EDBT 2026 Demo / reviewers in the wild / expert
Yanmao Man
dblp:174/4227
· DBLP profile ↗
11ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0002-3994-7416ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 6 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Investigating Physical Latency Attacks Against Camera-Based PerceptionabstractCamera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems. Raymond Muller, Ruoyu Song 0001, Chenyi Wang 0005, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
SP | 6 |
| 2025 | From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative Perception
Chenyi Wang 0005, Raymond Muller, Ruoyu Song 0001, Jean-Philippe Monteuuis, Jonathan Petit, Yanmao Man, Ryan M. Gerdes, Z. Berkay Celik, Ming Li 0003 |
USENIX Security Symposium | 6 |
| 2024 | Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial TrajectoryabstractMulti-Object Tracking (MOT) is a critical task in computer vision, with applications ranging from surveillance systems to autonomous driving. However, threats to MOT algorithms have yet been widely studied. In particular, incorrect association between the tracked objects and their assigned IDs can lead to severe consequences, such as wrong trajectory predictions. Previous attacks against MOT either focused on hijacking the trackers of individual objects, or manipulating the tracker IDs in MOT by attacking the integrated object detection (OD) module in the digital domain, which are model-specific, non-robust, and only able to affect specific samples in offline datasets. In this paper, we present AdvTraj, the first online and physical ID-manipulation attack against tracking-by-detection MOT, in which an attacker uses adversarial trajectories to transfer its ID to a targeted object to confuse the tracking system, without attacking OD. Our simulation results in CARLA show that AdvTraj can fool ID assignments with 100% success rate in various scenarios for white-box attacks against SORT, which also have high attack transferability (up to 93% attack success rate) against state-of-the-art (SOTA) MOT algorithms due to their common design principles. We characterize the patterns of trajectories generated by AdvTraj and propose two universal adversarial maneuvers that can be performed by a human walker/driver in daily scenarios. Our work reveals under-explored weaknesses in the object association phase of SOTA MOT systems, and provides insights into enhancing the robustness of such systems. Chenyi Wang 0005, Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes, Jonathan Petit |
ACSAC | 2 |
| 2024 | VOGUES: Validation of Object Guise using Estimated Components
Raymond Muller, Yanmao Man, Ming Li 0003, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik |
USENIX Security Symposium | 2 |
| 2024 | Remote Perception Attacks against Camera-based Object Recognition Systems and CountermeasuresabstractIn vision-based object recognition systems, imaging sensors perceive the environment and then objects are detected and classified for decision-making purposes, e.g., to maneuver an automated vehicle around an obstacle or to raise alarms for intruders in surveillance settings. In this work we demonstrate how camera-based perception can be unobtrusively manipulated to enable an attacker to create spurious objects or alter an existing object, by remotely projecting adversarial patterns into cameras, exploiting two common effects in optical imaging systems, viz., lens flare/ghost effects and auto-exposure control. To improve the robustness of the attack, we generate optimal patterns by integrating adversarial machine learning techniques with a trained end-to-end channel model. We experimentally demonstrate our attacks using a low-cost projector on three different cameras, and under different environments. Results show that, depending on the attack distance, attack success rates can reach as high as 100%, including under targeted conditions. We develop a countermeasure that reduces the problem of detecting ghost-based attacks into verifying whether there is a ghost overlapping with a detected object. We leverage spatiotemporal consistency to eliminate false positives. Evaluation on experimental data provides a worst-case equal error rate of 5%. Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2023 | That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency
Yanmao Man, Raymond Muller, Ming Li 0003, Z. Berkay Celik, Ryan M. Gerdes |
USENIX Security Symposium | 1 |
| 2022 | Physical Hijacking Attacks against Object TrackersabstractModern autonomous systems rely on both object detection and object tracking in their visual perception pipelines. Although many recent works have attacked the object detection component of autonomous vehicles, these attacks do not work on full pipelines that integrate object tracking to enhance the object detector's accuracy. Meanwhile, existing attacks against object tracking either lack real-world applicability or do not work against a powerful class of object trackers, Siamese trackers. In this paper, we present AttrackZone, a new physically-realizable tracker hijacking attack against Siamese trackers that systematically determines valid regions in an environment that can be used for physical perturbations. AttrackZone exploits the heatmap generation process of Siamese Region Proposal Networks in order to take control of an object's bounding box, resulting in physical consequences including vehicle collisions and masked intrusion of pedestrians into unauthorized areas. Evaluations in both the digital and physical domain show that AttrackZone achieves its attack goals 92% of the time, requiring only 0.3-3 seconds on average. Raymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li 0003, Ryan M. Gerdes |
CCS | 2 |
| 2020 | GhostImage: Remote Perception Attacks against Camera-based Image Classification Systems
Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
RAID | 1 |
| 2020 | SVM: secure vehicle motion verification with a single wireless receiverabstractConnected vehicles leverage wireless interfaces to broadcast their motion state information for improved traffic safety and efficiency. It is crucial for their motion claims (location and velocity) to be verified at the receivers to detect spoofing attacks. Existing approaches typically require multiple cooperative distributed verifiers, which is not applicable to vehicular networks. In this work, we propose a secure motion verification scheme based on Angle-of-Arrival and Frequency-of-Arrival that only requires a single verifier, by exploiting opportunistic signal reflection paths in the environment to create multiple virtual verifiers. We analyze the security of our scheme both theoretically and under realistic road topology. We also carry out real-world experiments with two vehicles in a campus environment, and results show that our scheme can accurately detect false motion claims in a low relative speed vehicular network. Mingshun Sun, Yanmao Man, Ming Li 0003, Ryan M. Gerdes |
WISEC | 2 |
| 2019 | SIMPLE: single-frame based physical layer identification for intrusion detection and prevention on in-vehicle networksabstractThe Controller Area Network (CAN) is a bus standard commonly used in the automotive industry for connecting Electronic Control Units (ECUs) within a vehicle. The broadcast nature of this protocol, along with the lack of authentication or strong integrity guarantees for frames, allows for arbitrary data injection/modification and impersonation of the ECUs. While mitigation strategies have been proposed to counter these attacks, high implementation costs or violation of backward compatibility hinder their deployment. In this work, we first examine the shortcomings of state-of-the-art CAN intrusion detection and identification systems that rely on multiple frames to detect misbehavior and attribute it to a particular ECU, and show that they are vulnerable to a Hill-Climbing-style attack. Then we propose SIMPLE, a real-time intrusion detection and identification system that exploits physical layer features of ECUs, which would not only allow an attack to be detected using a single frame but also be effectively nullified. SIMPLE has low computational and data acquisition costs, and its efficacy is demonstrated by both in-lab experiments with automotive-grade CAN transceivers as well as in-vehicle experiments, where average equal error rates of close to 0% and 0.8985% are achieved, respectively. Mahsa Foruhandeh, Yanmao Man, Ryan M. Gerdes, Ming Li 0003, Thidapat Chantem |
ACSAC | 2 |
| 2016 | Secure Routing Based on Social Similarity in Opportunistic NetworksabstractThe lack of pre-existing infrastructure or dynamic topology makes it impossible to establish end-to-end connections in opportunistic networks (OppNets). Instead, a store-and-forward strategy can be employed. However, such loosely knit routing paths depend heavily on the cooperation among participating nodes. Selfish or malicious behaviors of nodes impact greatly on the network performance. In this paper, we design and validate a dynamic trust management model for secure routing optimization. We propose the concept of incorporating social trust into the routing decision process and design a trust routing based on social similarity (TRSS) scheme. TRSS is based on the observation that nodes move around and contact each other according to their common interests or social similarities. A node sharing more social features in social history record with the destination is more likely to travel close to the latter in the near future and should be chosen as the next-hop forwarder. Furthermore, social trust can be established based on an observed node's trustworthiness and its encounter history. Based on direct and recommended trust, those untrustworthy nodes will be detected and purged from the trusted list. Since only trusted nodes' packets will be forwarded, the selfish nodes have the incentives to behave well again. Simulation evaluation demonstrates that TRSS is very effective in detecting selfish or even malicious nodes and achieving better performance. Lin Yao 0001, Yanmao Man, Jing Deng 0001, Xin Wang 0001 |
IEEE Trans. Wirel. Commun. | 2 |