EDBT 2026 Demo / reviewers in the wild / expert
Man Zhou 0004
dblp:165/8236-4
· DBLP profile ↗
28ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0002-1602-7369ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 6 first-author · 8 since 2021Security and privacy · 11 · 4 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GaitDG: A Single-Source Domain Generalization Framework for Cross-Domain Gait RecognitionabstractIn recent years, significant advances in gait recognition have been seen, with many methods reporting high accuracy on certain datasets. However, domain shifts, such as distribution inconsistencies in viewpoint or clothing, can severely degrade the performance of these models on unseen target domains, hindering the widespread application of gait recognition. Some unsupervised domain adaptation (UDA) methods have been proposed to address this problem. However, these approaches require continual updates with target domain data, which is often difficult to obtain due to privacy concerns and deployment complexity. This paper presents GaitDG, a single-source domain generalization framework designed to enhance the generalization ability of gait recognition models for unseen target domains, requiring training on only one source domain without accessing target domain data. During training, GaitDG employs adversarial training to disentangle domain-specific and identity-specific features, enabling the discovery of latent sub-domains and the extraction of domain-invariant features. Furthermore, GaitDG supports the integration of data augmentation to diversify the source domain data. We also introduce a data augmentation method, Segmentation Model Transfer (SMT), to mitigate recognition performance degradation caused by variations in segmentation models. As a model-agnostic approach, GaitDG can directly enhance the cross-domain recognition performance of gait recognition models without altering their structure. Comprehensive experiments on widely used gait datasets demonstrate that GaitDG significantly improves the cross-domain recognition performance of several state-of-the-art gait recognition models. Guancheng Lin, Man Zhou 0004, Lianmiao Wang, Qin Liu 0003, Yueyue Dai, Fue Zeng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Stealing Your Fingerprint via the Finger Friction SoundabstractFingerprint authentication is widely adopted in modern identity verification systems due to its efficiency and cost-effectiveness. However, its extensive use poses significant risks, as fingerprint leakage could lead to sensitive information theft, severe financial and personnel losses, and even threats to national security. MasterPrint, which can accidentally match a significant proportion of fingerprint populations, underscores the vulnerabilities in fingerprint authentication systems. This paper introduces PrintListener++, a novel side-channel attack targeting Automatic Fingerprint Identification Systems (AFIS). PrintListener++ extracts first-level fingerprint pattern features from users’ fingertip-swiping actions on the touchscreens and synthesizes stronger targeted MasterPrints by integrating potential second-level features. Based on the generated MasterPrint templates, PrintListener++ reconstructs realistic fingerprint images, further expanding its potential threat. This attack method is highly covert and versatile, requiring only fingertip friction sound recordings, which can be easily obtained through social media platforms. Extensive real-world experiments demonstrate that PrintListener++ significantly enhances the attack potency of MasterPrint, raising critical security concerns for fingerprint authentication systems. Man Zhou 0004, Lianmiao Wang, Yangguang Sun, Shuao Su, Xiaojing Ma 0002, Qi Li 0002, Qian Wang 0002 |
IEEE Trans. Netw. | 1 |
| 2025 | Enhancing Data-Free Substitute Training for Black-Box Adversarial AttacksabstractSubstitute training for black-box attacks, leveraging query synthesis, has recently gained significant attention, especially in data-free scenarios. Existing works focus on extracting the victim model without exploring the deployment of adversarial attacks, leading to inefficiencies and redundant queries. To address these issues, we present a novel data-free substitute training attack framework that focuses on aligning the ’chain of attack’ rather than the decision boundary of models. Specifically, we propose a Temporal Contrastive Sampling module to capture essential discriminative features. A Simplified Adversarial Training module is further introduced to restrict the routes crossing the decision boundary. For catastrophic forgetting and data imbalance considerations, we integrate a Substitute Model Resetting module strategy. Comprehensive experiments over three datasets demonstrate our effectiveness: under decision-based settings, we can achieve targeted attack success rates of 81.87% and 91.89% on the CIFAR-10 dataset with query budgets of 500k and 1M, surpassing state-of-the-art methods under score-based settings. Zijian Ling, Wenyu Zhou, Man Zhou 0004 |
ICME | 5 |
| 2025 | CaphandAuth: Robust and Anti-spoofing Hand Authentication via COTS Capacitive TouchscreensabstractUtilizing unique physiological or behavioral traits, biometrics offers an intuitive authentication approach. However, common biometric modalities are susceptible to ambient factors and privacy concerns. This paper proposes CaphandAuth, a novel capacitive touchscreen-based hand authentication system. Using intrinsic capacitive imaging within the touchscreen, it provides a new secure, cost-effective, and user-friendly biometric authentication solution that is inherently resilient to environmental factors. To this end, CaphandAuth captures consecutive capacitive frames as the hand moves across the touchscreen. These frames are processed with an innovative super-resolution algorithm tailored for deformable objects to enhance details. A learning-based feature extractor then derives expressive and adaptive feature representations from the enhanced images. Extensive experiments demonstrate that CaphandAuth achieves an authentication accuracy of 99.84% and an equal error rate (EER) of 2.77% on a commercial tablet. Moreover, Caphand-Auth exhibits formidable resilience to diverse deceiving attempts, including handprint simulation attacks, counterfeit spoofing attacks, and puppet attacks, making it a robust and secure solution in real-world scenarios. Man Zhou 0004, Xiaoxiao Qiao, Zijian Ling, Qin Liu 0003, Xiaojing Ma 0002, Zhengxiong Li |
SenSys | 2 |
| 2025 | NUSGuard: Smart Device Anti-Eavesdropping Protection Based on Near-Ultrasonic InterferenceabstractVoice assistants (VAs) have become ubiquitous in smart devices, and are highly valued for their ability to perform a variety of tasks through voice interaction, offering users hands-free convenience. However, the always-on microphones of VAs have raised significant privacy concerns in recent years. In this paper, we propose and implement NUSGuard, a novel and practical anti-eavesdropping system. To our knowledge, it is the first system to utilize the built-in speakers of commercial off-the-shelf (COTS) devices for anti-eavesdropping, thereby eliminating the need for dedicated ultrasonic transmitters. Specifically, it exploits human ears’ insensitivity to near-ultrasonic signals and the inherent non-linearity of mic to inject jamming noises into the microphones of unauthorized smart devices. Furthermore, we propose a robust mixed-noise scheme and a lexical-level automatic jammer control strategy, effectively disrupting unauthorized recordings while maintaining seamless voice interaction with authorized VA devices. Extensive digital and real-world experiments have demonstrated NUSGuard’s superior performance in terms of jamming effectiveness and security. Xiaoxiao Qiao, Man Zhou 0004, Hongwei Li 0001, Zhihao Yao 0001, Xiaojing Ma 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | PrintListener: Uncovering the Vulnerability of Fingerprint Authentication via the Finger Friction Sound
Man Zhou 0004, Shuao Su, Qian Wang 0002, Qi Li 0002, Xiaojing Ma 0002, Zhengxiong Li |
NDSS | 1 |
| 2024 | LV-auth: Lip Motion Fusion for Voiceprint Authentication
Wei Liu 0300, Qin Liu 0003, Peng Li 0046, Man Zhou 0004 |
WASA (1) | 5 |
| 2024 | Stealthy and Effective Physical Adversarial Attacks in Autonomous DrivingabstractIn autonomous assistance systems, accurate camera vision is indispensable for driving safety. Featuring this safety-critical scenario, physical adversarial examples are arguably the most threatening. However, existing physical adversarial attacks are either conspicuous or ineffective, leaving a dilemma for balancing between attack effectiveness and stealthiness. In this paper, we put forth a new type of adversarial patch attack, leveraging the behavior characteristic of high-speed shutters in autonomous driving cameras. Instead of deploying static images onto real-world objects, we embed adversarial examples into videos and cast them with projectors. By delicately deciding the frame contents and display frequencies, the adversarial frame contents are almost invisible to humans, but high-speed shutters can capture them (see our demos (https://anonymous.4open.science/r/7003)). We demonstrate the attack feasibility by fooling traffic sign detectors, altering speed limit signs to be mis-detected or undetected, and hence manipulating the driving speed of victims. We conduct extensive experiments under various conditions, confirming that our new attack is effective and robust: It can deceive state-of-the-art detector models with success rates of 99% and over 90% in untargeted and targeted manners, respectively. Our further investigations unravel the transferability of our attack to other detectors in a black-box setting. Man Zhou 0004, Wenyu Zhou, Junhui Yang, Minxin Du, Qi Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Securing Face Liveness Detection on Mobile Devices Using Unforgeable Lip Motion PatternsabstractFace authentication usually utilizes deep learning models to verify users with high accuracy. However, it is vulnerable to various attacks that cheat the models by manipulating the digital counterparts of human faces. So far, lots of liveness detection schemes have been developed to prevent such attacks. Unfortunately, the attacker can still bypass them by constructing sophisticated attacks. We study the security of existing face authentication services and typical liveness detection approaches. Particularly, we develop a new type of attack, i.e., the low-cost 3D projection attack that projects manipulated face videos on a 3D face model, which can easily evade these face authentication services and liveness detection approaches. To this end, we propose FaceLip, a novel face liveness detection scheme on mobile devices, which utilizes lip motion patterns built upon well-designed acoustic signals to enable a strong security guarantee. The unique lip motions for each user are unforgeable because FaceLip verifies the patterns by analyzing acoustic signals that are dynamically generated according to random challenges, which ensures that our signals for liveness detection cannot be manipulated. We prototype FaceLip on off-the-shelf smartphones and conduct extensive experiments under different settings. Our evaluation with 44 participants validates the effectiveness and robustness of FaceLip. Man Zhou 0004, Qian Wang 0002, Qi Li 0002, Wenyu Zhou, Jingxiao Yang, Chao Shen 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | FingerPattern: Securing Pattern Lock via Fingerprint-Dependent Friction SoundabstractPattern lock is widely used for user authentication in mobile devices due to its simplicity and ease of remembering. However, it is vulnerable to various attacks,e.g., shoulder surfing attacks. In this paper, we propose FingerPattern, a novel enhanced pattern lock authentication system by using friction sound as a second authentication factor. When the user inputs the pattern by swiping his/her fingertip on the screen, the friction sound is generated based on the user's fingerprint and is unique. Thus, FingerPattern can identify and rule out the illegality by utilizing fingerprint-dependent friction sound even if the adversary has inferred the pattern. By this method, FingerPattern secures pattern lock without the need for a change in user unlocking habits. Extensive experiments demonstrate that FingerPattern can identify legitimate users with 97.5% TAR in one attempt and defend against various attacks (e.g., only 16.8% FAR in five attempts even if the adversary can clearly spy on the user's unlocking process). FingerPattern can be incorporated into the existing pattern lock of mobile devices, which is cost-free. Furthermore, a user experience study shows that FingerPattern is well-received by users. Man Zhou 0004, Shuao Su, Qian Wang 0002, Qi Li 0002, Shengshan Hu, Chunwu Yu, Zhengxiong Li |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Smart Card Auto-Selection Using GPS and WiFi Fingerprints for SmartphonesabstractSmartphones equipped with NFC are increasingly emerging as favored alternatives to traditional physical smart cards. The E-wallet App on the phone mimics and stores digital credentials such as payment cards, transit cards, and door access cards. Thus it eliminates the need to carry multiple physical cards. However, users must scroll the screen and select the correct smart card manually before they tap the smartphone to the NFC terminal. It is not easy to correctly predict the smart card to be used because a user may swipe different cards in a short time, where a typical scenario is to tap an autogate at the entry of a building and open the NFC locks on the doors of the different office rooms inside the building. The key problem is to identify the NFC terminal to be tapped accurately and efficiently regardless of location. This motivates the need for a new approach to smart card selection. This paper proposes a method to identify the specific NFC terminal when the smartphone gets close to it and decide the most appropriate smart card automatically. It collects the GPS and WiFi fingerprints and stores them in the smartphone for a smart card when the phone is first bound to a terminal offline. During the online phase, the best-matched card is selected for tapping. Extensive tests are carried out on five mainstream Android smartphones in various indoor and outdoor environments to demonstrate the good performance of our proposed method. Xingying Wang, Linwen Zhang, Hang Tu, Qin Liu 0003, Man Zhou 0004 |
MSN | 5 |
| 2023 | SonarGuard: Ultrasonic Face Liveness Detection on Mobile DevicesabstractLiveness detection has been widely applied in face authentication systems to combat malicious attacks. However, existing methods purely depending on visual frames become vulnerable once visual perception is not reliable. The emerging face spoof and forge techniques urge the systems to exploit the defensive potential of non-visual modalities. To tackle this challenge, we introduce SonarGuard, a system combining ultrasonic and visual information to achieve robust liveness detection on mobile devices. More specifically, SonarGuard simultaneously extracts micro-doppler signatures from ultrasound reflections and motion trajectories from video frames both corresponding to the user’s lip movement. To further confirm the collected ultrasonic and visual information is not derived from malicious audio/video attacks, we consolidate the system via introducing a cross-modal matching mechanism, which demands the inherent consistency between these two modalities. Extensive experiments on a new dataset collected with existing mobile devices demonstrate that the proposed system could achieve average classification error rate of 0.91% under presentation attacks. This result indicates that SonarGuard can boost the security of face authenfication systems in real world usage without additional hardware modification. Dongheng Zhang, Jia Meng 0006, Jian Zhang 0079, Xinzhe Deng, Shouhong Ding, Man Zhou 0004, Qian Wang 0002, Qi Li 0002, Yan Chen 0007 |
IEEE Trans. Circuits Syst. Video Technol. | 6 |
| 2023 | Securing Liveness Detection for Voice Authentication via Pop NoisesabstractVoice authentication has been increasingly adopted for sensitive operations on mobile devices. While voice biometrics can distinguish individuals by their spectral features (such as voiceprints), they are known to be prone to spoofing attacks, where malicious attackers can use pre-recorded or synthesized samples from legitimate users or impersonate the speaking style of the targeted user to deceive the voice authentication system. In this paper, we design and implement a novel software-only anti-spoofing system on smartphones. Our system leverages thepop noise, which is generated by the user’s oral airflow when speaking the passphrase close to the microphone. The pop noise is delicate and subject to user diversity, making it hard to be recorded by replay attacks beyond a certain distance or to be imitated precisely by impersonators. Specifically, we design a new pop noise detection scheme to pinpoint pop noises at the phonemic level, based on which we establish a theoretical model to calculate the sound pressure level from the speech signal in order to get the estimated pressure signal, and then analyze the consistency with the actual pressure signal extracted from the pop noise. Furthermore, we calculate the similarity score of the unique sequences which describe the individually unique relationship between pop noises and phonemes to resist spoofing attacks. Our evaluation on a dataset of 30 participants and three smartphones shows that our system achieves over 94.79% accuracy. Our system requires no additional hardware and is robust to various factors including authentication angle, authentication distance, the length of passphrase, ambient noise, etc. Peipei Jiang 0002, Qian Wang 0002, Xiu Lin, Man Zhou 0004, Wenbing Ding, Cong Wang 0001, Chao Shen 0001, Qi Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | SoundID: Securing Mobile Two-Factor Authentication via Acoustic SignalsabstractMobile two-factor authentication (TFA), which uses mobile devices as a second security layer of protection to online accounts, has been widely applied with the proliferation of mobile phones. Currently, many studies propose to use acoustic fingerprints as the second factor. However, these solutions ignore the variations of the extracted static acoustic fingerprints incurred by the acoustic propagation process, which we show can be leveraged to develop an enhanced man-in-the-middle (MITM) attack to compromise the security strength of these systems, while hiding the traces of the attacking devices. To address this newly-uncovered vulnerability, we propose SoundID, a secure and novel authentication system that introduces a dual challenge-response design through the acoustic signals of the enrolled phone and the login device. Specifically, the enrolled phone first evaluates its proximity to the login device by the similarity of their audio recordings, and then the login authentication server compares the calculated dynamic acoustic fingerprint with the one received from the enrolled phone. To the best of our knowledge, SoundID is the first scheme that extracts dynamic acoustic fingerprints and can effectively defend against the enhanced MITM attack. SoundID combines the benefits of unpredictable influencing factors of acoustic propagation processes and the stable frequency response of the acoustic hardware, whose high complexity prevents attackers from predicting or impersonating them. We build a prototype of SoundID with off-the-shelf smartphones to validate its robustness and effectiveness. Our results show that SoundID is user-friendly and achieves over 96.62% accuracy with an equal error rate around 4.27%. Qian Wang 0002, Man Zhou 0004, Peipei Jiang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | PressPIN: Enabling Secure PIN Authentication on Mobile Devices via Structure-Borne SoundsabstractPIN authentication is widely used on mobile devices due to its usability and simplicity. However, it is known to be susceptible to shoulder surfing attacks, where an adversary spies the user’s PIN by direct human observation or camera-based recording. This paper proposes PressPIN, a novel enhanced PIN authenticator on mobile devices by sensing pressures from the user’s finger. Since pressure-sensitive touch screens are unavailable on most phones, we leverage the structure-borne propagation of sounds to estimate the pressure on the screen. When the user inputs the PINs, the pressure is extracted from each number to form the$n$-bit pressure code, where$n$corresponds to the length of the PIN sequence. The pressure code is difficult to be inferred by snooping or videotaping, and increases the entropy of passwords. In this way, PressPIN provides a low-cost, user-friendly, and more secure solution resistant to shoulder surfing attacks. Our extensive experiments with 30 participants and three types of smartphones demonstrate that PressPIN can authenticate legitimate users with high accuracy (e.g., as high as 96.7% within two trials), and is robust to various types of attacks (e.g., only 2.5% attack success rate even when the adversary can observe the legitimate user’s PIN sequence and finger pressing clearly). Additionally, PressPIN requires no additional hardware (e.g., the pressure sensor) and can be readily integrated into existing authentication systems of mobile devices. Man Zhou 0004, Qian Wang 0002, Xiu Lin, Yi Zhao 0011, Peipei Jiang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Where Are the Dots: Hardening Face Authentication on Smartphones With Unforgeable Eye Movement PatternsabstractWith the ubiquitous adoption, mobile face authentication systems have been facing constant security challenges, particularly the spoofing risks. Except for those using specialized hardware, existing proposals for face anti-spoofing on mainstream smartphones either leverage people’s 3D face characteristics or various facial expressions. While showing progress towards more resilient face authentication, they are still vulnerable to recent advanced attacks (e.g., 3D mask attacks, video attacks, etc.). This paper presents GazeGuard, an on-device face anti-spoofing system that leverages unpredictable and unforgeable eye movement patterns to provide strong security guarantees against all known attacks. Targeting mainstream smartphones, GazeGuard is designed to conduct eye movement-based authentication using only 2D front cameras. Specifically, by presenting a series of short-lasting random dots on the screen (named gazecode), GazeGuard simultaneously captures a user’s gaze responses and the corresponding deformed periocular features to ensure both the freshness and correctness for the anti-spoofing face authentication. We have extensively tested GazeGuard’s performance over 50 volunteers. Using a 4-digit gazecode (just four random dots), GazeGuard achieves an average 90.39% authentication accuracy and 81.57 out of 100 System Usability Scale (SUS) scores. Under the same settings, GazeGuard achieves detection accuracy of 95.72% for image attack, 95.59% for video attack, 99.73% for 3D mask attack, and 100% for physical adversarial attack. Qian Wang 0002, Cong Wang 0001, Man Zhou 0004, Yi Zhao 0011, Qi Li 0002, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Shielding Federated Learning: Mitigating Byzantine Attacks with Less ConstraintsabstractFederated learning is a newly emerging distributed learning framework that facilitates the collaborative training of a shared global model among distributed participants with their privacy preserved. However, federated learning systems are vulnerable to Byzantine attacks from malicious participants, who can upload carefully crafted local model updates to degrade the quality of the global model and even leave a backdoor. While this problem has received significant attention recently, current defensive schemes heavily rely on various assumptions, such as a fixed Byzantine model, availability of participants' local data, minority attackers, IID data distribution, etc. To relax those constraints, this paper presents Robust-FL, the first prediction-based Byzantine-robust federated learning scheme where none of the assumptions is leveraged. The core idea of the Robust-FL is exploiting historical global model to construct an estimator based on which the local models will be filtered through similarity detection. We then cluster local models to adaptively adjust the acceptable differences between the local models and the estimator such that Byzantine users can be identified. Extensive experiments over different datasets show that our approach achieves the following advantages simultaneously: (i) independence of participants' local data, (ii) tolerance of majority attackers, (iii) generalization to variable Byzantine model. Jianrong Lu, Shengshan Hu, Junyu Shi, Leo Yu Zhang, Man Zhou 0004, Yifeng Zheng 0001 |
MSN | 7 |
| 2021 | Stealing Your Android Patterns via Acoustic SignalsabstractPattern lock is an essential authentication method on mobile devices. Recent works on cracking pattern locks either require additional network facilities (e.g., WiFi hotspots) or suffer from strict constraints (e.g., physical closeness to the victim and good lighting). Being too susceptible to environment settings, these attacks are less effective in practice and cannot scale to a large number of users. To address these concerns, in this paper, we propose PatternListener+, a practical attack on pattern locks using the speakers and microphones on mobile devices. The speaker plays inaudible acoustic signals, which are reflected by the fingertip when the victim is drawing the pattern, and then recorded by the microphone. The recorded acoustic signals contain rich information of the fingertip motion that can be leveraged to infer the pattern. We carefully design a series of algorithms to eliminate the dynamic and static interferences, segment acoustic signals into fragments corresponding to all pattern lines, and recover each line composed of the pattern according to the signals. Finally, we recover the candidate pattern by mapping all line candidates into grid patterns with a tree structure. We implement a PatternListener+ prototype using off-the-shelf smartphones, and extensive experiments confirm the effectiveness and robustness of PatternListener+. The attack success rate is over 90 percent on 120 patterns in five attempts. Man Zhou 0004, Qian Wang 0002, Jingxiao Yang, Qi Li 0002, Peipei Jiang 0002, Yanjiao Chen, Zhibo Wang 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | Active Link Obfuscation to Thwart Link-flooding Attacks for Internet of ThingsabstractThe DDoS attack is a serious threat to Internet of Things (IoT). As a new class of DDoS attack, Link-flooding attack (LFA) disrupts connectivity between legitimate IoT devices and target servers by flooding only a small number of links. In this paper, we propose an active LFA mitigation mechanism, called Linkbait, that is a proactive and preventive defense to throttle LFA for IoT. We propose a link obfuscation algorithm in Linkbait that selectively reroutes probing flows to hide target links from adversaries and mislead them to identify bait links as target links. To block attack traffic and further reduce the impact in IoT, we propose a compromised IoT devices detection algorithm that extracts unique traffic patterns of LFA for IoT and leverages support vector machine (SVM) to identify attack traffic. We evaluate the performance of Linkbait by using both real-world experiments and large-scale simulations. The experimental results demonstrate the effectiveness of Linkbait. Xuyang Ding, Man Zhou 0004, Zhibo Wang 0001 |
TrustCom | 3 |
| 2020 | LVID: A Multimodal Biometrics Authentication System on SmartphonesabstractVoice authentication is becoming increasingly popular, which offers potential benefits over knowledge and possession based authentication methods. Meanwhile, the unique features of lip movements during speaking have been proved to be useful for authentication. However, the unimodal biometric authentication systems based on either voice or lip movements have certain limitations. Voice authentication systems are prone to spoofing attacks and suffer from serious performance degradation in noisy environments. Lip movements authentication systems are unstable and are sensitive to the user's physical and psychological conditions. In this paper, we propose and implement LVID, a multimodal biometrics authentication system on smartphones, which resolves the defects of the original systems by combining the advantages of lip movements and voice. LVID simultaneously captures these two biometrics with the built-in audio devices on smartphones and fuses them at the data level. The reliable and effective features are then extracted from the fused data for authentication. LVID is practical as it requires neither cumbersome operations nor additional hardwares but only a speaker and a microphone that are commonly available on smartphones. Our experimental results with 104 participants show that LVID can achieve 95% accuracy for user authentication, and 93.47% of the attacks can be detected. It is also verified that LVID works well with different smartphones and is robust to different smartphone positions. Jingxiao Yang, Man Zhou 0004, Yanjiao Chen, Qian Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | VoicePop: A Pop Noise based Anti-spoofing System for Voice Authentication on SmartphonesabstractVoice biometrics is widely adopted for identity authentication in mobile devices. However, voice authentication is vulnerable to spoofing attacks, where an adversary may deceive the voice authentication system with pre-recorded or synthesized samples from the legitimate user or by impersonating the speaking style of the targeted user. In this paper, we design and implement VoicePop, a robust software-only anti-spoofing system on smartphones. VoicePop leverages the pop noise, which is produced by the user breathing while speaking close to the microphone. The pop noise is delicate and subject to user diversity, making it hard to record by replay attacks beyond a certain distance and to imitate precisely by impersonators. We design a novel pop noise detection scheme to pinpoint pop noises at the phonemic level, based on which we establish individually unique relationship between phonemes and pop noises to identify legitimate users and defend against spoofing attacks. Our experimental results with 18 participants and three types of smartphones show that VoicePop achieves over 93.5% detection accuracy at around 5.4% equal error rate. VoicePop requires no additional hardware but only the built-in microphones in virtually all smartphones, which can be readily integrated in existing voice authentication systems for mobile devices. Qian Wang 0002, Xiu Lin, Man Zhou 0004, Yanjiao Chen, Cong Wang 0001, Qi Li 0002, Xiangyang Luo 0001 |
INFOCOM | 3 |
| 2019 | Dolphin: Real-Time Hidden Acoustic Signal Capture with SmartphonesabstractDual-channel screen-camera communication has been proposed to enable simultaneous screen viewing and hidden screen-camera communication. However, it strictly requires a well-controlled camera-screen alignment and an obstacle-free access. In this paper, we propose Dolphin, a novel real-time acoustics-based dual-channel communication system. Leveraging masking effects of human auditory system and readily available audio signals, Dolphin enables real-time unobtrusive speaker-microphone data communication without affecting the primary audio-hearing experience of human users. Compared with screen-camera communication, Dolphin supports non-line-of-sight transmissions and more flexible speaker-microphone alignments. Dolphin can also automatically adapt the data rate to various channel conditions. We further develop a secure data broadcasting scheme on Dolphin, where only designated privileged users can recover the embedded information in the acoustic signals. Our Dolphin prototype, built using COTS (Commercial Off-The-Shelf) smartphones, realizes (potentially secure) real-time hidden information communication, supports up to 8-meter signal capture distance and +900 listening angle, and achieves an average goodput of 240 bps at 2 m. Man Zhou 0004, Qian Wang 0002, Kui Ren 0001, Dimitrios Koutsonikolas, Lu Su 0001, Yanjiao Chen |
IEEE Trans. Mob. Comput. | 1 |
| 2018 | PatternListener: Cracking Android Pattern Lock Using Acoustic SignalsabstractPattern lock has been widely used for authentication to protect user privacy on mobile devices (e.g., smartphones and tablets). Several attacks have been constructed to crack the lock. However, these approaches require the attackers to be either physically close to the target device or able to manipulate the network facilities (e.g., wifi hotspots) used by the victims. Therefore, the effectiveness of the attacks is highly sensitive to the setting of the environment where the users use the mobile devices. Also, these attacks are not scalable since they cannot easily infer patterns of a large number of users. Motivated by an observation that fingertip motions on the screen of a mobile device can be captured by analyzing surrounding acoustic signals on it, we propose PatternListener, a novel acoustic attack that cracks pattern lock by leveraging and analyzing imperceptible acoustic signals reflected by the fingertip. It leverages speakers and microphones of the victim's device to play imperceptible audio and record the acoustic signals reflected from the fingertip. In particular, it infers each unlock pattern by analyzing individual lines that are the trajectories of the fingertip and composed of the pattern. We propose several algorithms to construct signal segments for each line and infer possible candidates of each individual line according to the signal segments. Finally, we produce a tree to map all line candidates into grid patterns and thereby obtain the candidates of the entire unlock pattern. We implement a PatternListener prototype by using off-the-shelf smartphones and thoroughly evaluate it using 130 unique patterns. The real experimental results demonstrate that PatternListener can successfully exploit over 90% patterns in five attempts. Man Zhou 0004, Qian Wang 0002, Jingxiao Yang, Qi Li 0002, Zhibo Wang 0001, Xiaofeng Chen 0001 |
CCS | 1 |
| 2018 | Enabling Online Robust Barcode-Based Visible Light Communication With Realtime FeedbackabstractBarcode-based visible light communication (VLC) over screen-camera links has attracted great research interest recently due to its many desirable properties, including being free of charge, free of complex network configurations, and its well-controlled communication security. However, existing VLC systems over screen-camera links suffer from low-communication capacity and reliability, and a lack of transmission feedback from the receiver. In this paper, we design RainBar+, an online robust high-goodput color barcode-based VLC system with realtime feedback, to fully guarantee the communication reliability and exploit the communication capacity under a different link quality. To the best of our knowledge, this is the first system that provides a feasible feedback mechanism to enable the sender to retransmit the lost frames and optimize the barcode configurations. To this end, RainBar+ is designed from three orthogonal perspectives: optimizing the encoding capacity of each frame, fully utilizing the transmission capacity of the sender by solving the frame synchronization problem and adaptively adjusting the barcode configurations, and enabling the selective retransmission via realtime feedback with the speaker-microphone link. Extensive experiments with two commercial off-the-shelf smartphones show that RainBar+ outperforms existing systems and can support realtime high-goodput data communication in dynamic environments. Man Zhou 0004, Qian Wang 0002, Tao Lei 0005, Zhibo Wang 0001, Kui Ren 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2017 | Poster: Enabling Secure Location Authentication in DroneabstractWith the popularity of commodity drones in a wide variety of applications, significant security issues have been raised. One of the major problems is that a legal drone may be illegally hijacked by GPS spoofing attacks. Though some GPS anti-spoofing techniques have been proposed, no effective technique has been implemented in commodity drones yet due to practical limitations. Motivated by the ubiquitous WiFi signals around us, we propose WiDrone, a WiFi fingerprint location cross-check based anti-hijacking system on commodity drones in this poster. WiDrone still relies on GPS for navigation but it will authenticate the destination by comparing current WiFi fingerprint (CWF) with the destination WiFi fingerprint (DWF) when the drone receives a landing order. Furthermore, we propose a WiFi fingerprint authentication algorithm to decide whether CWF matches DWF. We have designed and implemented the prototype of WiDrone on DJI Matrice 100 to ascertain the practicability of proposed system. Man Zhou 0004, Youcheng Liye, Jingxiao Yang, Qian Wang 0002 |
MobiCom | 2 |
| 2016 | Messages behind the sound: real-time hidden acoustic signal capture with smartphonesabstractWith the ever-increasing use of smart devices, recent research endeavors have led to unobtrusive screen-camera communication channel designs, which allow simultaneous screen viewing and hidden screen-camera communication. Such practices, albeit innovative and effective, require well-controlled alignment of camera and screen and obstacle-free access. Qian Wang 0002, Kui Ren 0001, Man Zhou 0004, Tao Lei 0005, Dimitrios Koutsonikolas, Lu Su 0001 |
MobiCom | 3 |
| 2016 | Real-time hidden acoustic signal capture with smartphones: demoabstractWith the ever-increasing use of smart devices, recent research endeavors have led to unobtrusive screen-camera communication channel designs, which allow simultaneous screen viewing and hidden screen-camera communication. Such practices, albeit innovative and effective, require well-controlled alignment of camera and screen and obstacle-free access. In this demo, we present Dolphin, a novel form of real-time acoustics-based dual-channel communication, which uses a speaker and the microphones on off-the-shelf smartphones to achieve concurrent audible and hidden communication. By leveraging masking effects of the human auditory system and readily available audio signals in our daily lives, Dolphin ensures real-time unobtrusive speaker-microphone data communication, while, at the same time, it overcomes the main limitations of existing screen-camera links. Qian Wang 0002, Kui Ren 0001, Man Zhou 0004, Tao Lei 0005, Dimitrios Koutsonikolas, Lu Su 0001 |
MobiCom | 3 |
| 2015 | Rain Bar: Robust Application-Driven Visual Communication Using Color BarcodesabstractColor barcode-based visible light communication (VLC) over screen-camera links has attracted great research interest in recent years due to its many desirable properties, including free of charge, free of interference, free of complex network configuration and well-controlled communication security. To achieve high-throughput barcode streaming, previous systems separately address design challenges such as image blur, imperfect frame synchronization and error correction etc., without being investigated as an interrelated whole. This does not fully exploit the capacity of color barcode streaming, and these solutions all have their own limitations from a practical perspective. This paper proposes RainBar, a new and improved color barcode-based visual communication system, which features a carefully-designed high-capacity barcode layout design to allow flexible frame synchronization and accurate code extraction. A progressive code locator detection and localization scheme and a robust color recognition scheme are proposed to enhance system robustness and hence the decoding rate under various working conditions. An extensive experimental study is presented to demonstrate the effectiveness and flexibility of RainBar. Results on Android smartphones show that our system achieves higher average throughput than previous systems, under various working environments. Qian Wang 0002, Man Zhou 0004, Kui Ren 0001, Tao Lei 0005, Jikun Li, Zhibo Wang 0001 |
ICDCS | 2 |