framework and enabling fire source localization even without any sound reflection by fire. We dedicatedly establish a correlation between fire severity and sound propagation delays, which serves as an effective indicator for estimating the heated region. Finally, an appropriate deep learning framework is employed to effectively extract temporal and spatial features from channel measurement. Extensive experiments demonstrate that 94% of the localization results have an error of less than 0.8m. Additionally, UltraFlame achieves an accuracy of 96.9% in fire severity assessment across diverse setups, providing real-time and reliable monitoring. Zheng Wang 0054, Yuanqing Zheng, Yanwen Wang 0001 |
INFOCOM | 3 |
| 2025 | Poster: Towards Privacy-Preserving and Personalized Smart Homes via Tailored Small Language ModelsabstractLarge Language Models (LLMs) exhibit remarkable language comprehension to revolutionize smart homes. Existing LLM-based smart home assistants typically transmit user commands, along with user profiles and home configurations, to remote servers to obtain personalized services. However, users are increasingly concerned about potential privacy leakage. To address this, we develop HomeLLaMA, an on-device assistant for privacy-preserving personalized smart homes with a tailored small language model (SLM). HomeLLaMA learns from cloud LLMs to deliver satisfactory responses and enable user-friendly interactions. Once deployed, HomeLLaMA facilitates proactive interactions by continuously updating local SLMs and user profiles. To further enhance user interaction while protecting privacy, we develop PrivShield to offer an optional privacy-preserving serving for those users who are unsatisfied with local responses and willing to send less-sensitive queries to remote servers. Experiments demonstrate HomeLLaMA provides satisfactory services while significantly enhancing user privacy. Leming Shen, Zijing Ma, Yuanqing Zheng |
MobiCom | 4 |
| 2025 | From Interference Mitigation to Toleration: Pathway to Practical Spatial Reuse in LPWANsabstractThis paper addresses the interference challenges, aiming to improve spatial reuse and optimize spectrum efficiency in LPWANs. We reveal that existing strategies such as interference cancellation and MIMO are ill-suited to the low-cost low-rate characteristics of LPWANs. Our work introduces a novel framework, HydraNet, which leverages the capture effect of LPWAN radios to enable robust concurrent transmissions. HydraNet exempts from strict clock synchronization or accurate channel estimation as required by conventional spatial reuse strategies for interference nulling. We conduct in-depth studies with LoRa radios to uncover their underlying packet reception mechanisms and for the first time characterize their unique capture effect. Based on the new findings, we devise novel strategies to jointly control the timing and power of concurrent LPWAN transmissions. These strategies ensure sufficient power differences between packets and interference at their intended receivers. We prototype HydraNet and integrate with operational LoRaWANs and comprehensively evaluate its performance. Results show that HydraNet achieves higher spectrum utilization with up to 3.6 × throughput improvements over the state-of-the-art. Xianjin Xia, Ningning Hou, Wenchang Chai, Shiming Yu, Yuanqing Zheng, Tao Gu 0001 |
MobiCom | 7 |
| 2025 | AutoIOT: LLM-Driven Automated Natural Language Programming for AIoT ApplicationsabstractThe advent of Large Language Models (LLMs) has profoundly transformed our lives, revolutionizing interactions with AI and lowering the barrier to AI usage. While LLMs are primarily designed for natural language interaction, the extensive embedded knowledge empowers them to comprehend digital sensor data. This capability enables LLMs to engage with the physical world through IoT sensors and actuators, performing a myriad of AIoT tasks. Consequently, this evolution triggers a paradigm shift in conventional AIoT application development, democratizing its accessibility to all by facilitating the design and development of AIoT applications via natural language. However, some limitations need to be addressed to unlock the full potential of LLMs in AIoT application development. First, existing solutions often require transferring raw sensor data to LLM servers, which raises privacy concerns, incurs high query fees, and is limited by token size. Moreover, the reasoning processes of LLMs are opaque to users, making it difficult to verify the robustness and correctness of inference results. This paper introduces AutoIOT, an LLM-based automated program generator for AIoT applications. AutoIOT enables users to specify their requirements using natural language (input) and automatically synthesizes interpretable programs with documentation (output). AutoIOT automates the iterative optimization to enhance the quality of generated code with minimum user involvement. AutoIOT not only makes the execution of AIoT tasks more explainable but also mitigates privacy concerns and reduces token costs with local execution of synthesized programs. Extensive experiments and user studies demonstrate AutoIOT's remarkable capability in program synthesis for various AIoT tasks. The synthesized programs can match and even outperform some representative baselines. Leming Shen, Qiang Yang 0018, Yuanqing Zheng, Mo Li 0001 |
MobiCom | 3 |
| 2025 | Poster: Towards Federated Embodied AI with FEAIabstractEmbodied AI (EAI) transforms our daily lives by bridging intelligent agents with various sensors and actuators. Large Language Models (LLMs) further enhance EAI agents in environment comprehension, task decomposition, and action execution for robotic manipulation. However, developing a general EAI agent capable of adapting to and continuously learning from diverse operating environments is extremely challenging: 1) Robots with mobility capture environments from multiple perspectives, leading to heterogeneous semantic interpretations, particularly in large or open settings. 2) Heterogeneous environments further exacerbate the variability of decomposed tasks and corresponding actions required for robotic manipulation. To address these challenges, we propose FEAI, a novel paradigm to enhance the adaptability and self-learning capabilities of EAI agents in heterogeneous environments via federated embodied learning. Specifically, FEAI shares and constructively aggregates environment semantic maps, decomposed task templates, and action-reward rules from federated EAI agents. The aggregated information can further enhance EAI agents' local models through continuous tuning or dynamically updated knowledge databases. We believe that FEAI has significant potential to integrate more advanced technologies, further advancing performance and innovation in the field of EAI. Leming Shen, Yuanqing Zheng |
MobiSys | 2 |
| 2025 | Are LoRa Logical Channels Really Orthogonal? Practically Orthogonalizing Massive Logical ChannelsabstractLoRaWANs are envisioned to connect billions of IoT devices through thousands of physically overlapping yet logically orthogonal channels (termed logical channels). These logical channels hold significant potential for enabling highly concurrent scalable IoT connectivity. Large-scale deployments however face strong interference between logical channels. This practical issue has been largely overlooked by existing works but becomes increasingly prominent as LoRaWAN scales up. To address this issue, we introduce Canas, an innovative gateway design that is poised to orthogonalize the logical channels by eliminating mutual interference. To this end, Canas develops a series of novel solutions to accurately extract the meta-information of individual ultra-weak LoRa signals from the received overlapping channels. The meta-information is then leveraged to accurately reconstruct and subtract the LoRa signals over thousands of logical channels iteratively. Real-world evaluations demonstrate that Canas can enhance concurrent transmissions across overlapping logical channels by 2.3× compared to the best known related works. Shiming Yu, Xianjin Xia, Yuanqing Zheng, Jiliang Wang |
MobiSys | 4 |
| 2025 | MoLoRa: Intelligent Mobile Antenna System for Enhanced LoRa Reception in Urban EnvironmentsabstractLoRa technology promises to enable Internet of Things applications over large geographical areas. However, its performance is often hampered by poor channel quality in urban environments, where blockage and multipath effects are prevalent. Our study uncovers that a slight shift in the position or attitude of the receiving antenna can substantially improve the received signal quality. This phenomenon can be attributed to the rich multipath characteristics of wireless signal propagation in urban environments, wherein even small antenna movement can alter the dominant signal path or reduce the polarization angular difference between transceivers. Leveraging these key observations, we propose and implement MoLoRa, an intelligent mobile antenna system designed to enhance LoRa packet reception. At its core, MoLoRa represents the position and attitude of an antenna as a state and employs a statistical optimization method to search for states that offer optimal signal quality efficiently. Through extensive evaluation, we demonstrate that MoLoRa achieves a maximum Signal-to-Noise Ratio (SNR) gain of 13 dB in a few attempts, enabling formerly problematic blind spots to reconnect and strengthening links for other nodes. Ningning Hou, Yifeng Wang 0002, Xianjin Xia, Shiming Yu, Yuanqing Zheng, Tao Gu 0001 |
SenSys | 5 |
| 2025 | GPIoT: Tailoring Small Language Models for IoT Program Synthesis and DevelopmentabstractCode Large Language Models (LLMs) enhance software development efficiency by automatically generating code and documentation based on user requirements. However, code LLMs cannot synthesize specialized programs when tasked with IoT applications that require domain knowledge. While Retrieval-Augmented Generation (RAG) offers a promising solution by fetching relevant domain knowledge, it necessitates powerful cloud LLMs (e.g., GPT-4) to process user requirements and retrieved contents, which raises significant privacy concerns. This approach also suffers from unstable networks and prohibitive LLM query costs. Moreover, it is challenging to ensure the correctness and relevance of the fetched contents. To address these issues, we propose GPIoT, a code generation system for IoT applications by fine-tuning locally deployable Small Language Models (SLMs) on IoT-specialized datasets. SLMs have smaller model sizes, allowing efficient local deployment and execution to mitigate privacy concerns and network uncertainty. Furthermore, by fine-tuning SLMs with our IoT-specialized datasets, the SLMs' ability to synthesize IoT-related programs can be substantially improved. To evaluate GPIoT's capability in synthesizing programs for IoT applications, we develop a benchmark, IoTBench. Extensive experiments and user trials demonstrate the effectiveness of GPIoT in generating IoT-specialized code, outperforming state-of-the-art code LLMs with an average task accuracy increment of 64.7% and significant improvements in user satisfaction. Leming Shen, Qiang Yang 0018, Zijing Ma, Yuanqing Zheng |
SenSys | 5 |
| 2025 | Towards Next-Generation Global IoT: Empowering Massive Connectivity with Harmonious Multi-Network CoexistenceabstractLoRaWAN offers a compelling solution for delivering cost-effective network access to millions of IoT devices worldwide. However, operators face challenges in scaling their services to meet the growing demands of IoT connections. Moreover, current LoRaWANs foster competition rather than cooperation among coexisting networks, resulting in substantial capacity degradation as network density increases. To identify the root causes limiting LoRaWAN scalability and to enable harmonious coexistence among network operators, this paper conducts an in-depth investigation of operational LoRaWANs. For the first time, our study reveals that the capacity degradation in LoRaWAN is not due to traditionally believed issues (such as wireless contention or interference) but rather a newly-identified decoder contention problem. This problem cannot be resolved using conventional approaches and hinders the scaled deployment of LoRaWANs as a global IoT infrastructure. Based on our new findings, we propose design principles that guide our exploration for effective strategies to address this emerging practical problem. We develop concrete deployable solutions to mitigate contention, optimize spectrum utilization, and promote spectrum sharing among network operators. Extensive evaluations demonstrate that our strategies effectively boost network capacity close to the theoretical bound, and support the coexistence of up to six networks with significant improvement in spectrum efficiency. Xianjin Xia, Yuanqing Zheng |
SIGCOMM | 4 |
| 2025 | DiskSpy: Exploring a Long-Range Covert-Channel Attack via mmWave Sensing of μm-level HDD Vibrations
Weiye Xu 0001, Danli Wen, Jianwei Liu 0008, Zixin Lin, Yuanqing Zheng, Jinsong Han |
USENIX Security Symposium | 5 |
| 2025 | Hierarchical and Heterogeneous Federated Learning via a Learning-on-Model ParadigmabstractFederated Learning (FL) collaboratively trains a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., smartphones and wearables) typically have disparate system resources. Traditional FL, however, adopts a one-size-fits-all solution, where a homogeneous large model is sent to and trained on each client. This method results in an overwhelming workload for less capable clients and starvation for others. To tackle this, we proposeFedConv, a client-friendly FL framework, minimizing the system overhead on resource-constrained clients by providing heterogeneous customized sub-models.FedConvfeatures a novellearning-on-modelparadigm that learns the parameters of heterogeneous sub-models viaconvolutional compression. To aggregate heterogeneous sub-models, we proposetransposed convolutional dilationto convert them back to large models with a unified size while retaining personalized information. The compression and dilation processes, transparent to clients, are tuned on the server using a small public dataset. We further propose ahierarchical and clustering-based local trainingstrategy for enhanced performance. Extensive experiments on six datasets show thatFedConvoutperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively). Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | FDLoRa: Scaling Downlink Concurrent Transmissions With Full-Duplex LoRa GatewaysabstractUnlike traditional data collection applications which primarily rely on uplink transmissions, emerging applications (e.g., device actuation, firmware update, packet reception acknowledgment) increasingly demand robust downlink transmission capabilities. Current LoRaWAN systems struggle to support these applications due to the inherent asymmetry between downlink and uplink capabilities. While uplink transmissions can handle multiple packets simultaneously, downlink transmissions are restricted to a single logical channel at a time, significantly limiting the deployment of applications that require substantial downlink capacity. To address this challenge,FDLoRaintroduces an innovative in-band full-duplex LoRa gateway design, featuring novel solutions to mitigate self-interference (i.e., the strong downlink interference to ultra-weak uplink reception). This approach enables full-spectrum in-band downlink transmissions without compromising the reception of weak uplink packets. Building on the capabilities of full-duplex gateways,FDLoRapresents a new downlink framework that supports concurrent downlink transmissions across multiple logical channels of available gateways. Evaluation results show thatFDLoRaenhances downlink capacity by 5.7× compared to LoRaWAN in a three-gateway testbed and achieves 2.58× higher downlink concurrency per gateway than the current leading solutions. Shiming Yu, Xianjin Xia, Ningning Hou, Yuanqing Zheng |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | XGate: Scaling LoRa Communications to Massive Logical ChannelsabstractLoRa is a promising technology that provides widespread low-power IoT connectivity. With its capabilities for multi-channel communication, orthogonal transmission, and spectrum sharing, LoRaWAN is poised to connect millions of IoT devices across thousands of logical channels. However, current LoRa gateways rely on hardwired Rx chains that cover less than 1% of these channels, restricting the potential for large-scale LoRa communications. This paper introduces XGate, a groundbreaking gateway design that uses a single Rx chain to simultaneously receive packets from all logical channels, enabling scalable LoRa transmission and flexible network access. Unlike the hardwired Rx chains in existing gateway designs, XGate dynamically allocates resources, including software-controlled Rx chains and demodulators, based on the extracted meta-information of incoming packets. XGate overcomes several challenges to efficiently detect incoming packets without prior knowledge of their parameter configurations. Evaluations demonstrate that XGate enhances LoRa concurrent transmissions by$8.4\times $compared to state-of-the-art solutions. Shiming Yu, Xianjin Xia, Ningning Hou, Yuanqing Zheng, Tao Gu 0001 |
IEEE Trans. Netw. | 4 |
| 2024 | MuSAC: Mutualistic Sensing and Communication for Mobile CrowdsensingabstractSensing and communication are at the core of the Internet of Things, which usually function independently. For example, a smartphone can communicate over Wi-Fi or cellular networks while continuously acquiring sensory data from the environment through various sensors. This paper presents a novel framework, MuSAC (Mutualistic Sensing and Commu-nication), which seamlessly integrates the collection of sensory data with existing communication systems, without adding any extra communication overhead. The framework leverages the mutualistic relationship between specific communication data and sensory data to effectively crowdsource heterogeneous sensory data without harming communication performance in practical distributed systems. To embed massive sensory data into the current transmission of communication data, MuSAC presents novel neural networks to distill universal features from the raw data for compression at the sender side and then extract invariant features on the server side. By doing so, MuSAC eliminates additional communication costs for sensory data collection while also mitigating privacy concerns and data heterogeneity in crowd-sensing. Our real-world experimental validation in Wi-Fi and cellular Massive MIMO communication scenarios demonstrates the effectiveness of the MuSAC framework, shedding light on efficient mobile crowdsensing for massive IoT data collection. Sijie Ji, Lixiang Lian, Yuanqing Zheng, Chenshu Wu |
ICDCS | 3 |
| 2024 | Neural Enhanced Underwater SOS DetectionabstractEvery day, one person loses his life due to drowning in swimming pools, even with professional lifeguards present. Contrary to what the public might assume, drowning swimmers can hardly splash or yell for help. This life-threatening situation calls for a robust SOS channel between the swimmers and the lifeguards. This paper proposes Neusos, a neural-enhanced underwater SOS communication system based on commercial wearable devices and low-cost hydrophones deployed in the swimming pool. Specifically, we repurpose popular wearable devices (e.g., smartwatches) as SOS transmitters, which can send a distress signal when the user is in an emergency. In response, an underwater hydrophone in the swimming pool can detect SOS signals and make alerts immediately to facilitate a timely rescue. The main technical challenge lies in reliably detecting weak SOS signals in non-stationary underwater scenarios. To achieve so, we thoroughly characterize the properties of underwater channels and examine the limitations of the traditional correlation-based signal detection method in underwater communication scenarios. Based on our empirical findings, we developed a robust SOS detection method enhanced with deep learning. By fully embedding signal characteristics into networks, Neusos outperforms traditional signal processing-based underwater SOS detection methods. In particular, our experiments in a real swimming pool show that Neusos can detect SOS signals with a detection rate of 98.2% under various underwater conditions. Given the increasing popularity of smartwatches among swimmers, our system holds immense potential to enhance their safety in swimming pools. Qiang Yang 0018, Yuanqing Zheng |
INFOCOM | 2 |
| 2024 | Talk2Radar: Talking to mmWave Radars via Smartphone SpeakerabstractIntegrated Sensing and Communication (ISAC) is gaining a tremendous amount of attention from both academia and industry. Recent work has brought communication capability to sensing-oriented mmWave radars, enabling more innovative applications. These solutions, however, either require hardware modifications or suffer from limited data rates. This paper presents Talk2Radar, which builds a faster communication channel between smartphone speakers and mmWave radars, without any hardware modification to either commodity smartphones or off-the-shelf radars. In Talk2Radar, a smartphone speaker sends messages by playing carefully designed sounds. A mmWave radar acting as a data receiver captures the emitted sounds by detecting the sound-induced smartphone vibrations, and then decodes the messages. Talk2Radar characterizes smartphone speakers for speaker-to-mmWave radar communication and addresses a series of technical challenges, including modulation and demodulation of extremely weak sound-induced vibrations, multi-speaker concurrent communication and human motion suppression. We implement and evaluate Talk2Radar in various practical settings. Experimental results show that Talk2Radar can achieve a data rate of up to 400bps with an average BER of less than 5%, outperforming the state-of-the-art by approximately 33×. Kaiyan Cui, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han |
INFOCOM | 3 |
| 2024 | IoTCoder: A Copilot for IoT Application DevelopmentabstractExisting code Large Language Models are primarily designed for generating simple and general algorithms but are not dedicated to IoT applications. To fill this gap, we present IoTCoder, a coding copilot specifically designed to synthesize programs for IoT application development. IoTCoder features three locally deployed small language models (SLMs): a Task Decomposition SLM that decomposes a complex IoT application into multiple tasks with detailed descriptions, a Requirement Transformation SLM that converts the decomposed tasks described in natural language to well-structured specifications, and a Modularized Code Generation SLM that generates modularized code based on the task specifications. Experiment results show that IoTCoder can synthesize programs adopting more IoT-specific algorithms and outperform state-of-the-art code LLMs in terms of both task accuracy (by more than 24.2% on average) and memory usage (by less than 358.4 MB on average). Leming Shen, Yuanqing Zheng |
MobiCom | 2 |
| 2024 | Revolutionizing LoRa Gateway with XGate: Scalable Concurrent Transmission across Massive Logical ChannelsabstractLoRa is a promising technology that offers ubiquitous low-power IoT connectivity. With the features of multi-channel communication, orthogonal transmission, and spectrum sharing, LoRaWAN is poised to connect millions of IoT devices across thousands of logical channels. However, current LoRa gateways utilize hardwired Rx chains that cover only a small fraction (<1%) of the logical channels, limiting the potential for massive LoRa communications. This paper presents XGate, a novel gateway design that uses a single Rx chain to concurrently receive packets from all logical channels, fundamentally enabling scalable LoRa transmission and flexible network access. Unlike hardwired Rx chains in the current gateway design, XGate allocates resources including software-controlled Rx chains and demodulators based on the extracted meta information of incoming packets. XGate addresses a series of challenges to efficiently detect incoming packets without prior knowledge of their parameter configurations. Evaluations show that XGate boosts LoRa concurrent transmissions by 8.4× than state-of-the-art. Shiming Yu, Xianjin Xia, Ningning Hou, Yuanqing Zheng, Tao Gu 0001 |
MobiCom | 4 |
| 2024 | FedConv: A Learning-on-Model Paradigm for Heterogeneous Federated ClientsabstractFederated Learning (FL) facilitates collaborative training of a shared global model without exposing clients' private data. In practical FL systems, clients (e.g., edge servers, smartphones, and wearables) typically have disparate system resources. Conventional FL, however, adopts a one-size-fits-all solution, where a homogeneous large global model is transmitted to and trained on each client, resulting in an overwhelming workload for less capable clients and starvation for other clients. To address this issue, we propose FedConv, a client-friendly FL framework, which minimizes the computation and memory burden on resource-constrained clients by providing heterogeneous customized sub-models. FedConv features a novel learning-on-model paradigm that learns the parameters of the heterogeneous sub-models via convolutional compression. Unlike traditional compression methods, the compressed models in FedConv can be directly trained on clients without decompression. To aggregate the heterogeneous sub-models, we propose transposed convolutional dilation to convert them back to large models with a unified size while retaining personalized information from clients. The compression and dilation processes, transparent to clients, are optimized on the server leveraging a small public dataset. Extensive experiments on six datasets demonstrate that FedConv outperforms state-of-the-art FL systems in terms of model accuracy (by more than 35% on average), computation and communication overhead (with 33% and 25% reduction, respectively). Leming Shen, Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng, Xiaoyong Wei, Jianwei Liu 0008, Jinsong Han |
MobiSys | 4 |
| 2024 | LoDiHAR: A Low-Cost Distributed Human Activity Recognition System Based on RFIDabstractHuman Activity Recognition has been extensively applied to fulfill tasks such as fall detection, human-computer interaction, virtual reality, etc. Existing radio frequency-based HAR methods, although overcoming limitations of wearable-, visual-, and acoustic-based sensing technology, still suffer from high costs and low efficiency, which limits their pervasive use. In this paper, we propose LoDiHAR, a low-cost, distributed HAR system leveraging Radio Frequency Identification technology. LoDiHAR employs low-cost and fully programmable commercial wireless components, providing full access to the PHY samples of the backscattered signals, in which signal phases can be extracted to infer different activities. Different from COTS RFID systems that adopt a polling interrogation scheme, LoDiHAR supports a distributed sensing scheme, which profiles human activities more efficiently. LoDiHAR addresses a series of technical challenges such as accurate phase extraction from backscattered signals, asynchronous distributed RF data fusion and insufficient training data. A Conditional Generative Adversarial Network framework combined with a Transformer model is designed for accurate time-series activity classification. LoDiHAR demonstrates pro-ficiency in recognizing eight types of human activities across diverse environments, achieving an accuracy of up to 94.9% while only costing 10% of the mainstream COTS RFID systems. Yanwen Wang 0001, Zheng Wang 0054, Xiaokang Shi, Yuanqing Zheng |
SECON | 6 |
| 2024 | FDLoRa: Tackling Downlink-Uplink Asymmetry with Full-duplex LoRa GatewaysabstractUnlike traditional data collection applications (e.g., environment monitoring) that are dominated by uplink transmissions, the newly emerging applications (e.g., device actuation, firmware update, packet reception acknowledgement) also pose ever-increasing demands on downlink transmission capabilities. However, current LoRaWAN falls short in supporting such applications primarily due to downlink-uplink asymmetry. While the uplink can concurrently receive multiple packets, downlink transmission is limited to a single logical channel at a time, which fundamentally hinders the deployment of downlink-hungry applications. To tackle this practical challenge, FDLoRa develops the first-of-its-kind in-band full-duplex LoRa gateway design with novel solutions to mitigate the impact of self-interference (i.e., strong downlink interference to ultra-weak uplink reception), which unleashes the full spectrum for in-band downlink transmissions without compromising the reception of weak uplink packets. Built upon the full-duplex gateways, FDLoRa introduces a new downlink framework to support concurrent downlink transmissions over multiple logical channels of available gateways. Evaluation results demonstrate that FDLoRa boosts downlink capacity by 5.7x compared to LoRaWAN on a three-gateway testbed and achieves 2.58x higher downlink concurrency per gateway than the state-of-the-art. Shiming Yu, Xianjin Xia, Ningning Hou, Yuanqing Zheng |
SenSys | 5 |
| 2024 | Room-Scale Voice Liveness Detection for Smart DevicesabstractVoice assistants are widely integrated into a variety of mobile devices, enabling users to easily complete daily tasks and even critical operations like online transactions with voice commands. Thus, once attackers replay a secretly-recorded voice command by loudspeakers to compromise users' voice assistants, this operation will cause serious consequences, such as information leakage and property loss. Unfortunately, most voice liveness detection approaches against replay attacks mainly rely on detecting lip motions or subtle physiological features in speech, which are limited within a very short range. In this paper, we propose VoShield to check whether a voice command is from a genuine user or a loudspeaker imposter. VoShield measures sound field dynamics, a feature that changes fast as the human mouths dynamically open and close. In contrast, it would remain rather stable for loudspeakers due to the fixed size. This feature enables VoShield to largely extend the working distance and remain resilient to user locations. Besides, sound field dynamics are extracted from the difference between multiple microphone channels, making this feature robust to voice volume. To evaluate VoShield, we conducted comprehensive experiments with various settings in different working scenarios. The results show that VoShield can achieve a detection accuracy of 98.2% and an Equal Error Rate of 2.0%, which serves as a promising complement to current voice authentication systems for smart mobile devices. Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Towards ISAC-Empowered mmWave Radars by Capturing Modulated VibrationsabstractIntegrated Sensing and Communication (ISAC) has emerged as a promising technology for next-generation mobile networks. Towards ISAC, we developmmRipplethat empowers commodity mmWave radars with communication capabilities through smartphone vibrations. InmmRipple, a smartphone (transmitter) sends messages by modulating smartphone vibrations, while a mmWave radar (receiver) receives the messages by detecting and decoding the smartphone vibrations. By doing so, a smartphone user can not only be passively sensed by a mmWave radar, but also actively send messages to the radar without any hardware modifications. Although promising, the data rate ofmmRippleis limited by Morse-style communication. To address this, we presentmmRipple+, which leverages the Pulse Width and Amplitude Modulation (PWAM) technique and suppresses inter-symbol interference to enable faster communication. We prototypemmRippleandmmRipple+on commodity mmWave radars and different types of smartphones. Experimental results show thatmmRippleachieves an average vibration pattern recognition accuracy of 98.60% within a$ 2$m communication range, and 97.74% within$ 3$m. The maximum communication range extends to$ 5$m. Meanwhile,mmRipple+achieves a bit rate of 100 bps with a BER of less than 3%, improving the data rate by 4× overmmRippewith the same symbol duration. This work pioneers smartphone-to-COTS mmWave radar communication via vibrations, unlocking diverse applications. Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Fu Xiao 0001, Jinsong Han |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | OmniResMonitor: Omnimonitoring of Human Respiration using Acoustic Multipath ReflectionabstractContactless respiration monitoring using wireless signals has drawn much attention in recent years. Many approaches have been proposed, however, they may not work when there is a lack of signals directly reflected from target's chest, e.g., a target faces away from the transceiver or a target is blocked by furniture. In this paper, we design and implement a novel omnimonitoring system for human respiration,OmniRespMonitor, using a pair of speaker and microphone. Different from Radio Frequency (RF) signal, acoustic signals cannot penetrate through walls and furniture. The multipath reflection in an indoor environment will result in highly abundant acoustic signals. In this case, even though there are lack of acoustic signals directly reflected by a target's chest, indirectly-reflected acoustic signals can still be received by the microphone. We can therefore monitor the target's respiration by extracting this subtle variation of indirectly reflected signals. To achieve this, we model chest movement using truncated System Frequency Response (SFR). We then develop a global search method based on the autocorrelation function to extract minute chest movement from SFR sequences. Finally, we dynamically synthesize the chest movement information to recover the breathing wave in real time. We conduct extensive experiments with both humans and animals (goat), the results show thatOmniResMonitoris able to monitor single target's respiration within 5 meters in indoor environments in various challenging scenarios there are lack of directly-reflected acoustic signals. Tianben Wang, Xiantao Liu, Leye Wang, Yuanqing Zheng, Jin Hu 0007, Tao Gu 0001, Daqing Zhang 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Anti-Spoofing Facial Authentication Based on COTS RFIDabstractCurrent facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, but they are still vulnerable to feature manipulation, e.g., 3D-printed human faces. In this article, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. Unlike images, RF signals are not perceptible to human eyes, so RFace protects user's privacy. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between facial features and RF signals. To enhance the security of RFace, we specify the tag reading order for each authentication to defend against the signal replay attack. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7$\%$and an EER of 4.4$\%$. More importantly, no replay attack or spoofing attack succeeds in deceiving RFace in the experiments. Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Fu Xiao 0001, Jinsong Han |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | DeepEar: Sound Localization With Binaural MicrophonesabstractThe binaural microphone, which refers to a pair of microphones with artificial human-shaped ears, is widely used in hearing aids and spatial audio recording to improve sound quality. It is crucial for such devices to find the voice direction in many applications such as binaural sound enhancement. However, sound localization with two microphones remains challenging, especially in multi-source scenarios. Most previous work utilized microphone arrays to deal with the multi-source localization problem. Extra microphones yet have space constraints for deployment in many scenarios (e.g., hearing aids). Inspired by the fact that humans have evolved to locate multiple sound sources with only two ears, we propose DeepEar, a binaural microphone-based sound localization system. To this end, we design a multisector-based neural network to locate multiple sound sources simultaneously, where each sector is a discretized region of the space for different angle of arrivals. DeepEar fuses explicit hand-crafted features and implicit latent sound representatives to facilitate sound localization. More importantly, the trained DeepEar model can adapt to new environments with a minimum amount of extra training data. The experiment results show that DeepEar substantially outperforms the state-of-the-art binaural deep learning approach by a large margin in terms of sound detection accuracy and azimuth estimation error. Qiang Yang 0018, Yuanqing Zheng |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | One Shot for All: Quick and Accurate Data Aggregation for LPWANsabstractThis paper presents our design and implementation of a fast and accurate data aggregation strategy for LoRa networks namedOne-shot. To facilitate data aggregation, One-shot assigns distinctive chirps for different LoRa nodes to encode individual data. One-shot coordinates the nodes to concurrently transmit encoded packets. Receiving concurrent transmissions, One-shot gateway examines the frequencies of superimposed chirp signals and computes application-defined aggregate functions (e.g., sum, max, count, ), which give a quick overview of sensor data in a large monitoring area. One-shot develops techniques to handle a series of practical challenges involved in frequency and time synchronization of concurrent chirps. We evaluate the effectiveness of One-shot with extensive experiments. Results show that One-shot substantially outperforms state-of-the-art data aggregation methods in terms of aggregation accuracy as well as query efficiency. Ningning Hou, Xianjin Xia, Yifeng Wang 0002, Yuanqing Zheng |
IEEE/ACM Trans. Netw. | 4 |
| 2024 | HyLink: Toward High Throughput LPWANs With LoRa Compatible CommunicationabstractThis paper presents the design and implementation of HyLink which aims to fill the gap between limited link capacity of LoRa and the diverse bandwidth requirements of IoT systems. At the heart of HyLink is a novel technique named parallel Chirp Spread Spectrum modulation, which tunes the number of modulated symbols to adapt bit-rates according to channel conditions. Over strong link connections, HyLink fully exploits the link capability to transmit more symbols and thus transforms good channel SNRs to high link throughput. While for weak links, it conservatively modulates one symbol and concentrates all transmit power onto the symbol to combat poor channels, which can achieve the same performance as legacy LoRa. HyLink addresses a series of technical challenges on encoding and decoding of multiple payloads in a single packet, aiming at amortizing communication overheads in terms of channel access, radio-on power, transmission air-time, etc. We perform extensive experiments to evaluate the effectiveness of HyLink. Evaluations show that HyLink produces up to$10\times $higher bit rates than LoRa when channel SNRs are higher than$\mathrm {5 dB}$. HyLink inter-operates with legacy LoRa devices and can support new emerging traffic-intensive IoT applications. Xianjin Xia, Qianwu Chen, Ningning Hou, Yuanqing Zheng, Tao Gu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | FedDM: Data and Model Heterogeneity-Aware Federated Learning via Dynamic Weight SharingabstractFederated Learning (FL) plays an indispensable role in edge computing systems. Prevalent FL methods mainly address challenges involved in heterogeneous data distribution across devices. Model heterogeneity, however, has seldom been put under scrutiny. In practice, different devices (e.g., PCs and smartphones) generally have disparate computation and communication resources, necessitating neural network models with varying parameter sizes. Therefore, we propose FedDM, a novel data and model heterogeneity-aware FL system, which improves the FL system's accuracy while reducing edge devices' computation and communication costs for heterogeneous model training. FedDM features: 1) dynamic weight sharing scheme that handles model heterogeneity by dynamically selecting parts of the large model to share with smaller ones; 2) tree-structured layer-wise client cooperation scheme that handles data heterogeneity by allowing clients with similar data distribution to share some network layers. We implement FedDM and evaluate it using five public datasets with different tasks. Leming Shen, Yuanqing Zheng |
ICDCS | 2 |
| 2023 | One Shot for All: Quick and Accurate Data Aggregation for LPWANsabstractThis paper presents our design and implementation of a fast and accurate data aggregation strategy for LoRa networks named One-shot. To facilitate data aggregation, One-shot assigns distinctive chirps for different LoRa nodes to encode individual data. One-shot coordinates the nodes to concurrently transmit encoded packets. Receiving concurrent transmissions, One-shot gateway examines the frequencies of superimposed chirp signals and computes application-defined aggregate functions (e.g., sum, max, count, etc.), which give a quick overview of sensor data in a large monitoring area. One-shot develops techniques to handle a series of practical challenges involved in frequency and time synchronization of concurrent chirps. We evaluate the effectiveness of One-shot with extensive experiments. Results show that One-shot substantially outperforms state-of-the-art data aggregation methods in terms of aggregation accuracy as well as query efficiency. Ningning Hou, Xianjin Xia, Yifeng Wang 0002, Yuanqing Zheng |
INFOCOM | 4 |
| 2023 | VoShield: Voice Liveness Detection with Sound Field Dynamics
Qiang Yang 0018, Kaiyan Cui, Yuanqing Zheng |
INFOCOM | 3 |
| 2023 | mmRipple: Communicating with mmWave Radars through Smartphone VibrationabstractThis paper presents the design and implementation of mmRipple, which empowers commodity mmWave radars with the communication capability through smartphone vibrations. In mmRipple, a smartphone (transmitter) sends messages by modulating smartphone vibrations, while a mmWave radar (receiver) receives the messages by detecting and decoding the smartphone vibrations with mmWave signals. By doing so, a smartphone user can not only be passively sensed by a mmWave radar, but also actively send messages to the radar using her smartphone without any hardware modifications to either the smartphone or the mmWave radar. mmRipple addresses a series of unique technical challenges, including vibration signal generation, tiny vibration sensing, multiple object separation, and movement interference mitigation. We implement and evaluate mmRipple using commodity mmWave radars and smartphones in different practical conditions. Experimental results show that mmRipple achieves an average vibration pattern recognition accuracy of 98.60% within a 2m communication range, and 97.74% within 3m on 11 different types of smartphones. The communication range can be further extended up to 5m with an accuracy of 91.67% with line-of-sight path. To our best knowledge, mmRipple is the first work that allows smartphones to send data to COTS mmWave radars via smartphone vibrations and will enable many new applications such as vibration-based near field communication and pedestrian-to-sensing-infrastructure communication. Kaiyan Cui, Qiang Yang 0018, Yuanqing Zheng, Jinsong Han |
IPSN | 3 |
| 2023 | XCopy: Boosting Weak Links for Reliable LoRa CommunicationabstractLoRaWAN suffers dramatic performance degradation over a long communication range due to signal attenuation and blockages. To ensure reliable data transfer, LoRaWAN adopts retransmission mechanism where an unacknowledged packet is retransmitted multiple times in the hope of successfully delivering the packet at least once over harsh wireless channels. This retransmission mechanism is ill-suited for LoRa: 1) unsuccessful retransmissions lead to high power consumption for battery-powered LoRa nodes, and 2) a retransmission at another time does not necessarily improve the signal strength over harsh wireless channels. Xianjin Xia, Qianwu Chen, Ningning Hou, Yuanqing Zheng, Mo Li 0001 |
MobiCom | 4 |
| 2023 | AquaHelper: Underwater SOS Transmission and Detection in Swimming PoolsabstractDrowning incidents can occur in swimming pools even with professional lifeguards present. This is because drowning swimmers often face difficulties in calling for help due to choking, making it challenging for lifeguards to recognize them and provide a timely rescue. To address this problem, this paper presents AquaHelper, an underwater SOS system that can transmit and detect acoustic SOS signals in swimming pools. Specifically, a wearable device (e.g., a smartwatch) serves as an underwater SOS transmitter, with which a swimmer can call for help in emergency situations. Multiple underwater acoustic receivers are deployed to detect SOS signals and promptly alert lifeguards. The main challenge lies in the low transmission power of lightweight wearable devices, which poses difficulties in detecting weak SOS signals, particularly in low-SNR underwater scenarios. To achieve reliable underwater SOS detection, AquaHelper develops novel techniques (e.g., incorporating high-order harmonics, multi-scale window aggregation, and coherent combining of multiple receivers) to fully leverage the spectral, temporal, and spatial diversity of underwater acoustic signals. We also describe lessons learned and our solutions to address practical challenges involved in underwater SOS transmission and detection. Our experiments demonstrate the effectiveness of AquaHelper in detecting SOS signals in typical swimming pool environments. Qiang Yang 0018, Yuanqing Zheng |
SenSys | 2 |
| 2023 | Construct 3D Hand Skeleton with Commercial WiFiabstractThis paper presents HandFi, which constructs hand skeletons with practical WiFi devices. Unlike previous WiFi hand sensing systems that primarily employ predefined gestures for pattern matching, by constructing the hand skeleton, HandFi can enable a variety of downstream WiFi-based hand sensing applications in gaming, healthcare, and smart homes. Deriving the skeleton from WiFi signals is challenging, especially because the palm is a dominant reflector compared with fingers. HandFi develops a novel multi-task learning neural network with a series of customized loss functions to capture the low-level hand information from WiFi signals. During offline training, HandFi takes raw WiFi signals as input and uses the leap motion to provide supervision. During online use, only with commercial WiFi, HandFi is capable of producing 2D hand masks as well as 3D hand poses. We demonstrate that HandFi can serve as a foundation model to enable developers to build various applications such as finger tracking and sign language recognition, and outperform existing WiFi-based solutions. Artifacts can be found: https://github.com/SIJIEJI/HandFi Sijie Ji, Xuanye Zhang, Yuanqing Zheng, Mo Li 0001 |
SenSys | 3 |
| 2023 | A One-Way Time Synchronization Scheme for Practical Energy-Efficient LoRa Network Based on Reverse Asymmetric FrameworkabstractLong Range (LoRa) network has been thriving in the IoT era due to its long-range coverage and energy efficiency. Prevalent LoRa applications rely on time synchronization to achieve accurate data ordering and coordination among the LoRa network. The energy-efficient nature of the LoRa network where end nodes in sleep scheduling always initiate communications, however, contradicts most conventional time synchronization methods based on message exchanges. In this paper, we propose a one-way time synchronization scheme tailored for the energy-efficient LoRa network based on the reverse asymmetric framework. We first discuss the delay minimization and compensation for the reverse one-way time synchronization in the LoRa network. We then propose a time synchronization scheme consisting of two time translation methods with different computational complexities and error bounds, respectively for resource-abundant and -constrained LoRa gateway and end nodes. Experiment results on a real LoRa testbed consisting of LoRa gateway and end nodes demonstrate that the proposed scheme could achieve microsecond-level synchronization accuracy in both scenarios between the end node and gateway and between the end node and end node; the latter scenario is advocated in the recent multi-hop LoRa network research. Xintao Huan, Han Hu 0003, Yuanqing Zheng |
IEEE Trans. Commun. | 5 |
| 2023 | SymmeProof: Compact Zero-Knowledge Argument for Blockchain Confidential TransactionsabstractTo reduce the transmission cost of blockchain confidential transactions, we propose SymmeProof, a novel communication efficient non-interactive zero-knowledge range proof protocol without a trusted setup. We design and integrate two new techniques in SymmeProof, namely vector compression and inner-product range proof. The proposed vector compression is able to reduce the communication cost to log(n) for n-size vectors. The proposed inner-product range proof converts a range proof relation into an inner-product form, which can further reduce the range proof size with the vector compression technique. Based on these two techniques, SymmeProof can eventually achieve a log(n)-size range proof. The proposed SymmeProof can be used in many important applications such as blockchain confidential transactions as well as arguments for arithmetic circuits satisfiability. We evaluate the performance of SymmeProof. The results show that SymmeProof substantially outperforms representative methods such as Bulletproofs in the proof size without a trusted setup. Shang Gao 0006, Zhe Peng, Yuanqing Zheng, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | ShakeReader: 'Read' UHF RFID Using SmartphoneabstractUHF RFID technology becomes increasingly popular in stores, since it can quickly read a large number of RFID tags from afar. The deployed RFID infrastructure, however, does not directly benefit smartphone users in stores, mainly because smartphones cannot read UHF RFID tags or fetch relevant information. This paper aims to bridge the gap and allow users to 'read' UHF RFID tags using their smartphones, without any hardware modification to either deployed RFID systems or smartphone hardware. To ‘read’ an interested tag, a user makes a pre-defined smartphone gesture in front of an interested tag. The smartphone gesture causes changes in 1) RFID measurement data captured by RFID infrastructure, and 2) motion sensor data captured by the user's smartphone. By matching the two data, our system (named ShakeReader) can pair the interested tag with the corresponding smartphone, thereby enabling the smartphone to indirectly 'read' the interested tag. We build a novel reflector polarization model to analyze the impact of smartphone gesture to RFID backscattered signals. We enhance the basic version of ShakeReader [6] by improving its performance in densely deployed scenarios. Experimental results show that ShakeReader can accurately pair interested tags with their corresponding smartphones with an accuracy of >96.3%. Kaiyan Cui, Yanwen Wang 0001, Yuanqing Zheng, Jinsong Han |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | CloakLoRa: A Covert Channel Over LoRa PHYabstractThis paper describes our design and implementation of a covert channel over LoRa physical layer (PHY). LoRa adopts a unique modulation scheme (chirp spread spectrum (CSS)) to enable long range communication at low-power consumption. CSS uses the initial frequencies of LoRa chirps to differentiate LoRa symbols, while simply ignoring other RF parameters (e.g., amplitude and phase). Our study reveals that the LoRa physical layer leaves sufficient room to build a covert channel by embedding covert information with a modulation scheme orthogonal to CSS. To demonstrate the feasibility of building a covert channel, we implementCloakLoRa.CloakLoRaembeds covert information into a regular LoRa packet by modulating the amplitudes of LoRa chirps while keeping the frequency intact. As amplitude modulation is orthogonal to CSS, a regular LoRa node receives the LoRa packet as if no secret information is embedded into the packet. Such an embedding method is transparent to all security mechanisms at upper layers in current LoRaWAN. As such, an attacker can create an amplitude modulated covert channel over LoRa without being detected by current LoRaWAN security mechanism. We conduct comprehensive evaluations with COTS LoRa nodes and receive-only software defined radios and experiment results show thatCloakLoRacan send covert information over 250 m. Ningning Hou, Xianjin Xia, Yuanqing Zheng |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | Don't Miss Weak Packets: Boosting LoRa Reception with Antenna DiversitiesabstractLoRa technology promises to connect billions of battery-powered devices over a long range for years. However, recent studies and industrial deployment find that LoRa suffers severe signal attenuation because of signal blockage in smart cities and long communication ranges in smart agriculture applications. As a result, weak LoRa packets cannot be correctly demodulated or even be detected in practice. To address this problem, this paper presents the design and implementation of MALoRa: a new LoRa reception scheme which aims to improve LoRa reception performance with antenna diversities. At a high level, MALoRa improves signal strength by reliably detecting and coherently combining weak signals received by multiple antennas of a gateway. MALoRa addresses a series of practical challenges, including reliable packet detection, symbol edge extraction, and phase-aligned constructive combining of weak signals. Moreover, MALoRa can also be applied to mobile devices. Experiment results show that MALoRa can effectively expand communication range, increase battery life of LoRa devices, and improve packet detection and demodulation performance especially in ultra-low SNR scenarios. Ningning Hou, Xianjin Xia, Yuanqing Zheng |
ACM Trans. Sens. Networks | 3 |
| 2023 | Jamming of LoRa PHY and CountermeasureabstractLoRaWAN forms a one-hop star topology where LoRa nodes send data via one-hop uplink transmission to a LoRa gateway. If the LoRa gateway can be jammed by attackers, it may not be able to receive any data from any nodes in the network. Our empirical study shows that although the LoRa physical layer (PHY) is robust and resilient by design, it is still vulnerable to synchronized jamming chirps. Potential protection solutions (e.g., collision recovery, parallel decoding) may fail to extract LoRa packets if an attacker transmits synchronized jamming chirps at higher power. To protect the LoRa PHY from such attacks, we propose a new protection method that can separate LoRa chirps from jamming chirps by leveraging their difference in power domain. We note that the new protection solution is orthogonal to existing solutions that leverage the chirp misalignment in the time domain or the frequency disparity in the frequency domain. We conduct experiments with COTS LoRa nodes and software-defined radios with varied experiment settings such as different spreading factors, bandwidths, and code rates. Results show that synchronized jamming chirps at high power can jam all previous solutions, whereas our protection solution can effectively protect LoRa gateways from the jamming attacks. Ningning Hou, Xianjin Xia, Yuanqing Zheng |
ACM Trans. Sens. Networks | 3 |
| 2022 | Don't Miss Weak Packets: Boosting LoRa Reception with Antenna DiversitiesabstractLoRa technology promises to connect billions of battery-powered devices over a long range for years. However, recent studies and industrial deployment find that LoRa suffers severe signal attenuation because of signal blockage in smart cities and long communication ranges in smart agriculture applications. As a result, weak LoRa packets cannot be correctly demodulated or even be detected in practice. To address this problem, this paper presents the design and implementation of MALoRa: a new LoRa reception scheme which aims to improve LoRa reception performance with antenna diversities. At a high level, MALoRa improves signal strength by reliably detecting and coherently combining weak signals received by multiple antennas of a gateway. MALoRa addresses a series of practical challenges, including reliable packet detection, symbol edge extraction, and phase-aligned constructive combining of weak signals. Experiment results show that MALoRa can effectively expand communication range, increase battery life of LoRa devices, and improve packet detection and demodulation performance especially in ultra-low SNR scenarios. Ningning Hou, Xianjin Xia, Yuanqing Zheng |
INFOCOM | 3 |
| 2022 | DeepEar: Sound Localization with Binaural MicrophonesabstractBinaural microphones, referring to two microphones with artificial human-shaped ears, are pervasively used in humanoid robots and hearing aids improving sound quality. In many applications, it is crucial for such robots to interact with humans by finding the voice direction. However, sound source localization with binaural microphones remains challenging, especially in multi-source scenarios. Prior works utilize microphone arrays to deal with the multi-source localization problem. Extra arrays yet incur higher deployment costs and take up more space. However, human brains have evolved to locate multiple sound sources with only two ears. Inspired by this fact, we propose DeepEar, a binaural microphone-based localization system that can locate multiple sounds. To this end, we develop a neural network to mimic the acoustic signal processing pipeline of the human auditory system. Different from hand-crafted features used in prior works, DeepEar can automatically extract useful features for localization. More importantly, the trained neural networks can be extended and adapted to new environments with a minimum amount of extra training data. Experiment results show that DeepEar can substantially outperform the state-of-the-art deep learning approach, with a sound detection accuracy of 93.3% and an azimuth estimation error of 7.4 degrees in multisource scenarios. Qiang Yang 0018, Yuanqing Zheng |
INFOCOM | 2 |
| 2022 | Mask does not matter: anti-spoofing face authentication using mmWave without on-site registrationabstractFace authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and hence susceptible to face occlusion (e.g., facial masks) and vulnerable to spoofing attacks (e.g., 3D-printed masks). This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans the human face by moving a commodity off-the-shelf (COTS) mmWave radar along a specific trajectory. The mmWave signals bounced off the human face carry the facial biometric features and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well even if users wear masks. We explore a distance-resistant facial structure feature to suppress the impact of unstable face-to-device distance. To avoid inconvenient on-site registration, we also propose a novel virtual registration approach based on the core idea of cross-modal transformation from photos to mmWave signals. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments show that mmFace can realize accurate FA as well as reliable liveness detection. Weiye Xu 0001, Wenfan Song, Jianwei Liu 0008, Yuanqing Zheng, Jinsong Han, Xinhuai Wang, Kui Ren 0001 |
MobiCom | 6 |
| 2022 | Integrated Sensing and Communication between Daily Devices and mmWave RadarsabstractMillimeter wave (mmWave) radar has demonstrated excellent performance in object tracking and micro-displacement detection. Besides the powerful sensing function, this work brings the communication function, allowing daily devices to communicate with mmWave radars through vibrations. In this work, we present VibBeat, in which a daily device (e.g., smartphone and smartwatch) sends messages by modulating vibrations, while a mmWave radar receives the messages by detecting and decoding the vibrations with reflected mmWave signals. By doing so, the device (user) can not only be passively sensed by a mmWave radar, but also actively send messages to the radar for a personalized response. We implement our system using a COTS mmWave radar and smartphones without any hardware modification. Experimental results show that VibBeat supports multiple object communication and achieves a communication range of up to 5m. Kaiyan Cui, Qiang Yang 0018, Leming Shen, Yuanqing Zheng, Jinsong Han |
SenSys | 4 |
| 2022 | HyLink: Towards High Throughput LPWANs with LoRa Compatible CommunicationabstractThis paper presents the design and implementation of HyLink which aims to fill the gap between limited link capacity of LoRa and the diverse bandwidth requirements of IoT systems. At the heart of HyLink is a novel technique named parallel Chirp Spread Spectrum modulation, which tunes the number of modulated symbols to adapt bit-rates according to channel conditions. Over strong link connections, HyLink fully exploits the link capability to transmit more symbols and thus transforms good channel SNRs to high link throughput. While for weak links, it conservatively modulates one symbol and concentrates all transmit power onto the symbol to combat poor channels, which can achieve the same performance as legacy LoRa. HyLink addresses a series of technical challenges on encoding and decoding of multiple payloads in a single packet, aiming at amortizing communication overheads in terms of channel access, radio-on power, transmission air-time, etc. We perform extensive experiments to evaluate the effectiveness of HyLink. Evaluations show that HyLink produces up to 10× higher bit rates than LoRa when channel SNRs are higher than 5 dB. HyLink inter-operates with legacy LoRa devices and can support new emerging traffic-intensive IoT applications. Xianjin Xia, Qianwu Chen, Ningning Hou, Yuanqing Zheng |
SenSys | 4 |
| 2022 | Ants can Carry Cheese: Secure and Private RFID-Enabled Third-Party DistributionabstractRadio Frequency Identification (RFID) is a key emerging technology to improve data sharing in item distribution systems. By attaching RFID tags to items, item related data can be bound to items and participants involved in an item distribution system can directly store, access and update the data by interrogating the tags. Such a flexible data access manner of RFID technology, however, raises privacy and security concerns. In this article, we focus on a special item distribution system named RFID-enabled Third-party Distribution (RTD) system and identify two inherent security and privacy requirements. We further design a Secure RTD system called Ants, which uses cryptography to protect item messages carried by tags to satisfy both of the requirements while preserving the flexible data access manner of RFID technology. Ants introduces two new techniques named commitment accumulation and selective message proof for memory-constrained tags to carry long crypto-item messages. We conduct theoretical analysis and experiments to demonstrate the security and efficiency of Ants. Saiyu Qi, Yuanqing Zheng, Xiaofeng Chen 0001, Wei Wei 0006 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | DE-Sword: Incentivized Verifiable Tag Path Query in RFID-Enabled Supply Chain SystemsabstractIn this article, we propose Double Edged (DE)-Sword, an incentivized verifiable tag path query scheme. DE-Sword queries tag records stored across a path of participants within an RFID-enabled supply chain in a verifiable way. Different with previous works, DE-Sword works in a dishonest-data owner model in which participants are the owners of tag records and may be dishonest. DE-Sword introduces a novel double-edged reputation incentive mechanism to encourage participants to behave honestly; and couples it with cryptographic primitives to ensure query verifiability. We evaluate DE-Sword through game theory, security analysis, and performance evaluation. The game theory and security analysis shows that DE-Sword guarantees query verifiability. The evaluation results show that DE-Sword incurs low overhead in supply chain systems. Saiyu Qi, Yuanqing Zheng, Yue Li 0060, Xiaofeng Chen 0001, Jianfeng Ma 0001, Dongyi Yang, Yong Qi 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Accelerating at the Edge: A Storage-Elastic Blockchain for Latency-Sensitive Vehicular Edge ComputingabstractThe application of blockchain to Vehicular Edge Computing (VEC) has attracted significant interests. As the Internet of Things plays an essential and fundamental role for data collecting, data analyzing, and data management in VEC, it is vital to guarantee the security of the data. However, the resource-constraint nature of edge node makes it challenging to meet the needs to maintain long life-cycle IoT data since vast volumes of IoT data quickly increase. In this paper, we propose Acce-chain, a storage-elastic blockchain based on different storage capacities at the edge. Acce-chain supports re-write operation to re-write the historical block with a newly generated block without breaking the hash links between the blocks. As a result, Acce-chain ensures that the hot data can be efficiently accessed at the edge without incurring much communication costs or increasing the total size of the chain. To guarantee the security of the re-write process, we propose a new cryptographic primitive named Dynamic Threshold Trapdoor Chameleon Hash (DTTCH). To guarantee the verifiability of query operation, we design a novel storage structure namedHybridStoreto ensure the verifiable query for on-chain/off-chain IoT data. As a result, Acce-chain achieves both authorized re-write and verifiable query simultaneously. We provide security analysis for the DTTCH scheme and the IoT data query algorithms. We evaluate Acce-chain through experiments and the results show that the performance of the re-write operation is feasible in real-world VEC settings, and the query efficiency can achieve up to several magnitudes better than which of the baseline. The results also demonstrate that Acce-chain can provide high service quality for the latency-sensitive VEC systems. Youshui Lu, Jingning Zhang, Yong Qi 0001, Saiyu Qi, Yuanqing Zheng, Yuhao Liu 0004, Hongyu Song, Wei Wei 0006 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Push the Limit of Acoustic Gesture RecognitionabstractWith the flourish of the smart devices and their applications, controlling devices using gestures has attracted increasing attention for ubiquitous sensing and interaction. Recent works use acoustic signals to track hand movement and recognize gestures. However, they suffer from low robustness due to frequency selective fading, interference and insufficient training data. In this work, we propose RobuCIR, a robust contact-free gesture recognition system that can work under different practical impact factors with high accuracy and robustness. RobuCIR adopts frequency-hopping mechanism to mitigate frequency selective fading and avoid signal interference. To further increase system robustness, we investigate a series of data augmentation techniques based on a small volume of collected data to emulate different practical impact factors. The augmented data is used to effectively train neural network models and cope with various influential factors (e.g., gesture speed, distance to transceiver,etc.). Our experiment results show that RobuCIR can recognize 15 gestures and outperform state-of-the-art works in terms of accuracy and robustness. Yanwen Wang 0001, Jiaxing Shen, Yuanqing Zheng |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | Introduction to the Special Issue on Low Power Wide Area NetworksabstractNo abstract available. Mo Li 0001, Jiliang Wang, Swarun Kumar, Yuanqing Zheng |
ACM Trans. Sens. Networks | 4 |
| 2022 | Secure and Efficient Item Traceability for Cloud-Aided IIoTabstractCloud computing is an essential technique to provide item traceability for industrial internet of things (IIoT) systems by providing item data sharing services. However, a malicious cloud server may prevent industrial participants from acquiring accurate traceability of items by providing inconsistent item data. To fix this issue, we propose Acics, an item data consistency auditing scheme in untrusted cloud services for cloud-aided IIoT systems. Acics presents two variants named S-Acics and L-Acics. S-Acics enables industrial participants to audit item data consistency for each item and circularly play the auditing role. L-Acics further enables industrial participants to audit item data consistency for a sampled subset of items while resisting data selection attack via a new separated storage mechanism. Finally, Acics integrates a fair payment mechanism built on smart contract to incentivize the cloud server to provide consistent item data access service for industrial participants. The experiment results show that our solution can audit item data consistency with reasonable cost. Saiyu Qi, Wei Wei 0006, Jingxian Cheng, Yuanqing Zheng, Zhou Su 0001, Jingning Zhang, Yong Qi 0001 |
ACM Trans. Sens. Networks | 4 |
| 2022 | PCube: Scaling LoRa Concurrent Transmissions with Reception DiversitiesabstractThis article presents the design and implementation of PCube, a phase-based parallel packet decoder for concurrent transmissions of LoRa nodes. The key enabling technology behind PCube is a novel air-channel phase measurement technique that is able to extract phase differences of air-channels between LoRa nodes and multiple antennas of a gateway. PCube leverages the reception diversities of multiple receiving antennas of a gateway and scales the concurrent transmissions of a large number of LoRa nodes, even exceeding the number of receiving antennas at a gateway. As a phase-based parallel decoder, PCube provides a new dimension to resolve collisions and supports more concurrent transmissions by complementing time and frequency-based parallel decoders. PCube is implemented and evaluated with synchronized software defined radios and off-the-shelf LoRa nodes in both indoors and outdoors. Results demonstrate that PCube can substantially outperform state-of-the-art works in terms of aggregated throughput by 4.9× and the number of concurrent nodes by up to 5×. More importantly, PCube scales well with the number of receiving antennas of a gateway, which is promising to break the barrier of concurrent transmissions. Xianjin Xia, Ningning Hou, Yuanqing Zheng, Tao Gu 0001 |
ACM Trans. Sens. Networks | 3 |
| 2021 | Collaborative Transmission over Intermediate Links in Duty-Cycle WSNs
Qianwu Chen, Xianjin Xia, Zhigang Li 0003, Yuanqing Zheng |
ICPADS | 4 |
| 2021 | ShakeReader: 'Read' UHF RFID using SmartphoneabstractUHF RFID technology becomes increasingly popular in RFID-enabled stores (e.g., UNIQLO), since UHF RFID readers can quickly read a large number of RFID tags from afar. The deployed RFID infrastructure, however, does not directly benefit smartphone users in the stores, mainly because smartphones cannot read UHF RFID tags or fetch relevant information (e.g., updated price, real-time promotion). This paper aims to bridge the gap and allow users to `read' UHF RFID tags using their smartphones, without any hardware modification to either deployed RFID systems or smartphone hardware. To `read' an interested tag, a user makes a pre-defined smartphone gesture in front of an interested tag. The smartphone gesture causes changes in 1) RFID measurement data (e.g., phase) captured by RFID infrastructure, and 2) motion sensor data (e.g., accelerometer) captured by the user's smartphone. By matching the two data, our system (named ShakeReader) can pair the interested tag with the corresponding smartphone, thereby enabling the smartphone to indirectly `read' the interested UHF tag. We build a novel reflector polarization model to analyze the impact of smartphone gesture to RFID backscattered signals. Experimental results show that ShakeReader can accurately pair interested tags with their corresponding smartphones with an accuracy of >94.6%. Kaiyan Cui, Yanwen Wang 0001, Yuanqing Zheng, Jinsong Han |
INFOCOM | 3 |
| 2021 | Jamming of LoRa PHY and CountermeasureabstractLoRaWAN forms a one-hop star topology where LoRa nodes send data via one-hop up-link transmission to a LoRa gateway. If the LoRa gateway can be jammed by attackers, the LoRa gateway may not be able to receive any data from any nodes in the network. Our empirical study shows that although LoRa physical layer (PHY) is robust and resilient by design, it is still vulnerable to synchronized jamming chirps. Potential protection solutions (e.g., collision recovery, parallel decoding) may fail to extract LoRa packets if an attacker transmits synchronized jamming chirps at high power. To protect the LoRa PHY from such attacks, we propose a new protection method that can separate LoRa chirps from jamming chirps by leveraging their difference in the received signal strength in power domain. We note that the new protection solution is orthogonal to existing solutions which leverage the chirp misalignment in time domain or the frequency disparity in frequency domain. We conduct experiments with COTS LoRa nodes and software defined radios. The results show that synchronized jamming chirps at high power can jam all previous solutions, while our protection solution can effectively protect LoRa gateways from the jamming attacks. Ningning Hou, Xianjin Xia, Yuanqing Zheng |
INFOCOM | 3 |
| 2021 | RFace: Anti-Spoofing Facial Authentication Using COTS RFIDabstractCurrent facial authentication (FA) systems are mostly based on the images of human faces, thus suffering from privacy leakage and spoofing attacks. Mainstream systems utilize facial geometry features for spoofing mitigation, which are still easy to deceive with the feature manipulation, e.g., 3D-printed human faces. In this paper, we propose a novel privacy-preserving anti-spoofing FA system, named RFace, which extracts both the 3D geometry and inner biomaterial features of faces using a COTS RFID tag array. These features are difficult to obtain and forge, hence are resistant to spoofing attacks. RFace only requires users to pose their faces in front of a tag array for a few seconds, without leaking their visual facial information. We build a theoretical model to rigorously prove the feasibility of feature acquisition and the correlation between the facial features and RF signals. For practicality, we design an effective algorithm to mitigate the impact of unstable distance and angle deflection from the face to the array. Extensive experiments with 30 participants and three types of spoofing attacks show that RFace achieves an average authentication success rate of over 95.7% and an EER of 4.4%. More importantly, no spoofing attack succeeds in deceiving RFace in the experiments. Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Feng Lin 0004, Jinsong Han, Fu Xiao 0001, Kui Ren 0001 |
INFOCOM | 4 |
| 2021 | PCube: scaling LoRa concurrent transmissions with reception diversitiesabstractThis paper presents the design and implementation of PCube, a phase-based parallel packet decoder for concurrent transmissions of LoRa nodes. The key enabling technology behind PCube is a novel air-channel phase measurement technique which is able to extract phase differences of air-channels between LoRa nodes and multiple antennas of a gateway. PCube leverages the reception diversities of multiple receiving antennas of a gateway and scales the concurrent transmissions of a large number of LoRa nodes, even exceeding the number of receiving antennas at a gateway. As a phase-based parallel decoder, PCube provides a new dimension to resolve collisions and supports more concurrent transmissions by complementing time and frequency based parallel decoders. PCube is implemented and evaluated with synchronized software defined radios and off-the-shelf LoRa nodes in both indoors and outdoors. Results demonstrate that PCube can substantially outperform state-of-the-art works in terms of aggregated throughput by 4.9× and the number of concurrent nodes by up to 5×. More importantly, PCube scales well with the number of receiving antennas of a gateway, which is promising to break the barrier of concurrent transmissions. Xianjin Xia, Ningning Hou, Yuanqing Zheng, Tao Gu 0001 |
MobiCom | 3 |
| 2021 | Toward a Low-Cost Software-Defined UHF RFID System for Distributed Parallel SensingabstractThis article presents the design and implementation of a low-cost software-defined radio-frequency identification (RFID) system for distributed parallel sensing. We aim to implement essential sensing functionalities with low-cost commodity radio components and provide full access to physical layer raw data (e.g., PHY samples of backscatter signals) to enable various RFID sensing applications at low implementation cost. The proposed solution is built in a distributed way where the functionalities of interrogating RFID tags and receiving their backscattered signals are separated into two modules, which naturally supports distributed parallel sensing. A set of innovative techniques is developed, e.g., packet-in-packet communication, carrier frequency offset (CFO) cancellation, self-interference cancellation, etc., to address a range of practical challenges, including RFID command generation with cross technology communication, real-time correction of CFO, etc. We present three case studies enabled by the proposed solution, which demonstrates its applicability and potential of boosting RFID sensing research by substantially cutting the implementation cost of software-defined RFID sensing system. Yanwen Wang 0001, Jiannong Cao 0001, Yuanqing Zheng |
IEEE Internet Things J. | 3 |
| 2021 | Crypt-DAC: Cryptographically Enforced Dynamic Access Control in the CloudabstractEnabling cryptographically enforced access controls for data hosted in untrusted cloud is attractive for many users and organizations. However, designing efficient cryptographically enforced dynamic access control system in the cloud is still challenging. In this paper, we propose Crypt-DAC, a system that provides practical cryptographic enforcement of dynamic access control. Crypt-DAC revokes access permissions by delegating the cloud to update encrypted data. In Crypt-DAC, a file is encrypted by a symmetric key list which records a file key and a sequence of revocation keys. In each revocation, a dedicated administrator uploads a new revocation key to the cloud and requests it to encrypt the file with a new layer of encryption and update the encrypted key list accordingly. Crypt-DAC proposes three key techniques to constrain the size of key list and encryption layers. As a result, Crypt-DAC enforces dynamic access control that provides efficiency, as it does not require expensive decryption/re-encryption and uploading/re-uploading of large data at the administrator side, and security, as it immediately revokes access permissions. We use formalization framework and system implementation to demonstrate the security and efficiency of our construction. Saiyu Qi, Yuanqing Zheng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Cpds: Enabling Compressed and Private Data Sharing for Industrial Internet of Things Over BlockchainabstractInternet of Things (IoT) is a promising technology to provide product traceability for industrial systems. By using sensing and networking techniques, an IoT-enabled industrial system enables its participants to efficiently track products and record their status during production process. Current industrial IoT systems lack a unified product data sharing service, which prevents the participants from acquiring trusted traceability of products. Using emerging blockchain technology to build such a service is a promising direction. However, directly storing product data on blockchain incurs in efficiency and privacy issues in data management due to its distributed infrastructure. In response, we propose Cpds, a compressed and private data sharing framework, that provides efficient and private data management for product data stored on the blockchain. Cpds devises two new mechanisms to store compressed and policy-enforced product data on the blockchain. As a result, multiple industrial participants can efficiently share product data with fine-grained access control in a distributed environment without relying on a trusted intermediary. We conduct extensive empirical studies and demonstrate the feasibility of Cpds in improving the efficiency and security protection of product data storage on the blockchain. Saiyu Qi, Youshui Lu, Yuanqing Zheng, Yumo Li, Xiaofeng Chen 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | LiteNap: Downclocking LoRa ReceptionabstractThis paper presents LiteNap which improves the energy efficiency of LoRa by enabling LoRa nodes to operate in a downclocked ‘light sleep’ mode for packet reception. A fundamental limit that prevents radio downclocking is the Nyquist sampling theorem which demands the clock-rate being at least twice the bandwidth of LoRa chirps. Our study reveals under-sampled LoRa chirps suffer frequency aliasing and cause ambiguity in symbol demodulation. LiteNap addresses the problem by leveraging an empirical observation that the hardware of LoRa radio can cause phase jitters on modulated chirps, which result in frequency leakage in the time domain. The timing information of phase jitters and frequency leakages can serve as physical fingerprints to uniquely identify modulated chirps. We propose a scheme to reliably extract the fingerprints from under-sampled chirps and resolve ambiguities in symbol demodulation. We update the reception pipeline of LoRa radio to enable reliable packet detection and decoding when operating in downclocked mode. We implement LiteNap on a software defined radio platform and conduct trace-driven evaluation to validate the proposed strategies. Experiment results show that LiteNap can downclock LoRa receiver to sub-Nyquist rates for energy savings (e.g., 1/8 of Nyquist rate), without substantially affecting packet reception performance (e.g., >95% packet reception rate). Xianjin Xia, Yuanqing Zheng, Tao Gu 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2020 | CloakLoRa: A Covert Channel over LoRa PHYabstractThis paper describes our design and implementation of a covert channel over LoRa physical layer (PHY). LoRa adopts a unique modulation scheme (chirp spread spectrum (CSS)) to enable long range communication at low-power consumption. CSS uses the initial frequencies of LoRa chirps to differentiate LoRa symbols, while simply ignoring other RF parameters (e.g., amplitude and phase). Our study reveals that the LoRa physical layer leaves sufficient room to build a covert channel by embedding covert information with a modulation scheme orthogonal to CSS. To demonstrate the feasibility of building a covert channel, we implement CloakLoRa. CloakLoRa embeds covert information into a regular LoRa packet by modulating the amplitudes of LoRa chirps while keeping the frequency intact. As amplitude modulation is orthogonal to CSS, a regular LoRa node receives the LoRa packet as if no secret information is embedded into the packet. Such an embedding method is transparent to all security mechanisms at upper layers in current LoRaWAN. As such, an attacker can create an amplitude modulated covert channel over LoRa without being detected by current LoRaWAN security mechanism. We conduct comprehensive evaluations with COTS LoRa nodes and receive-only software defined radios and experiment results show that CloakLoRa can send covert information over 250m. Ningning Hou, Yuanqing Zheng |
ICNP | 2 |
| 2020 | Push the Limit of Acoustic Gesture RecognitionabstractWith the flourish of the smart devices and their applications, controlling devices using gestures has attracted increasing attention for ubiquitous sensing and interaction. Recent works use acoustic signals to track hand movement and recognize gestures. However, they suffer from low robustness due to frequency selective fading, interference and insufficient training data. In this work, we propose RobuCIR, a robust contact-free gesture recognition system that can work under different usage scenarios with high accuracy and robustness. RobuCIR adopts frequency-hopping mechanism to mitigate frequency selective fading and avoid signal interference. To further increase system robustness, we investigate a series of data augmentation techniques based on a small volume of collected data to emulate different usage scenarios. The augmented data is used to effectively train neural network models and cope with various influential factors (e.g., gesture speed, distance to transceiver, etc.). Our experiment results show that RobuCIR can recognize 15 gestures and outperform state-of-the-art works in terms of accuracy and robustness. Yanwen Wang 0001, Jiaxing Shen, Yuanqing Zheng |
INFOCOM | 3 |
| 2020 | LiteNap: Downclocking LoRa ReceptionabstractThis paper presents LiteNap which improves the energy efficiency of LoRa by enabling LoRa nodes to operate in a downclocked `light sleep' mode for packet reception. A fundamental limit that prevents radio downclocking is the Nyquist sampling theorem which demands the clock-rate being at least twice the bandwidth of LoRa chirps. Our study reveals under-sampled LoRa chirps suffer frequency aliasing and cause ambiguity in symbol demodulation. LiteNap addresses the problem by leveraging an empirical observation that the hardware of LoRa radio can cause phase jitters on modulated chirps, which result in frequency leakage in the time domain. The timing information of phase jitters and frequency leakages can serve as physical fingerprints to uniquely identify modulated chirps. We propose a scheme to reliably extract the fingerprints from under-sampled chirps and resolve ambiguities in symbol demodulation. We implement LiteNap on a software defined radio platform and conduct trace-driven evaluation. Experiment results show that LiteNap can downclock LoRa nodes to sub-Nyquist rates for energy savings (e.g., 1/8 of Nyquist rate), without substantially affecting packet reception performance (e.g., >95% packet reception rate). Xianjin Xia, Yuanqing Zheng, Tao Gu 0001 |
INFOCOM | 2 |
| 2020 | TagBreathe: Monitor Breathing with Commodity RFID SystemsabstractBreath monitoring helps assess the general personal health and gives clues to chronic diseases. Yet, current breath monitoring technologies are inconvenient and intrusive. For instance, typical breath monitoring devices need to attach nasal probes or chest bands to users. Wireless sensing technologies have been applied to monitor breathing using radio waves without physical contact. Those wireless sensing technologies however require customized radios which are not readily available. More importantly, due to interference, such technologies do not work well with multiple users. When multiple users are present, the detection accuracy of existing systems decreases dramatically. In this paper, we propose to monitor users' breathing using commercial-off-the-shelf (COTS) RFID systems. In our system, passive lightweight RFID tags are attached to users' clothes and backscatter radio waves, and commodity RFID readers report low level data (e.g., phase values). We reliably detect the effective human respiration corresponded signal and track periodic body movement due to inhaling and exhaling by analyzing the low level data reported by commodity readers. To enhance the measurement robustness, we synthesize data streams from an array of multiple tags to improve the monitoring accuracy. Our design follows the standard EPC protocol which arbitrates collisions in the presence of multiple tags. We implement a prototype for the breath monitoring system with commodity RFID systems. The experiment results show that the prototype system can simultaneously monitor breathing with high accuracy even with the presence of multiple users. Yanwen Wang 0001, Yuanqing Zheng |
IEEE Trans. Mob. Comput. | 2 |
| 2020 | FTrack: Parallel Decoding for LoRa TransmissionsabstractLoRa has emerged as a promising Low-Power Wide Area Network (LP-WAN) technology to connect a huge number of Internet-of-Things (IoT) devices. The dense deployment and an increasing number of IoT devices lead to intense collisions due to uncoordinated transmissions. However, the current MAC/PHY design of LoRaWAN fails to recover collisions, resulting in degraded performance as the system scales. This article presents FTrack, a novel communication paradigm that enables demodulation of collided LoRa transmissions. FTrack resolves LoRa collisions at the physical layer and thereby supports parallel decoding for LoRa transmissions. We propose a novel technique to separate collided transmissions by jointly considering both the time domain and the frequency domain features. The proposed technique is motivated from two key observations: (1) the symbol edges of the same frame exhibit periodic patterns, while the symbol edges of different frames are usually misaligned in time; (2) the frequency of LoRa signal increases continuously in between the edges of symbol, yet exhibits sudden changes at the symbol edges. We detect the continuity of signal frequency to remove interference and further exploit the time-domain information of symbol edges to recover symbols of all collided frames. We substantially optimize computation-intensive tasks and meet the real-time requirements of parallel LoRa decoding. We implement FTrack on a low-cost software defined radio. Our testbed evaluations show that FTrack demodulates collided LoRa frames with low symbol error rates in diverse SNR conditions. It increases the throughput of LoRaWAN in real usage scenarios by up to 3 times. Xianjin Xia, Yuanqing Zheng, Tao Gu 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2019 | FTrack: parallel decoding for LoRa transmissionsabstractLoRa has emerged as a promising Low-Power Wide Area Network (LP-WAN) technology to connect a huge number of Internet-of-Things (IoT) devices. The dense deployment and an increasing number of IoT devices lead to intense collisions due to uncoordinated transmissions. However, the current MAC/PHY design of LoRaWAN fails to recover collisions, resulting in degraded performance as the system scales. This paper presents FTrack, a novel communication paradigm that enables demodulation of collided LoRa transmissions. FTrack resolves LoRa collisions at the physical layer and thereby supports parallel decoding for LoRa transmissions. We propose a novel technique to separate collided transmissions by jointly considering both the time domain and the frequency domain features. The proposed technique is motivated from two key observations: (1) the symbol edges of the same frame exhibit periodic patterns, while the symbol edges of different frames are usually misaligned in time; (2) the frequency of LoRa signal increases continuously in between the edges of symbol, yet exhibits sudden changes at the symbol edges. We detect the continuity of signal frequency to remove interference and further exploit the time-domain information of symbol edges to recover symbols of all collided frames. We implement FTrack on a low-cost software defined radio. Our testbed evaluations show that FTrack demodulates collided LoRa frames with low symbol error rates in diverse SNR conditions. It increases the throughput of LoRaWAN in real usage scenarios by up to 3 times. Xianjin Xia, Yuanqing Zheng, Tao Gu 0001 |
SenSys | 2 |
| 2019 | Contactless Respiration Monitoring Using Ultrasound Signal With Off-the-Shelf Audio DevicesabstractRecent years have witnessed advances of Internet of Things technologies and their applications to enable contactless sensing and elderly care in smart homes. Continuous and real-time respiration monitoring is one of the important applications to promote assistive living for elders during sleep and attracted wide attention in both academia and industry. Most of the existing respiration monitoring systems require expensive and specialized devices to sense chest displacement. However, chest displacement is not a direct indicator of breathing and thus false detection may often occur. In this paper, we design and implement a real-time and contactless respiration monitoring system by directly sensing the exhaled airflow from breathing using ultrasound signals with off-the-shelf speaker and microphone. Exhaled airflow from breathing can be regarded as air turbulence, which scatters the sound wave and results in Doppler effect. Our system works as an acoustic radar which transmits sound wave and detects the Doppler effect caused by breathing airflow. We mathematically model the relationship between the Doppler frequency change and the direction of breathing airflow. Based on this model, we design a minimum description length-based algorithm to effectively capture the Doppler effect caused by exhaled airflow. We conduct extensive experiments with 25 participants (7 elders, 2 young kids, and 16 adults, including 11 females and 14 males) in four different rooms. The participants take four different sleep postures (lying on one's back, on right/left side, and on one's stomach) in different positions of the bed. Experiment results show that our system achieves a median error lower than 0.3 breaths/min (2%) for respiration monitoring and can accurately identify Apnea. The results also demonstrate that the system is robust to different respiration styles (shallow, normal, and deep), respiration rate variation, ambient noise, sensing distance variation (within 0.7 m), and transmitted signal frequency variation. Tianben Wang, Daqing Zhang 0001, Leye Wang, Yuanqing Zheng, Tao Gu 0001, Bernadette Dorizzi, Xingshe Zhou 0001 |
IEEE Internet Things J. | 4 |
| 2019 | Enabling Out-of-Band Coordination of Wi-Fi Communications on SmartphonesabstractThis paper identifies two energy saving opportunities of Wi-Fi interface emerged during smartphone's screen-off periods. Exploiting the opportunities, we propose a new power saving strategy, BackPSM, for screen-off Wi-Fi communications. BackPSM regulates client to send and receive packets in batches and coordinates multiple clients to communicate at different slots (i.e., beacon interval). The core problem in BackPSM is how to coordinate client without incurring extra traffic overheads. To handle the problem, we propose a novel paradigm, Out-of-Band Communication (OBC), for client-to-client direct communications. OBC exploits the Traffic Indication Map (TIM) field of Wi-Fi Beacon to create a free side-channel between clients. It is based upon the observation that a client may control 1 → 0 appearing on TIM bit by locally regulating packet receiving operations. We adopt this 1 → 0 as the basic signal, and leverage the time length in between two signals to encode information. We demonstrate that OBC can be used to convey coordination information with close to 100% accuracy. We have implemented and evaluated BackPSM on a testbed. The results show that BackPSM can decode the traffic pattern of peers reliably using OBC, and establish collision-free schedules fast to achieve out-ofband coordination of client communications. BackPSM reduces screen-off energy by up to 60% and outperforms the state-ofthe-art strategies by 16%-42%. Xianjin Xia, ShiNing Li, Yu Zhang 0034, Bingqi Li, Yuanqing Zheng, Tao Gu 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2018 | PHY-Tree: Physical Layer Tree-Based RFID Identification
Yuxiao Hou, Yuanqing Zheng |
IEEE/ACM Trans. Netw. | 2 |
| 2017 | TagBreathe: Monitor Breathing with Commodity RFID SystemsabstractBreath monitoring helps assess the general personal health and gives clues to chronic diseases. Yet current breath monitoring technologies are inconvenient and intrusive. For instance, typical breath monitoring devices need to attach nasal probes or chest bands to users. Wireless sensing technologies have been applied to monitor breathing using radio waves without physical contact. Those wireless sensing technologies however require customized radios which are not readily available. More importantly, due to interference, such technologies do not work well with multiple users. With multiple users in presence, the detection accuracy of existing systems decreases dramatically. In this paper, we propose to monitor users' breathing using commercial-off-the-shelf (COTS) RFID systems. In our system, passive lightweight RFID tags are attached to users' clothes and backscatter radio waves, and commodity RFID readers report low level data (e.g., phase values). We track periodic body movement due to inhaling and exhaling by analyzing the low level data reported by commodity readers. To enhance the measurement robustness, we synthesize data streams from an array of multiple tags to improve the monitoring accuracy. Our design follows the standard EPC protocol which arbitrates collisions in the presence of multiple tags. We implement a prototype the breath monitoring system with commodity RFID systems. The experiment results show that the prototype system can simultaneously monitor breathing with high accuracy even with the presence of multiple users. Yuxiao Hou, Yanwen Wang 0001, Yuanqing Zheng |
ICDCS | 3 |
| 2017 | Double-Edged Sword: Incentivized Verifiable Product Path Query for RFID-Enabled Supply ChainabstractQuerying the path information of individual products in a supply chain is key to many applications. RFID (Radio-Frequency IDentification) is a main technology to enable product path information query today. With RFID technology, supply chain participants can efficiently track products in transit and record their production information in databases. In this paper, we investigate the following question: how can we conduct privacy-preserving product path information query with verifiability on an RFID-enabled distributedsupplychain?WeaddressthisquestionwithDouble Edged(DE)-Sword,anincentivizedverifiablequerysystem. DESword introduces a novel double-edged reputation incentive mechanism to encourage supply chain participants to behave; and couples it with cryptographic primitives and careful protocol design. We evaluate DE-Sword through security analysis and performance experiments. The security analysis shows that DE-Sword guarantees both verifiability and privacy. The experiment results show that DE-Sword achieves low overhead in RFID-enabled supply chain applications. Saiyu Qi, Yuanqing Zheng, Xiaofeng Chen 0001, Jianfeng Ma 0001, Yong Qi 0001 |
ICDCS | 2 |
| 2017 | DBF: A general framework for anomaly detection in RFID systemsabstractRFID technologies are making their way into numerous applications, including inventory management, supply chain, product tracking, transportation, logistics, etc. One important application is to automatically detect anomalies in RFID systems, such as missing tags, unknown tags, or cloned tags due to theft, management error, or targeted attacks. Existing solutions are all designed to detect a certain type of RFID anomalies, but lack a general functionality for detecting different types of anomalies. This paper attempts to propose a general framework for anomaly detection in RFID systems, thereby reducing the complexity for readers and tags to implement different anomaly-detection protocols. We introduce a new concept of differential Bloom filter (DBF), which turns physical-layer signal data into a segmented Bloom filter that encodes the IDs of abnormal tags. As a case study, we propose a protocol that builds DBF for identifying all missing tags in an efficient way. We implement a prototype for missing-tag identification using USRP and WISP tags to verify the effectiveness our protocol, and use large-scale simulations for performance evaluation. The results show that our solution can significantly improve time efficiency, when comparing with the best existing work. Min Chen 0007, Jia Liu 0008, Shigang Chen, Yuanqing Zheng |
INFOCOM | 5 |
| 2017 | PHY assisted tree-based RFID identificationabstractTree-based RFID identification adopts a binary-tree structure to collect IDs of an unknown set. Tag IDs locate at the leaf nodes and the reader queries through intermediate tree nodes and converges to these IDs using feedbacks from tag responses. Existing works cannot function well under random ID distribution as they ignore the distribution information hidden in the physical-layer signal of colliding tags. Different from them, we introduce PHY-Tree, a novel tree-based scheme that collects two types of distribution information from every encountered colliding signal. First, we detect if all colliding tags send the same bit content at each bit index by looking into inherent temporal features of the tag modulation schemes. If such resonant states are detected, either left or right branch of a certain subtree can be trimmed horizontally. Second, we estimate the number of colliding tags in a slot by computing a related metric defined over the signal's constellation map, based on which nodes in the same layers of a certain subtree can be skipped vertically. Evaluations from both experiments and simulations demonstrate that PHY-Tree outperforms state-of-the-art schemes by at least 1.79×. Yuxiao Hou, Yuanqing Zheng |
INFOCOM | 2 |
| 2017 | From Rateless to HoplessabstractThis paper presents a hopless networking paradigm. Incorporating recent techniques of rateless codes, senders break packets into rateless information streams and each single stream automatically adapts to diverse channel qualities at all potential receivers, regardless of their hop distances. The receivers are capable of accumulating rateless information pieces from different senders and jointly decoding the packet, largely improving throughput. We develop a practical protocol, called HOPE, which instantiates the hopless networking paradigm. Compared with the existing opportunistic routing protocol family, HOPE best exploits the wireless channel diversity and takes full advantage of the wireless broadcast effect. HOPE incurs minimum protocol overhead and serves general networking applications. We extensively evaluate the performance of HOPE with indoor network traces collected from USRP N210s and Intel 5300 NICs. The results show that HOPE achieves 1.7× and 1.3× goodput gain over EXOR and MIXIT, respectively. We further implement HOPE on a sensor network testbed, achieving the goodput gains over CTP. Zhenjiang Li 0001, Wan Du, Yuanqing Zheng, Mo Li 0001, Dapeng Oliver Wu |
IEEE/ACM Trans. Netw. | 3 |
| 2017 | Come and Be Served: Parallel Decoding for COTS RFID TagsabstractCurrent commodity RFID systems incur high communication overhead due to severe tag-to-tag collisions. Although some recent works have been proposed to support parallel decoding for concurrent tag transmissions, they require accurate channel measurements, tight tag synchronization, or modifications to standard RFID tag operations. In this paper, we present BiGroup, a novel RFID communication paradigm that allows the reader to decode the collision from multiple commodity-off-the-shelf (COTS) RFID tags in one communication round. In BiGroup, COTS tags can directly join ongoing communication sessions and get decoded in parallel. The collision resolution intelligence is solely put at the reader side. To this end, BiGroup examines the tag collisions at RFID physical layer from constellation domain as well as time domain, exploits the under-utilized channel capacity due to low tag transmission rate, and leverages tag diversities. We implement BiGroup with USRP N210 software radio that is able to read and decode multiple concurrent transmissions from COTS passive tags. Our experimental study gives encouraging results that BiGroup greatly improves RFID communication efficiency, i.e., 11 times performance improvement compared with the alternative decoding scheme for COTS tags. Jiajue Ou, Mo Li 0001, Yuanqing Zheng |
IEEE/ACM Trans. Netw. | 3 |
| 2017 | Travi-Navi: Self-Deployable Indoor Navigation SystemabstractWe present Travi-Navi-a vision-guided navigation system that enables a self-motivated user to easily bootstrap and deploy indoor navigation services, without comprehensive indoor localization systems or even the availability of floor maps. Travi-Navi records high-quality images during the course of a guider's walk on the navigation paths, collects a rich set of sensor readings, and packs them into a navigation trace. The followers track the navigation trace, get prompt visual instructions and image tips, and receive alerts when they deviate from the correct paths. Travi-Navi also finds shortcuts whenever possible. In this paper, we describe the key techniques to solve several practical challenges, including robust tracking, shortcut identification, and high-quality image capture while walking. We implement Travi-Navi and conduct extensive experiments. The evaluation results show that Travi-Navi can track and navigate users with timely instructions, typically within a four-step offset, and detect deviation events within nine steps. We also characterize the power consumption of Travi-Navi on various mobile phones. Yuanqing Zheng, Guobin Shen, Liqun Li, Chunshui Zhao, Mo Li 0001, Feng Zhao 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | Fair QoS multi-resource allocation for uplink traffic in WLAN
Yuxiao Hou, Yuanqing Zheng, Mo Li 0001 |
Wirel. Networks | 2 |
| 2016 | Secure and Private RFID-Enabled Third-Party Supply Chain SystemsabstractRadio Frequency Identification (RFID) is a key emerging technology for supply chain systems. By attaching RFID tags to various products, product-related data can be efficiently indexed, retrieved and shared among multiple participants involved in an RFID-enabled supply chain. The flexible data access property, however, raises security and privacy concerns. In this paper, we target at security and privacy issues in RFID-enabled supply chain systems. We investigate RFID-enabled Third-party Supply chain (RTS) systems and identify several inherent security and efficiency requirements. We further design a Secure RTS system called SRTS, which leverages RFID tags to deliver computation-lightweight crypto-IDs in the RTS system to meet both the security and efficiency requirements. SRTS introduces a Private Verifiable Signature (PVS) scheme to generate computation-lightweight crypto-IDs for product batches, and couples the primitive in RTS system through careful design. We conduct theoretical analysis and experiments to demonstrate the security and efficiency of SRTS. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Li Lu 0001, Yunhao Liu 0001 |
IEEE Trans. Computers | 2 |
| 2016 | PLACE: Physical Layer Cardinality Estimation for Large-Scale RFID SystemsabstractEstimating the number of RFID tags is a fundamental operation in RFID systems and has recently attracted wide attentions. Despite the subtleties in their designs, previous methods estimate the tag cardinality from the slot measurements, which distinguish idle and busy slots and based on that derive the cardinality following some probability models. In order to fundamentally improve the counting efficiency, in this paper we introduce PLACE, a physical layer based cardinality estimator. We show that it is possible to extract more information and infer integer states from the same slots in RFID communications. We propose a joint estimator that optimally combines multiple sub-estimators, each of which independently counts the number of tags with different inferred PHY states. Extensive experiments based on the GNURadio/USRP platform and the large-scale simulations demonstrate that PLACE achieves approximately 3 ~ 4× performance improvement over state-of-the-art cardinality estimation approaches. Yuxiao Hou, Jiajue Ou, Yuanqing Zheng, Mo Li 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2016 | Scalable Industry Data Access Control in RFID-Enabled Supply ChainabstractBy attaching RFID tags to products, supply chain participants can identify products and create product data to record the product particulars in transit. Participants along the supply chain share their product data to enable information exchange and support critical decisions in production operations. Such an information sharing essentially requires a data access control mechanism when the product data relate to sensitive business issues. However, existing access control solutions are ill-suited to the RFID-enabled supply chain, as they are not scalable in handling a huge number of tags, introduce vulnerability to the product data, and perform poorly to support privilege revocation of product data. We present a new scalable industry data access control system that addresses these limitations. Our system provides an item-level data access control mechanism that defines and enforces access policies based on both the participants' role attributes and the products' RFID tag attributes. Our system further provides an item-level privilege revocation mechanism by allowing the participants to delegate encryption updates in revocation operation without disclosing the underlying data contents. We design a new updatable encryption scheme and integrate it with ciphertext policy-attribute-based encryption to implement the key components of our system. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Yunhao Liu 0001, Jinli Qiu |
IEEE/ACM Trans. Netw. | 2 |
| 2016 | Read Bulk Data From Computational RFIDsabstractWithout the need of local energy supply, computational RFID (CRFID) sensors are emerging as important platforms enabling a variety of sensing and computing applications. Nevertheless, the data throughput of CRFIDs is very low. This paper aims at efficiently reading bulk data from CRFIDs using commodity RFID readers. We carry out thorough experiment studies to investigate the root cause of the low data throughput of CRFIDs. The experiment results suggest that the fundamental problem of data transfer stems from the mismatch between the stringent timing requirement of commodity standard and the limited packet handling capability of CRFIDs. We further propose several simple yet effective techniques to allow CRFIDs to meet stringent timing requirement of commodity RFID readers and achieve efficient data transfer. We implement a prototype system based on the WISP CRFIDs and commercial off-the-self RFID readers. We carry out extensive experiments on the prototype systems, which show that the proposed scheme works well with the commodity RFID readers. Yuanqing Zheng, Mo Li 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2015 | PLACE: Physical layer cardinality estimation for large-scale RFID systemsabstractEstimating the number of RFID tags is a fundamental operation in RFID systems and has recently attracted wide attentions. Despite the subtleties in their designs, previous methods estimate the tag cardinality from the slot measurements, which distinguish idle and busy slots and based on that derive the cardinality following some probability models. In order to fundamentally improve the counting efficiency, in this paper we introduce PLACE, a physical layer based cardinality estimator. We show that it is possible to extract more information and infer integer states from the same slots in RFID communications. We propose a joint estimator that optimally combines multiple sub-estimators, each of which independently counts the number of tags with different inferred PHY states. Extensive experiments based on the GNURadio/USRP platform and the large-scale simulations demonstrate that PLACE achieves approximately 3~4× performance improvement over state-of-the-art cardinality estimation approaches. Yuxiao Hou, Jiajue Ou, Yuanqing Zheng, Mo Li 0001 |
INFOCOM | 3 |
| 2015 | Come and Be Served: Parallel Decoding for COTS RFID TagsabstractCurrent commodity RFID systems incur high communication overhead due to severe tag-to-tag collisions. Although some recent works have been proposed to support parallel decoding for concurrent tag transmissions, they require accurate channel measurements, tight tag synchronization, or modifications to standard RFID tag operations. In this paper, we present BiGroup, a novel RFID communication paradigm that allows the reader to decode the collision from multiple COTS (commodity-off-the-shelf) RFID tags in one communication round. In BiGroup, COTS tags can directly join ongoing communication sessions and get decoded in parallel. The collision resolution intelligence is solely put at the reader side. To this end, BiGroup examines the tag collisions at RFID physical layer from constellation domain as well as time domain, exploits the under-utilized channel capacity due to low tag transmission rate, and leverages tag diversities. We implement BiGroup with USRP N210 software radio that is able to read and decode multiple concurrent transmissions from COTS passive tags. Our experimental study gives encouraging results that BiGroup greatly improves RFID communication efficiency, i.e., 11× performance improvement compared to the alternative decoding scheme for COTS tags and 6× gain in time efficiency when applied to EPC C1G2 tag identification. Jiajue Ou, Mo Li 0001, Yuanqing Zheng |
MobiCom | 3 |
| 2015 | From Rateless to HoplessabstractThis paper presents a hopless networking paradigm. Incorporating recent techniques of rateless codes, senders break packets into rateless information streams and each single stream automatically adapts to diverse channel qualities at all potential receivers, regardless of their hop distances. The receivers are capable of accumulating rateless information pieces from different senders and jointly decoding the packet, largely improving throughput. We develop a practical protocol, called HOPE, which instantiates the hopless networking paradigm. Compared with the existing opportunistic routing protocol family, HOPE best exploits the wireless channel diversity and takes full advantage of the wireless broadcast effect. HOPE incurs minimum protocol overhead and serves general networking applications. We extensively evaluate the performance of HOPE with indoor network traces collected from USRP N210s and Intel 5300 NICs. The results show that HOPE achieves 1.7x and 1.3x goodput gain over ExOR and MIXIT, respectively. Zhenjiang Li 0001, Wan Du, Yuanqing Zheng, Mo Li 0001, Dapeng Oliver Wu |
MobiHoc | 3 |
| 2015 | P-MTI: Physical-Layer Missing Tag Identification via Compressive SensingabstractRadio frequency identification (RFID) systems are emerging platforms that support a variety of pervasive applications. RFID tags can be used to label items and enable item-level monitoring. The problem of identifying missing tags in RFID systems has attracted wide attention due to its practical importance (e.g., anti-theft). This paper presents P-MTI: a Physical-layer Missing Tag Identification scheme that effectively makes use of the lower-layer information and dramatically improves operational efficiency. Unlike conventional approaches, P-MTI looks into the aggregated tag responses instead of focusing on individual tag responses and extracts useful information from physical-layer collisions. P-MTI leverages the sparsity of missing tag events and reconstructs tag responses through compressive sensing. We prototype P-MTI using the USRP software defined radio and Intel WISP platform. We also evaluate the performance of P-MTI with extensive simulations and compare to previous approaches. The experiment results show the promising performance of P-MTI in identification accuracy, time efficiency, as well as robustness over noisy channels. Yuanqing Zheng, Mo Li 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2015 | IODetector: A Generic Service for Indoor/Outdoor DetectionabstractThe location and context switching, especially the indoor/outdoor switching, provides essential and primitive information for upper-layer mobile applications. In this article, we present IODetector: a lightweight sensing service that runs on the mobile phone and detects the indoor/outdoor environment in a fast, accurate, and efficient manner. Constrained by the energy budget, IODetector primarily leverages lightweight sensing resources, such as light sensors, magnetism sensors, and cell tower signals. For universal applicability, IODetector assumes no prior knowledge (e.g., fingerprints) of the environment and uses only on-board sensors common to mainstream mobile phones. Being a generic and lightweight service component, IODetector greatly benefits many location-based and context-aware applications. We prototype the IODetector on Android mobile phones and evaluate the system comprehensively with data collected from 34 traces that include 133 different places during a 6-week period, employing different phone models. We further perform a case study where we make use of IODetector to instantly infer the GPS availability and localization accuracy in different indoor/outdoor environments. Mo Li 0001, Yuanqing Zheng, Zhenjiang Li 0001, Guobin Shen |
ACM Trans. Sens. Networks | 3 |
| 2014 | Scalable Data Access Control in RFID-Enabled Supply ChainabstractBy attaching RFID tags to products, supply chain participants can identify products and create product data to record the product particulars in transit. Participants along the supply chain share their product data to enable information exchange and support critical decisions in production operations. Such an information sharing essentially requires a data access control mechanism when the product data relates to sensitive business issues. However, existing access control solutions are ill suited to the RFID-enabled supply chain, as they are not scalable in handling a huge number of tags, introduce vulnerability to the product data, and performs poorly to support privilege revocation of product data. We present a new scalable data access control system that addresses these limitations. Our system provides an item-level data access control mechanism that defines and enforces access policies based on both the participants' role attribute and the products' RFID tag attribute. Our system further provides an item-level privilege revocation mechanism by allowing the participants to delegate encryption updates in revocation operation without disclosing the underlying data contents. We design a new updatable encryption scheme and integrate it with Cipher text Policy-Attribute Based Encryption (CP-ABE) to implement the key components of our system. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Yunhao Liu 0001, Jinli Qiu |
ICNP | 2 |
| 2014 | MISC: Merging incorrect symbols using constellation diversity for 802.11 retransmissionabstract802.11 WLANs suffer from high packet losses due to interference and noise. Packet retransmission is a fundamental way to recover a lost packet. To extract useful information from incorrect symbols and improve retransmission efficiency, we present MISC, a packet retransmission scheme that merges incorrect symbols from multiple transmissions to produce correct ones. MISC proactively creates constellation diversity by rearranging the constellation maps in retransmissions. MISC addresses practical implementation issues and makes minimum amendments to integrate into current 802.11 WLAN framework. We implement MISC in an 802.11-based GNURadio/USRP platform and conduct extensive experiments to evaluate its efficacy. Experiment results demonstrate that MISC can substantially improve the throughput. Jiajue Ou, Yuanqing Zheng, Mo Li 0001 |
INFOCOM | 2 |
| 2014 | COLLECTOR: A secure RFID-enabled batch recall protocolabstractBatch recall is a practically important problem for most industry manufacturers. The batches of products which contain flawed parts need to be recalled by manufacturers in time to prevent further economic and health loss. Accurate batch recall could be a challenging issue as flawed parts may have already been integrated into a large number of products and distributed to customers. The recent development of Radio Frequency Identification (RFID) provides us a promising opportunity to implement batch recall in an accurate and efficient way. RFID-enabled batch recall provides us the opportunity to further enhance the security of batch recall operation, allowing us to achieve recognition of problematic products, privacy preserving of production pattern, recall authentication and non-repudiation, etc. In this paper, we thoroughly study the security aspects and identify the unique requirements in RFID-enabled batch recall. We propose a practically secure protocol, COLLECTOR, to enable accurate, secure and efficient RFID batch recall. Saiyu Qi, Yuanqing Zheng, Mo Li 0001, Li Lu 0001, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2014 | Read bulk data from computational RFIDsabstractWithout the need of local energy supply, computational RFID (CRFID) sensors are emerging as important platforms enabling a variety of sensing and computing applications. Nevertheless, the data throughput of CRFIDs is very low. This paper aims at efficiently transferring bulk data from CRFIDs to commodity RFID readers. We first investigate the problem of low data throughput of CRFIDs. We then propose several simple yet effective techniques to allow CRFIDs to meet stringent timing requirement of commodity RFID readers and achieve efficient data transfer. We implement a prototype system based on the WISP CRFIDs and commercial off-the-self RFID reader. The experiment results show that our approach provides better compatibility with EPCglobal C1G2 compliant RFID devices and works perfectly with the commodity RFID readers. Yuanqing Zheng, Mo Li 0001 |
INFOCOM | 1 |
| 2014 | Fair QoS multi-resource allocation for wireless LANabstractWe consider the problem of allocating two network resources (wireless bandwidth and backhaul router buffer) to support fair QoS in WLAN. We transform the QoS requirements to multi-resource demands and apply the DRF scheme to achieve fair allocation of the two different types of resources. We define a QoS utility function which measures the user QoS satisfaction. We briefly prove the property of resource-based strategy proofness of DRF, the corresponding mathematical expression is used to prove QoS-based strategy-proofness in terms of both resource share and user QoS. Finally our simulation results confirm the properties of DRF and demonstrate that our DRF-based approach performs better than several multi-resource allocation schemes with respect to both fairness and utility. Yuxiao Hou, Mo Li 0001, Yuanqing Zheng |
IWQoS | 3 |
| 2014 | Travi-Navi: self-deployable indoor navigation systemabstractWe present Travi-Navi - a vision-guided navigation system that enables a self-motivated user to easily bootstrap and deploy indoor navigation services, without comprehensive indoor localization systems or even the availability of floor maps. Travi-Navi records high quality images during the course of a guider's walk on the navigation paths, collects a rich set of sensor readings, and packs them into a navigation trace. The followers track the navigation trace, get prompt visual instructions and image tips, and receive alerts when they deviate from the correct paths. Travi-Navi also finds the most efficient shortcuts whenever possible. We encounter and solve several challenges, including robust tracking, shortcut identification, and high quality image capture while walking. We implement Travi-Navi and conduct extensive experiments. The evaluation results show that Travi-Navi can track and navigate users with timely instructions, typically within a 4-step offset, and detect deviation events within 9 steps. Yuanqing Zheng, Guobin Shen, Liqun Li, Chunshui Zhao, Mo Li 0001, Feng Zhao 0001 |
MobiCom | 1 |
| 2014 | How Long to Wait? Predicting Bus Arrival Time With Mobile Phone Based Participatory SensingabstractThe bus arrival time is primary information to most city transport travelers. Excessively long waiting time at bus stops often discourages the travelers and makes them reluctant to take buses. In this paper, we present a bus arrival time prediction system based on bus passengers' participatory sensing. With commodity mobile phones, the bus passengers' surrounding environmental context is effectively collected and utilized to estimate the bus traveling routes and predict bus arrival time at various bus stops. The proposed system solely relies on the collaborative effort of the participating users and is independent from the bus operating companies, so it can be easily adopted to support universal bus service systems without requesting support from particular bus operating companies. Instead of referring to GPS-enabled location information, we resort to more generally available and energy efficient sensing resources, including cell tower signals, movement statuses, audio recordings, etc., which bring less burden to the participatory party and encourage their participation. We develop a prototype system with different types of Android-based mobile phones and comprehensively experiment with the NTU campus shuttle buses as well as Singapore public buses over a 7-week period. The evaluation results suggest that the proposed system achieves outstanding prediction accuracy compared with those bus operator initiated and GPS supported solutions. We further adopt our system and conduct quick trial experiments with London bus system for 4 days, which suggests the easy deployment of our system and promising system performance across cities. At the same time, the proposed solution is more generally available and energy friendly. Yuanqing Zheng, Mo Li 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2014 | Towards More Efficient Cardinality Estimation for Large-Scale RFID SystemsabstractRadio frequency identification (RFID) cardinality estimation with an accuracy guarantee is of practical importance in various large-scale RFID applications. This paper proposes a fast RFID cardinality estimation protocol, named Zero-One Estimator (ZOE). ZOE only requires 1-bit response from the RFID tags per estimation round. More importantly, ZOE rapidly converges to optimal parameter configurations and achieves higher estimation efficiency compared to existing protocols. ZOE guarantees arbitrary accuracy requirement without imposing heavy computation and memory overhead at RFID tags except the routine operations of C1G2 standard. ZOE also provides reliable cardinality estimation with unreliable channels due to the robust protocol design. We prototype ZOE using the USRP software defined radio and the Intel WISP tags. We extensively evaluate the performance of ZOE compared to existing protocols, which demonstrates encouraging results in terms of estimation accuracy, time efficiency, as well as robustness over a large range of tag population. Yuanqing Zheng, Mo Li 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2013 | ZOE: Fast cardinality estimation for large-scale RFID systemsabstractEstimating the RFID cardinality with accuracy guarantee is an important task in large-scale RFID systems. This paper proposes a fast RFID cardinality estimation scheme. The proposed Zero-One Estimator (ZOE) protocol rapidly converges to optimal parameter settings and achieves high estimation efficiency. ZOE significantly improves the cardinality estimation efficiency, achieving 3x performance gain compared with existing protocols. Meanwhile, ZOE guarantees arbitrary accuracy requirement without imposing computation and memory overhead at RFID tags. Due to the simplicity and robustness, the ZOE protocol provides reliable cardinality estimation even over noisy channel. We implement a prototype system using the USRP software defined radio and Intel WISP RFID tags. We also evaluate the performance of ZOE with extensive simulations. The evaluation of ZOE shows encouraging results in terms of estimation accuracy, time efficiency, as well as robustness. Yuanqing Zheng, Mo Li 0001 |
INFOCOM | 1 |
| 2013 | P-MTI: Physical-layer Missing Tag Identification via compressive sensingabstractRFID systems are emerging platforms that support a variety of pervasive applications. The problem of identifying missing tag in RFID systems has attracted wide attention due to its practical importance. This paper presents P-MTI: a Physical-layer Missing Tag Identification scheme which effectively makes use of the lower layer information and dramatically improves operational efficiency. Unlike conventional approaches, P-MTI looks into the aggregated responses instead of focusing on individual tag responses and extracts useful information from physical layer symbols. P-MTI leverages the sparsity of missing tag events and reconstructs tag responses through compressive sensing. We implement P-MTI and prototype the system based on the USRP software defined radio and Intel WISP platform which demonstrates the efficacy. We also evaluate the performance of P-MTI with extensive simulations and compare with previous approaches under various scenarios. The evaluation shows promising results of P-MTI in terms of identification accuracy, time efficiency, as well as robustness over noisy channels. Yuanqing Zheng, Mo Li 0001 |
INFOCOM | 1 |
| 2013 | Fast Tag Searching Protocol for Large-Scale RFID SystemsabstractFast searching a particular subset in a large number of products attached with radio frequency identification (RFID) tags is of practical importance for a variety of applications, but not yet thoroughly investigated. Since the cardinality of the products can be extremely large, collecting the tag information directly from each of those tags could be highly inefficient. To address the tag searching efficiency in large-scale RFID systems, this paper proposes several algorithms to meet the stringent delay requirement in developing fast tag searching protocols. We formally formulate the tag searching problem in large-scale RFID systems. We propose utilizing compact approximators to efficiently aggregate a large volume of RFID tag information and exchange such information with a two-phase approximation protocol. By estimating the intersection of two compact approximators, the proposed two-phase compact approximator-based tag searching protocol significantly reduces the searching time compared to all possible solutions we can directly borrow from existing studies. We further introduce a scalable cardinality range estimation method that provides inexpensive input for our tag searching protocol. We conduct comprehensive simulations to validate our design. The results demonstrate that the proposed tag searching protocol is highly efficient in terms of both time efficiency and transmission overhead, leading to good applicability and scalability for large-scale RFID systems. Yuanqing Zheng, Mo Li 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2012 | How long to wait?: predicting bus arrival time with mobile phone based participatory sensingabstractThe bus arrival time is primary information to most city transport travelers. Excessively long waiting time at bus stops often discourages the travelers and makes them reluctant to take buses. In this paper, we present a bus arrival time prediction system based on bus passengers' participatory sensing. With commodity mobile phones, the bus passengers' surrounding environmental context is effectively collected and utilized to estimate the bus traveling routes and predict bus arrival time at various bus stops. The proposed system solely relies on the collaborative effort of the participating users and is independent from the bus operating companies, so it can be easily adopted to support universal bus service systems without requesting support from particular bus operating companies. Instead of referring to GPS enabled location information, we resolve to more generally available and energy efficient sensing resources, including cell tower signals, movement statuses, audio recordings, etc., which bring less burden to the participatory party and encourage their participation. We develop a prototype system with different types of Android based mobile phones and comprehensively experiment over a 7 week period. The evaluation results suggest that the proposed system achieves outstanding prediction accuracy compared with those bus company initiated and GPS supported solutions. At the same time, the proposed solution is more generally available and energy friendly. Yuanqing Zheng, Mo Li 0001 |
MobiSys | 2 |
| 2012 | Demo: how long to wait?: predicting bus arrival time with mobile phone based participatory sensingabstractNo abstract available. Yuanqing Zheng, Mo Li 0001 |
MobiSys | 2 |
| 2012 | IODetector: a generic service for indoor outdoor detectionabstractThe location and context switching, especially the indoor/outdoor switching, provides essential and primitive information for upper layer mobile applications. In this paper, we present IODetector: a lightweight sensing service which runs on the mobile phone and detects the indoor/outdoor environment in a fast, accurate, and efficient manner. Constrained by the energy budget, IODetector leverages primarily lightweight sensing resources including light sensors, magnetism sensors, celltower signals, etc. For universal applicability, IODetector assumes no prior knowledge (e.g., fingerprints) of the environment and uses only on-board sensors common to mainstream mobile phones. Being a generic and lightweight service component, IODetector greatly benefits many location-based and context-aware applications. We prototype the IODetector on Android mobile phones and evaluate the system comprehensively with data collected from 19 traces which include 84 different places during one month period, employing different phone models. We further perform a case study where we make use of IODetector to instantly infer the GPS availability and localization accuracy in different indoor/outdoor environments. Yuanqing Zheng, Zhenjiang Li 0001, Mo Li 0001, Guobin Shen |
SenSys | 2 |
| 2012 | IODetector: a generic service for indoor outdoor detectionabstractA generic and lightweight service for indoor and outdoor detection is demonstrated that mainly uses three lightweight sensing resources, including light sensors, cell tower signals and magnetism sensors, to make ambient environment detection in a fast, accurate and efficient manner. In particular, we do not need to fingerprint the environment to acquire a priori knowledge. Thus the proposed system greatly benefits many location-based and context-ware applications. Yuanqing Zheng, Zhenjiang Li 0001, Mo Li 0001, Guobin Shen |
SenSys | 2 |
| 2012 | PET: Probabilistic Estimating Tree for Large-Scale RFID EstimationabstractEstimating the number of RFID tags in the region of interest is an important task in many RFID applications. In this paper, we propose a novel approach for efficiently estimating the approximate number of RFID tags. Compared with existing approaches, the proposed Probabilistic Estimating Tree (PET) protocol achieves {\cal O}(\log \log n) estimation efficiency, which remarkably reduces the estimation time while meeting the accuracy requirement. PET also largely reduces the computation and memory overhead at RFID tags. As a result, we are able to apply PET with passive RFID tags and provide scalable and inexpensive solutions for large-scale RFID systems. We validate the efficacy and effectiveness of PET through theoretical analysis as well as extensive simulations. Our results suggest that PET outperforms existing approaches in terms of estimation accuracy, efficiency, and overhead. Yuanqing Zheng, Mo Li 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2011 | PET: Probabilistic Estimating Tree for Large-Scale RFID EstimationabstractEstimating the number of RFID tags in the region of interest is an important task in many RFID applications. In this paper we propose a novel approach for efficiently estimating the approximate number of RFID tags. Compared with existing approaches, the proposed Probabilistic Estimating Tree (PET) protocol achieves O(loglogn) estimation efficiency, which remarkably reduces the estimation time while meeting the accuracy requirement. PET also largely reduces the computation and memory overhead at RFID tags. As a result, we are able to apply PET with passive RFID tags and provide scalable and inexpensive solutions for large-scale RFID systems. We validate the efficacy and effectiveness of PET through theoretical analysis as well as extensive simulations. Our results suggest that PET outperforms existing approaches in terms of estimation accuracy, efficiency, and overhead. Yuanqing Zheng, Mo Li 0001, Chen Qian 0001 |
ICDCS | 1 |
| 2011 | Fast tag searching protocol for large-scale RFID systemsabstractFast searching a particular subset in a large number of products attached with RFID tags is of practical importance for a variety of applications but not yet thoroughly investigated. Since the cardinality of the products can be extremely large, collecting the tag information directly from each of those tags could be highly inefficient. To address the tag searching efficiency in large-scale RFID systems, this paper proposes several algorithms to meet the stringent delay requirement in developing fast tag searching protocols. We formally formulate the tag searching problem in large-scale RFID systems. We propose utilizing compact approximators to efficiently aggregate a large volume of RFID tag information and exchange such information with a two-phase approximation protocol. By estimating the intersection of two compact approximators, the proposed two-phase compact approximator based tag searching protocol significantly reduces the searching time compared with all possible solutions we can directly borrow from existing studies. We further introduce a scalable cardinality range estimation method which provides inexpensive input for our tag searching protocol. We conduct comprehensive simulations to validate our design. The results demonstrate that the proposed tag searching protocol is highly efficient in terms of both time-efficiency and transmission overhead, leading to good applicability and scalability for large-scale RFID systems. Yuanqing Zheng, Mo Li 0001 |
ICNP | 1 |