EDBT 2026 Demo / reviewers in the wild / expert
Paul L. Yu
dblp:12/6699
· DBLP profile ↗
29ranked-venue papers
3as first author
8since 2021 · last 2024
0000-0003-1577-3914ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 4 since 2021Computer networks · 5 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 5Theory of computation · 4 · 3 since 2021Artificial intelligence and machine learning · 3Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | DNS Exfiltration Guided by Generative Adversarial NetworksabstractToday, DNS exfiltration attacks are detected by checking for anomalies present in the traffic, such as unusu-ally high transmission rates to a single domain and/or DNS query patterns that are very different from those in benign queries. While such approaches are seemingly robust, we show in this paper that our carefully designed and novel DNS exfiltration attack, Dolos, that uses a generative adversarial network (GAN), can guide the encoding of sensitive data in a manner that both evades these detectors and significantly speeds up the exfiltration rate compared to prior methods. At its core, Dolos divides the exfiltration data into smaller chunks, and projects each chunk into a representation that is very similar to benign queries. In addition, Dolosadaptively tunes its exfiltration rate to conform with benign DNS traffic from the compromised host, and introduces proper levels of spurious traffic to reduce entropy. Importantly, Dolos evades machine learning (ML) based detectors with no prior knowledge of their architectures or training sets (i.e., it is a blackbox exfiltration). We perform extensive evaluations using multiple datasets and also have a real im-plementation of DOLOS. Our evaluations show that DOLOS has a 12% detection probability even if 6 out of the 9 state-of-the-art defenses that we consider, are jointly used to detect exfiltration; if any of today's baseline exfiltration techniques try to achieve the same rate as Dolos in this setting, they are almost surely detected. If we reduce the rates of the baselines to achieve even a low albeit slightly higher detection probability than Dolos (0.15), we see that they take 25 x longer to achieve the exfiltration. With the other three defenses, we find that baselines are almost surely detected while Dolos remains relatively unaffected regardless of the rate of exfiltration. Abdulrahman Fahim, Shitong Zhu, Zhiyun Qian, Chengyu Song, Evangelos E. Papalexakis, Supriyo Chakraborty, Kevin S. Chan, Paul L. Yu, Trent Jaeger, Srikanth V. Krishnamurthy |
EuroS&P | 8 |
| 2024 | Don't Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type Checks
Yizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan, Trent Jaeger, Paul L. Yu, Srikanth V. Krishnamurthy |
USENIX Security Symposium | 6 |
| 2024 | TenGAN: adversarially generating multiplex tensor graphsabstractAbstract In this work, we explore multiplex graph (networks with different types of edges) generation with deep generative models. We discuss some of the challenges associated with multiplex graph generation that make it a more difficult problem than traditional graph generation. We propose TenGAN, the first neural network for multiplex graph generation, which greatly reduces the number of parameters required for multiplex graph generation. We also propose 3 different criteria for evaluating the quality of generated graphs: a graph-attribute-based, a classifier-based, and a tensor-based method. We evaluate its performance on 4 datasets and show that it generally performs better than other existing statistical multiplex graph generative models. We also adapt HGEN, an existing deep generative model for heterogeneous information networks, to work for multiplex graphs and show that our method generally performs better. William Shiao, Benjamin A. Miller, Kevin S. Chan, Paul L. Yu, Tina Eliassi-Rad, Evangelos E. Papalexakis |
Data Min. Knowl. Discov. | 4 |
| 2023 | Keyless Authentication for AWGN ChannelsabstractThis work establishes that the physical layer can be used to perform information-theoretic authentication in additive white Gaussian noise (AWGN) channels, as long as the adversary is not omniscient. The model considered consists of an encoder, decoder, and adversary, where the adversary knows the message given to the encoder, has a non-causal noisy observation of the encoder’s transmission and may use unlimited transmission power, while the decoder observes a noisy version of the sum of the encoder and adversary’s outputs. A method to modify a generic existing channel code to enable authentication is presented. This method relies on injecting message-dependent noise into the transmission and accepting the transmission as authentic only if the correct noise levels for the decoded message are observed. One drawback to this method is that the encoder must still transmit a low-power signal in the case where there is no message to send. It is shown that this modification costs an asymptotically negligible amount of the coding rate, while still enabling authentication as long as the adversary’s observation is not noiseless. Also notable is that this modification is not (asymptotically) a function of the statistical characterization of the adversary’s channel and no secret key is required. We believe these features will pave the way for a robust practical implementation. Using these results, the channel-authenticated capacity is calculated and shown to be equal to the non-adversarial channel capacity. As our results will show, information-theoretic authentication in AWGN channels is possible without the need for the legitimate party to have a model-based advantage over the adversary. While this modular scheme is designed for use in the given channel model, it is applicable to a wide range of settings. Eric Graves 0001, Allison Beemer, Jörg Kliewer, Oliver Kosut, Paul L. Yu |
IEEE Trans. Inf. Theory | 5 |
| 2022 | Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel
Yizhuo Zhai, Yu Hao 0006, Zheng Zhang 0058, Weiteng Chen, Guoren Li, Zhiyun Qian, Chengyu Song, Manu Sridharan, Srikanth V. Krishnamurthy, Trent Jaeger, Paul L. Yu |
NDSS | 11 |
| 2022 | Secret Key-Enabled Authenticated-Capacity Region, Part - II: Typical-AuthenticationabstractThis paper investigates the secret key-authenticated-capacity region, where information-theoretic authentication is defined by the ability of the decoder to accept and decode messages originating from a valid encoder while rejecting messages from other invalid sources. The model considered here consists of a valid encoder-decoder pairing that can communicate through a channel controlled by an adversary who is also able to eavesdrop on the encoder’s transmissions. Prior to the encoder’s transmission, the adversary decides whether or not to replace the decoder’s observation with an arbitrary one of the adversary’s choosing, with the adversary’s objective being to have the decoder accept and decode their observation to a valid message (different from that of the encoder). To combat the adversary, the encoder and decoder share a secret key. The secret key-authenticated-capacity region is defined as the region of jointly achievable message rate, authentication rate (a to be defined per symbol measure that will generally represent the likelihood that an adversary can fool the decoder), and the key-consumption rate (how many bits of secret key are needed per symbol sent). This is the second of a two-part study, with the parts differing in their measure of the authentication rate. For this second study, the probability of false authentication is considered as a function of the system state, where the system state is defined by the message being transmitted, the value of the secret key, the adversary’s channel observations, and the adversary’s (possibly stochastic) choice for the decoder’s observation. Termed the typical-authentication rate, the authentication measure considered here corresponds to an upper bound on the probability of false authentication for the majority of system states. For this measure, we derive matching inner and outer bounds for the secret key-enabled authenticated capacity region in terms of traditional information-theoretic measures. In doing so, it is shown that the typical-authentication rate and the message rate exhibit a one-to-one trade-off in the capacity region. Eric Graves 0001, Jake B. Perazzone, Paul L. Yu, Rick S. Blum |
IEEE Trans. Inf. Theory | 3 |
| 2022 | Secret Key-Enabled Authenticated-Capacity Region, Part I: Average AuthenticationabstractThis paper investigates the secret-key-authenticated-capacity region, where information-theoretic authentication is defined by the ability of the decoder to accept and decode messages originating from a valid encoder while rejecting messages from other invalid sources. The model considered here consists of a valid encoder-decoder pairing that can communicate through a channel controlled by an adversary who is also able to eavesdrop on the encoder’s transmissions. Over multiple rounds of communication, the adversary first decides whether or not to replace the decoder’s observation with an arbitrary one of the adversary’s choosing, with the goal of the adversary being to have the decoder accept and decode their observation as a valid message (different from that of the encoder). To combat the adversary, the encoder and decoder share a secret key. The secret-key-authenticated-capacity region here is then defined as the region of jointly achievable message rate, authentication rate (a to be defined per symbol measure that will generally represent the likelihood that an adversary can fool the decoder), and the key-consumption rate (how many bits of secret key are needed per symbol sent). This is the first of a two-part study, with the parts differing in their measure of the authentication rate. In this first study, the authentication rate is the exponent of blocklength-normalized exponent of the expected probability of false authentication. For this metric, we provide an inner bound which improves on those existing in the literature. This is achieved by adopting and merging different classical techniques in novel ways. Within these classical secret-key-based authentication techniques, one technique derives authentication capability from secure channel coding to send the secret key with the message, and the other technique derives its authentication capability directly from obscuring the source. Jake B. Perazzone, Eric Graves 0001, Paul L. Yu, Rick S. Blum |
IEEE Trans. Inf. Theory | 3 |
| 2021 | Artificial Noise-Aided MIMO Physical Layer Authentication With Imperfect CSIabstractFingerprint embedding at the physical layer is a highly tunable authentication framework for wireless communication that achieves information-theoretic security by hiding a traditional HMAC tag in noise. In a multiantenna scenario, artificial noise (AN) can be transmitted to obscure the tag even further. The AN strategy, however, relies on perfect knowledge of the channel state information (CSI) between the legitimate users. When the CSI is not perfectly known, the added noise leaks into the receiver's observations. In this article, we explore whether AN still improves security in the fingerprint embedding authentication framework with only imperfect CSI available at the transmitter and receiver. Specifically, we discuss and design detectors that account for AN leakage and analyze the adversary's ability to recover the key from observed transmissions. We compare the detection and security performance of the optimal perfect CSI detector with the imperfect CSI robust matched filter test and a generalized likelihood ratio test (GLRT). We find that utilizing AN can greatly improve security, but suffers from diminishing returns when the quality of CSI knowledge is poor. In fact, we find that in some cases allocating additional power to AN can begin to decrease key security. Jake B. Perazzone, Paul L. Yu, Brian M. Sadler, Rick S. Blum |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Authentication with Mildly Myopic AdversariesabstractIn unsecured communications settings, ascertaining the trustworthiness of received information, called authentication, is paramount. We consider keyless authentication over an arbitrarily-varying channel, where channel states are chosen by a malicious adversary with access to noisy versions of transmitted sequences. We have shown previously that a channel condition termed U-overwritability is a sufficient condition for zero authentication capacity over such a channel, and also that with a deterministic encoder, a sufficiently clear-eyed adversary is essentially omniscient. In this paper, we show that even if the authentication capacity with a deterministic encoder and an essentially omniscient adversary is zero, allowing a stochastic encoder can result in a positive authentication capacity. Furthermore, the authentication capacity with a stochastic encoder can be equal to the no-adversary capacity of the underlying channel in this case. We illustrate this for a binary channel model, which provides insight into the more general case. Allison Beemer, Eric Graves 0001, Jörg Kliewer, Oliver Kosut, Paul L. Yu |
ISIT | 5 |
| 2020 | UBITect: a precise and scalable method to detect use-before-initialization bugs in Linux kernelabstractUse-before-Initialization (UBI) bugs in the Linux kernel have serious security impacts, such as information leakage and privilege escalation. Developers are adopting forced initialization to cope with UBI bugs, but this approach can still lead to undefined behaviors (e.g., NULL pointer dereference). As it is hard to infer correct initialization values, we believe that the best way to mitigate UBI bugs is detection and manual patching. Precise detection of UBI bugs requires path-sensitive analysis. The detector needs to track an associated variable’s initialization status along all the possible program execution paths to its uses. However, such exhaustive analysis prevents the detection from scaling to the whole Linux kernel. This paper presents UBITect, a UBI bug finding tool which combines flow-sensitive type qualifier analysis and symbolic execution to perform precise and scalable UBI bug detection. The scalable qualifier analysis guides symbolic execution to analyze variables that are likely to cause UBI bugs. UBITect also does not require manual effort for annotations and hence, it can be directly applied to the kernel without any source code or intermediate representation (IR) change. On the Linux kernel version 4.14, UBITect reported 190 bugs, among which 78 bugs were deemed by us as true positives and 52 were confirmed by Linux maintainers. Yizhuo Zhai, Yu Hao 0006, Hang Zhang 0012, Daimeng Wang, Chengyu Song, Zhiyun Qian, Mohsen Lesani, Srikanth V. Krishnamurthy, Paul L. Yu |
ESEC/SIGSOFT FSE | 9 |
| 2019 | Principled Unearthing of TCP Side Channel VulnerabilitiesabstractRecent work has showcased the presence of subtle TCP side channels in modern operating systems, that can be exploited by off-path adversaries to launch pernicious attacks such as hijacking a connection. Unfortunately, most work to date is on the manual discovery of such side-channels, and patching them subsequently. In this work we ask "Can we develop a principled approach that can lead to the automated discovery of such hard-to-find TCP side-channels?" We identify that the crux of why such side-channels exist is the violation of the non-interference property between simultaneous TCP connections i.e., there exist cases wherein a change in state of one connection implicitly leaks some information to a different connection (controlled possibly by an attacker). To find such non-interference property violations, we argue that model-checking is a natural fit. However, because of limitations with regards to its scalability, there exist many challenges in using model checking. Specifically, these challenges relate to (a) making the TCP code base self-contained and amenable to model checking and (b) limiting the search space of model checking and yet achieving reasonable levels of code coverage. We develop a tool that we call SCENT (for Side Channel Excavation Tool) that addresses these challenges in a mostly automated way. At the heart of SCENT is an automated downscaling component that transforms the TCP code base in a consistent way to achieve both a reduction in the state space complexity encountered by the model checker and the number and types of inputs needed for verification. Our extensive evaluations show that SCENT leads to the discovery of 12 new side channel vulnerabilities in the Linux and FreeBSD kernels. In particular, a real world validation with one class of vulnerabilities shows that an off-path attacker is able to infer whether two arbitrary hosts are communicating with each other, within slightly more than 1 minute, on average. Yue Cao 0003, Zhongjie Wang 0002, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Paul L. Yu |
CCS | 6 |
| 2019 | Figment: Fine-grained Permission Management for Mobile AppsabstractToday's Android systems do not allow users to manage the permissions granted to applications (apps) in a flexible and dynamic way. Recent studies show that apps often misuse these permissions to access private information, or have trapdoors via which other malicious apps can do the same. In this paper, we develop a framework Figment, which consists of set of libraries that developers can easily use to build in fine-grained dynamic permission management capabilities. The users of their apps can readily invoke these capabilities during execution. The apps would potentially run with reduced functionalities if the user does not wish to allow certain permissions. Figment also allows either the developer or a user to specify context aware permissions, which cause different permissions to be granted to the app in different functional modes (contexts). We believe that Figment reduces the attack surface exposed to potentially malicious apps and offers a significant step in preserving user privacy. While the rudimentary version of Figment uses aspect-oriented programming and does not need rooting of the phone or changes to the Android sub-system, we also provide an optional root-level fail safe implementation that facilitates the embedding of dynamic permission management functions in old applications not built by using Figment libraries. We show that Figment offers significant benefits over the Android Marshmallow permission management system with lower runtime overheads; the main penalty is a one time higher compilation overhead. Ioannis Gasparis, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Rajiv Gupta 0001, Paul L. Yu |
INFOCOM | 6 |
| 2019 | Structured Coding for Authentication in the Presence of a Malicious AdversaryabstractAuthentication in the presence of a malicious adversary consists of either recovering the legitimate transmission or declaring that the adversary has interfered with the transmission. In this work, we present a structured coding scheme for keyless authentication over a discrete memoryless binary-input, symmetric adversarial channel. Our scheme allows for coding rates up to the non-adversarial capacity of the underlying channel, as well as bounded-complexity decoding. Allison Beemer, Oliver Kosut, Jörg Kliewer, Eric Graves 0001, Paul L. Yu |
ISIT | 5 |
| 2019 | Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics Libraries
Daimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh, Srikanth V. Krishnamurthy, Edward Colbert, Paul L. Yu |
NDSS | 7 |
| 2019 | Employing attack graphs for intrusion detectionabstractIntrusion detection systems are a commonly deployed defense that examines network traffic, host operations, or both to detect attacks. However, more attacks bypass IDS defenses each year, and with the sophistication of attacks increasing as well, we must examine new perspectives for intrusion detection. Current intrusion detection systems focus on known attacks and/or vulnerabilities, limiting their ability to identify new attacks, and lack the visibility into all system components necessary to confirm attacks accurately, particularly programs. To change the landscape of intrusion detection, we propose that future IDSs track how attacks evolve across system layers by adapting the concept of attack graphs. Attack graphs were proposed to study how multi-stage attacks could be launched by exploiting known vulnerabilities. Instead of constructing attacks reactively, we propose to apply attack graphs proactively to detect sequences of events that fulfill the requirements for vulnerability exploitation. Using this insight, we examine how to generate modular attack graphs automatically that relate adversary accessibility for each component, called its attack surface, to flaws that provide adversaries with permissions that create threats, called attack states, and exploit operations from those threats, called attack actions. We evaluate the proposed approach by applying it to two case studies: (1) attacks on file retrieval, such as TOCTTOU attacks, and (2) attacks propagated among processes, such as attacks on Shell-shock vulnerabilities. In these case studies, we demonstrate how to leverage existing tools to compute attack graphs automatically and assess the effectiveness of these tools for building complete attack graphs. While we identify some research areas, we also find several reasons why attack graphs can provide a valuable foundation for improving future intrusion detection systems. Frank Capobianco, Rahul George, Kaiming Huang, Trent Jaeger, Srikanth V. Krishnamurthy, Zhiyun Qian, Mathias Payer, Paul L. Yu |
NSPW | 8 |
| 2019 | Magnalium: Highly Reliable SDC Networks with Multiple Control Plane CompositionabstractExisting software-defined SDx architectures highly depend on a centralized control plane and hence can face substantial reliability challenges in software-defined coalition (SDC) settings, in which the centralized control plane can be weakly connected to the data plane, or even disconnected from the data plane due to high dynamicity. On the contrary, distributed control planes (e.g., OLSRv2) provide autonomy but lose flexibility and global policy guarantees. In this paper, we present Magnalium, a novel system to achieve high reliability in SDC networks by composing multiple control planes in real-time. Magnalium introduces a novel, unified composition framework that uses a distributed verification to systematically generate forwarding rules in accordance with desired policy requirements. Magnalium also introduces several supporting components to address challenges in wireless environment and resource management. We conduct data-driven simulations, showing that Magnalium benefits from both centralized and distributed control planes and even reduces downtime by 65% over the most reliable individual control plane. Akrit Mudvari, Kerim Gökarslan, Patrick Baker, Sastry Kompella, Franck Le, Kelvin Marcus, Jeremy Tucker, Yang Richard Yang, Paul L. Yu |
SMARTCOMP | 10 |
| 2019 | Jointly Compressing and Caching Data in Wireless Sensor NetworksabstractWe propose a novel policy for data compression and caching in a wireless sensor network (WSN) that provably optimizes utility and cost jointly, providing a theoretical basis to understand the compression-caching tradeoff for data analytics in a WSN. Our optimization framework provides analytical answers to how much compression should be performed at each sensors, and where the data should be cached in the network. We propose a distributed algorithm to implement the optimal policy and adapt to the changes (e.g., cache size and request processes) in the network. We evaluate our approach through extensive simulations on WSNs. Nitish Panigrahy, Jian Li 0008, Faheem Zafari, Don Towsley, Paul L. Yu |
SMARTCOMP | 5 |
| 2018 | Inner Bound for the Capacity Region of Noisy Channels with an Authentication RequirementabstractThe rate regions of many variations of the standard and wire-tap channels have been thoroughly explored. Secrecy capacity characterizes the loss of rate required to ensure that the adversary gains no information about the transmissions. Authentication does not have a standard metric, despite being an important counterpart to secrecy. While some results have taken an information-theoretic approach to the problem of authentication coding, the full rate region and accompanying trade-offs have yet to be characterized. In this paper, we provide an inner bound of achievable rates with an average authentication and reliability constraint. The bound is established by combining and analyzing two existing authentication schemes for both noisy and noiseless channels. We find that our coding scheme improves upon existing schemes. Jake B. Perazzone, Eric Graves 0001, Paul L. Yu, Rick S. Blum |
ISIT | 3 |
| 2018 | Cryptographic Side-Channel Signaling and Authentication via Fingerprint EmbeddingabstractAuthentication via fingerprint embedding at the physical layer utilizes noise in the wireless channel to attain a certain degree of information theoretic security that traditional HMAC methods cannot provide. Fingerprint embedding refers to a key-aided process of superimposing a low-power tag to the primary message waveform for the purpose of authenticating the transmission. The tag is uniquely created from the message and key and successful authentication is achieved when the correct tag is detected by the receiver. This paper generalizes a framework for embedding physical layer fingerprints to create an authenticated side-channel for minimal cost. Side-channel information is conveyed to the receiver through the transmitter's choice of tag from a secret codebook generated by the primary message and a shared secret key. In addition, a new linear coding scheme is introduced which enhances the ability to trade off the performance goals of authentication, side-channel rate, secrecy, and privacy. Jake B. Perazzone, Paul L. Yu, Brian M. Sadler, Rick S. Blum |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Jaal: Towards Network Intrusion Detection at ISP ScaleabstractWe have recently seen an increasing number of attacks that are distributed, and span an entire wide area network (WAN). Today, typically, intrusion detection systems (IDSs) are deployed at enterprise scale and cannot handle attacks that cover a WAN. Moreover, such IDSs are implemented at a single entity that expects to look at all packets to determine an intrusion. Transferring copies of raw packets to centralized engines for analysis in a WAN can significantly impact both network performance and detection accuracy. In this paper, we propose Jaal, a framework for achieving accurate network intrusion detection at scale. The key idea in Jaal is to monitor traffic and construct in-network packet summaries. The summaries are then processed centrally to detect attacks with high accuracy. The main challenges that we address are (a) creating summaries that are concise, but sufficient to draw highly accurate inferences and (b) transforming traditional IDS rules to handle summaries instead of raw packets. We implement Jaal on a large scale SDN testbed. We show that on average Jaal yields a detection accuracy of about 98%, which is the highest reported for ISP scale network intrusion detection. At the same time, the overhead associated with transferring summaries to the central inference engine is only about 35% of what is consumed if raw packets are transferred. Azeem Aqil, Karim Khalil, Ahmed Atya, Evangelos E. Papalexakis, Srikanth V. Krishnamurthy, Trent Jaeger, K. K. Ramakrishnan, Paul L. Yu, Ananthram Swami |
CoNEXT | 8 |
| 2017 | Defining and Detecting Environment Discrimination in Android Apps
Yunfeng Hong, Yongjian Hu, Chun-Ming Lai, Shyhtsun Felix Wu, Iulian Neamtiu, Patrick D. McDaniel, Paul L. Yu, Hasan Çam, Gail-Joon Ahn |
SecureComm | 7 |
| 2016 | Optimal Monitor Placement for Detection of Persistent ThreatsabstractWe study optimal monitor placement for intrusion detection in networks with persistent attackers. The problem is modeled as a stochastic game in which the attacker attempts to control targets by delivering malicious packets while the defender tries to detect such attempts. The state of the game is determined by the target end-systems in the network, each of which can be in either a healthy or a compromised state. Compromised targets are controlled by the attacker and may be used to inject malicious packets into the network to attack healthy targets. In addition, a random re-imaging process is deployed on all targets to regain control of compromised targets. We find the game value and the equilibrium strategies for both players under different assumptions on the knowledge of the state at the defender. Karim Khalil, Zhiyun Qian, Paul L. Yu, Srikanth V. Krishnamurthy, Ananthram Swami |
GLOBECOM | 3 |
| 2016 | Keyless authentication in the presence of a simultaneously transmitting adversaryabstractIf Alice must communicate with Bob over a channel shared with the adversarial Eve, then Bob must be able to validate the authenticity of the message. In particular we consider the model where Alice and Eve share a discrete memoryless multiple access channel with Bob, thus allowing simultaneous transmissions from Alice and Eve. By traditional random coding arguments, we demonstrate an inner bound on the rate at which Alice may transmit, while still granting Bob the ability to authenticate. Furthermore this is accomplished in spite of Alice and Bob lacking a pre-shared key, as well as allowing Eve prior knowledge of both the codebook Alice and Bob share and the messages Alice transmits. Eric Graves 0001, Paul L. Yu, Predrag Spasojevic |
ITW | 2 |
| 2015 | Fisher Information-based Experiment Design for Network TomographyabstractNetwork tomography aims to infer the individual performance of networked elements (e.g., links) using aggregate measurements on end-to-end paths. Previous work on network tomography focuses primarily on developing estimators using the given measurements, while the design of measurements is often neglected. We fill this gap by proposing a framework to design probing experiments with focus on probe allocation, and applying it to two concrete problems: packet loss tomography and packet delay variation (PDV) tomography. Based on the Fisher Information Matrix (FIM), we design the distribution of probes across paths to maximize the best accuracy of unbiased estimators, asymptotically achievable by the maximum likelihood estimator. We consider two widely-adopted objective functions: determinant of the inverse FIM (D-optimality) and trace of the inverse FIM (A-optimality). We also extend the A-optimal criterion to incorporate heterogeneity in link weights. Under certain conditions on the FIM, satisfied by both loss and PDV tomography, we derive explicit expressions for both objective functions. When the number of probing paths equals the number of links, these lead to closed-form solutions for the optimal design; when there are more paths, we develop a heuristic to select a subset of paths and optimally allocate probes within the subset. Observing the dependency of the optimal design on unknown parameters, we further propose an algorithm that iteratively updates the design based on parameter estimates, which converges to the design based on true parameters as the number of probes increases. Using packet-level simulations on real datasets, we verify that the proposed design effectively reduces estimation error compared with the common approach of uniformly distributing probes. Ting He 0001, Ananthram Swami, Don Towsley, Theodoros Salonidis, Andrei Iu. Bejan, Paul L. Yu |
SIGMETRICS | 7 |
| 2015 | Measurement and characterization of the short-range low-VHF channelabstractThe lower VHF band shows potential for reliable communications in low power, short range scenarios among near-ground nodes in both indoor and urban environments. Such scenarios are of great interest, for example, in military and search-and-rescue settings. Most prior work at low VHF focuses on modeling path loss at long range. In this paper, we study indoor/outdoor near-ground scenarios through experiments focusing on both line-of-sight (LoS) and non-LoS (NLoS), at ranges up to 200 meters. By transmitting tones and pulses from various locations in a realistic environment, we acquire channel data via a mobile data collection platform which gathers data at hundreds of different locations. We show that the measured channels have a nearly ideal scalar attenuation and delay transfer function, with minimal phase distortion, and little evidence of multipath propagation. We further confirm the absence of small scale fading by measuring bit error rate (BER) versus received signal-to-noise ratio (SNR) for QPSK transmission in an indoor setting. Using only timing and carrier estimation at the receiver, the resulting BER curves coincide with theoretical additive white Gaussian noise channel BER predictions. Fikadu T. Dagefu, Gunjan Verma, Chirag Rao, Paul L. Yu, Brian M. Sadler, Kamal Sarabandi |
WCNC | 4 |
| 2012 | RSS gradient-assisted frontier exploration and radio source localizationabstractWe consider the combined problem of frontier exploration in a complex indoor environment while seeking a radio source. To do this in an efficient manner, we incorporate radio signal strength (RSS) information into the exploration algorithm by locally sampling the RSS and estimating the 2-D RSS gradient. The algorithm exploits the local motion to collect RSS samples for gradient estimation and seeks to explore in a way that brings the robot to the signal source. This strategy avoids random or exhaustive exploration. An indoor experiment demonstrates the exploration algorithm that uses this information to dynamically prioritize candidate frontiers and traverse to a radio source. Simulations, including radio propagation modeling with a ray-tracing algorithm, enable study of control algorithm tradeoffs and statistical performance. Jeffrey N. Twigg, Jonathan Fink, Paul L. Yu, Brian M. Sadler |
ICRA | 3 |
| 2011 | MIMO Authentication via Deliberate Fingerprinting at the Physical LayerabstractWe consider authentication of a wireless multiple-input-multiple-output (MIMO) system by deliberately introducing a stealthy fingerprint at the physical layer. The fingerprint is superimposed onto the data and uniquely conveys an authentication message as a function of the transmitted data and a shared secret key. A symbol synchronous approach to fingerprint embedding provides low complexity operation. In comparison with a conventional tag-based authentication approach, fingerprinting conveys much less information on the secret key to an eavesdropper. We study the trade-offs between stealth, security, and robustness, and show that very good operating points exist. We consider the cases when deterministic or statistical channel state information is available to the transmitter, and show how precoding and channel mode power allocation can be applied to both the data and the fingerprint in combination to enhance the authentication process. Paul L. Yu, Brian M. Sadler |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2008 | Multicarrier authentication at the physical layerabstractAuthentication is the process where claims of identity are verified. Though authentication mechanisms typically exist above the physical layer, physical layer methods have recently been introduced that do not require extra bandwidth. In this paper we propose a multi-carrier extension to the work and consider the stealth and robustness tradeoffs. We conclude by discussing the power-reliability tradeoff and the applicability to cross-layer security. Paul L. Yu, John S. Baras, Brian M. Sadler |
WOWMOM | 1 |
| 2008 | Physical-Layer AuthenticationabstractAuthentication is the process where claims of identity are verified. Most mechanisms of authentication (e.g., digital signatures and certificates) exist above the physical layer, though some (e.g., spread-spectrum communications) exist at the physical layer often with an additional cost in bandwidth. This paper introduces a general analysis and design framework for authentication at the physical layer where the authentication information is transmitted concurrently with the data. By superimposing a carefully designed secret modulation on the waveforms, authentication is added to the signal without requiring additional bandwidth, as do spread-spectrum methods. The authentication is designed to be stealthy to the uninformed user, robust to interference, and secure for identity verification. The tradeoffs between these three goals are identified and analyzed in block fading channels. The use of the authentication for channel estimation is also considered, and an improved bit-error rate is demonstrated for time-varying channels. Finally, simulation results are given that demonstrate the potential application of this authentication technique. Paul L. Yu, John S. Baras, Brian M. Sadler |
IEEE Trans. Inf. Forensics Secur. | 1 |