EDBT 2026 Demo / reviewers in the wild / expert
Tian Xie 0001
dblp:18/4584-1
· DBLP profile ↗
20ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0003-1309-6091ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 4 first-author · 13 since 2021Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks, and CountermeasuresabstractLost and stolen phone reporting services are widely deployed to prevent unauthorized device use by blacklisting International Mobile Equipment Identities (IMEIs). However, through an extensive experimental study across three major U.S. carriers and diverse mobile devices, we discover that these services unexpectedly introduce severe and previously unexplored security risks. Specifically, we identify six new vulnerabilities spanning the device, carrier, and cross-carrier domains, which together enable attackers to arbitrarily block cellular devices from accessing carrier networks. Building on these findings, we design and validate two practical denial-of-service (DoS) attacks: Home Security System Freezing, which disables cellular-based home security gateways and blocks alarm delivery, and Zero-Day Flagship Phone Ambush, which preemptively blocks brand-new flagship phones from accessing mobile services at launch. Both attacks are experimentally validated on operational 5G/4G networks. Finally, we propose practical, backward-compatible countermeasures and implement a prototype to evaluate their effectiveness. Min-Yue Chen, Yiwen Hu 0002, Yu-An Chen, Chi-Yu Li 0001, Tian Xie 0001, Guan-Hua Tu |
MobiSys | 5 |
| 2026 | Uncovering Risks of Data-Free Feature Vector Inversion Attacks Against Vector DatabasesabstractThe vector database stores data as high-dimensional feature vectors. Some recently proposed attack techniques enable an adversary to launch feature vector inversion (FVI) attacks against vector databases. In FVI attacks, an adversary trains an FVI attack network to reconstruct the original private data from their feature vectors based on the assumption that an auxiliary dataset is available to the adversary. However, such a data-available assumption is too strong, making such FVI attacks unrealistic in many real-world scenarios. In this paper, we make the first systematic study on FVI attacks against vector databases in the data-free setting. To tackle the issue of no training data, we develop an output-to-input data generation technique that helps to generate synthetic fake samples for the FVI attack network training. In addition, to ensure the high quality of generated fake samples, we develop the accelerable complete bipartite graph (CBG) search strategy and the downstream-classifier-aided generator training strategy. Furthermore, as the key insight of this work, we find that the proposed output-to-input data generation technique can be employed to launch the other three ML attacks. Intriguingly, we find that the proposed FVI attack technique in the data-free setting can be directly employed to boost the attack performance of FVI attacks in the auxiliary-dataset-available setting. Finally, we propose and study defenses against the proposed attacks. Shengyang Qin, Nankun Mu, Hongyu Huang 0001, Tian Xie 0001, Xiao Zhang 0037 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | When Mobile Equipment Security Lags Behind Infrastructure: Vulnerabilities, Attacks, and Countermeasures in IMS Services
Jingwen Shi, Min-Yue Chen, Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Yiwen Hu 0002, Man-Hsin Chen, Haitian Yan, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Netw. | 5 |
| 2025 | ViKey: Secure Door Access Control Using Passive Visible Light TagsabstractDoor Access Control (DAC) plays a pivotal role in balancing security and convenience in modern infrastructures. However, current vision-based DAC systems exhibit limitations including privacy concerns (e.g., facial data leakage), performance degradation under suboptimal lighting conditions, high computational overhead and system costs. While RFID and Bluetooth-based alternatives exist, they exhibit vulnerabilities to attacks including replay attacks, signal cloning, and eavesdropping. Recent advances in visible light sensing and backscatter communication have enabled promising opportunities for secure, low-power access control systems with sub-dollar hardware costs. In this paper, we propose ViKey, the first visible light backscatter-based DAC system that utilizes polarized birefringence to generate 3D position-dependent color patterns as keys, enabling robust and contactless authentication. We design and implement a ViKey prototype using commercial off-the-shelf (COTS) components, with a tag cost of less than $0.2. Real-world experiments show that our current ViKey prototype can achieve an average authentication accuracy of 90.5% at 0.5m with our best patterns. These results demonstrate the effectiveness of our low-cost visible light backscatter technology for future smart DAC applications. Jaskirat Sudan, Fatima Qasem, Hasky Fynn, Fatima Mohammed, Ashwin Sarvadey, Tian Xie 0001, Xiao Zhang 0037 |
MASS | 6 |
| 2024 | Uncovering Problematic Designs Hindering Ubiquitous Cellular Emergency Services AccessabstractCellular networks provide the most accessible emergency services with ubiquitous coverage, yet their emergency-specific designs remain largely unexplored. To systematically explore potential design defects that lead to failures or delays in emergency services, we introduce M911-Verifier, an emergency-specific model checking tool. It reveals many counterintuitive findings regarding the ubiquitous access support for cellular emergency services. Our study shows that, despite sufficient wireless signal coverage, users may still experience prolonged emergency call setup times, call initiation failures, or call drops due to flaws in the design of cellular emergency services. These design defects arise from three major causes: problematic network selection for initiating emergency calls, emergency-unaware call operation, and network escalation forbidden during emergency calls. The impacts of these defects have been experimentally validated across three U.S. carriers and two Taiwan carriers using commodity smartphones. Finally, we propose solutions and evaluate their effectiveness. Yiwen Hu 0002, Min-Yue Chen, Haitian Yan, Chuan-Yi Cheng, Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Chunyi Peng 0001, Li Xiao 0001, Jiliang Tang |
MobiCom | 7 |
| 2024 | IMS is Not That Secure on Your 5G/4G PhonesabstractIMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities. Jingwen Shi, Sihan Wang 0002, Min-Yue Chen, Guan-Hua Tu, Tian Xie 0001, Man-Hsin Chen, Yiwen Hu 0002, Chi-Yu Li 0001, Chunyi Peng 0001 |
MobiCom | 5 |
| 2024 | Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure DesignsabstractCellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities. Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
IEEE/ACM Trans. Netw. | 7 |
| 2024 | Dissecting Operational Cellular IoT Service Security: Attacks and DefensesabstractMore than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to${\$}226$with less than 120 MB spam traffic, increase an IoT text bill at a rate of${\$}5$per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Tian Xie 0001, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked SystemsabstractNowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework,${{\sf MPKIX}}$, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509).${{\sf MPKIX}}$secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of${{\sf MPKIX}}$and implement an${{\sf MPKIX}}$prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of${{\sf MPKIX}}$with low overhead. Tian Xie 0001, Sihan Wang 0002, Jingwen Shi, Guan-Hua Tu, Chi-Yu Li 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Insecurity of Operational IMS Call Systems: Vulnerabilities, Attacks, and CountermeasuresabstractIMS (IP Multimedia Subsystem) is an essential 4G/5G component to offer multimedia services. It is used worldwide to support two call services: VoLTE (Voice over LTE) and VoWiFi (Voice over WiFi). In this study, it is shown that the signaling and voice sessions of VoWiFi can both be hijacked by a malicious adversary. By hijacking the signaling session, s(he) gains the ability to make ghost calls to launch stealthy DoS (Denial of Service) or caller-ID spoofing attacks against specific cellular users. Such attacks can be carried out without any malware or network information, and require only the victim’s phone number to be known. It is shown that phones vulnerable to the call DoS attacks can be detected at run time by exploiting a vulnerability of cellular network infrastructures referred to as call information leakage, which is exposed based on a machine learning method. Especially, the call DoS attacks can prevent victims from receiving incoming calls for up to 99.0% time without user awareness. Moreover, by hijacking the voice session, an adversary can launch stealthy free data transfer attacks based on phone numbers alone rather than IP addresses. The identified vulnerabilities/attacks are validated in the operational 4G networks of four top-tier carriers across Asia and North America with seven phone brands. The study concludes by presenting a suite of solutions to address them. Yu-Han Lu, Sandy H. Hsiao, Chi-Yu Li 0001, Yi-Chen Hsieh, Po-Yi Chou, Yao-Yu Li, Tian Xie 0001, Guan-Hua Tu |
IEEE/ACM Trans. Netw. | 7 |
| 2022 | Uncovering insecure designs of cellular emergency services (911)abstractCellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities. Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
MobiCom | 7 |
| 2021 | Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and CountermeasuresabstractNowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards. Yiwen Hu 0002, Sihan Wang 0002, Guan-Hua Tu, Li Xiao 0001, Tian Xie 0001, Chi-Yu Li 0001 |
CODASPY | 5 |
| 2021 | BFastPay: A Routing-free Protocol for Fast Payment in Bitcoin NetworkabstractBitcoin is the most popular cryptocurrency which supports payment services via the Bitcoin peer-to-peer network. However, Bitcoin suffers from a fundamental problem. In practice, a secure Bitcoin transaction requires the payee to wait for at least 6 block confirmations (one hour) to be validated. Such a long waiting time thwarts the wide deployment of the Bitcoin payment services because many usage scenarios require a much shorter waiting time. In this paper, we propose BFastPay to accelerate the Bitcoin payment validation. BFastPay employs a smart contract called BFPayArbitrator to host the payer's security deposit and fulfills the role of a trusted payment arbitrator which guarantees that a payee always receives the payment even if attacks occur. BFastpay is a routing-free solution that eliminates the requirement for payment routing in the traditional payment routing network (e.g., Lightning Network). The theoretical and experimental results show that BFast is able to significantly reduce the Bitcoin payment waiting time (e.g., from 60 mins to less than 1 second) with nearly no extra operation cost. Guan-Hua Tu, Tian Xie 0001, Sihan Wang 0002 |
CODASPY | 3 |
| 2021 | Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresabstractMore than 150 cellular networks worldwide have rolled out massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover five vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices and launch data/text spamming attacks against them. We experimentally validate these vulnerabilities and attacks with three major U.S. IoT carriers. The attack evaluation result shows that the adversary can raise an IoT data bill by up to $226 with less than 120 MB spam traffic and increase an IoT text bill at a rate of $5 per second; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
MobiCom | 4 |
| 2021 | How Can IoT Services Pose New Security Threats In Operational Cellular Networks?abstractCarriers are rolling out Internet of Things (IoT) services including various IoT devices and use scenarios. Compared with conventional non-IoT devices such as smartphones and tablets, IoT devices have limited network capabilities (e.g., low rates) and specific use scenarios (e.g., inside vehicles only). These specialized use scenarios lead to carries often offering cheaper device access fees for IoT devices. However, the aforementioned disparity of service charging between IoT and non-IoT devices may lead to security issues. In this work, we conduct the first empirical security study on cellular IoT service charging over two major US carriers and make three major contributions. First, we discover four security vulnerabilities and analyze their root causes, which help us identify two significant security threats, IoT masquerading and IoT use scenario abuse. Second, we devise three proof-of-concept attacks and assess their real-world impact. We determine that they can be exploited to allow adversaries to pay 43.75-80.00 percent less for cellular data services. Third, we analyze the challenges in addressing these vulnerabilities and develop an anti-abuse solution to mitigate attack incentives. The solution is standard-compliant and can be used immediately in practice. Our prototype and evaluation confirm its effectiveness. Tian Xie 0001, Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | The Untold Secrets of WiFi-Calling Services: Vulnerabilities, Attacks, and CountermeasuresabstractSince 2016, all of four major U.S. operators have rolled out Wi-Fi calling services. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrusted Wi-Fi networks and the Internet. This exposure to insecure networks can cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA, IPSec, etc. However, are they sufficient to secure Wi-Fi calling services? Unfortunately, our study yields a negative answer. We conduct the first security study on the operational Wi-Fi calling services in three major U.S. operators networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof and uncover three vulnerabilities. By exploiting the vulnerabilities, we devise two proof-of-concept attacks: telephony harassment or denial of voice service and user privacy leakage; both of them can bypass the existing security defenses. We have confirmed their feasibility using real-world experiments, as well as assessed their potential damages and proposed a solution to address all identified vulnerabilities. Tian Xie 0001, Guan-Hua Tu, Bangjie Yin, Chi-Yu Li 0001, Chunyi Peng 0001, Mi Zhang 0002, Hui Liu 0031, Xiaoming Liu 0002 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | An Inter-blockchain Escrow Approach for Fast Bitcoin PaymentabstractIn recent years, the Bitcoin (BTC) payment is increasingly popular in retailers and service providers. A BTC transaction (tx) needs six confirmations (one hour) to be validated, making it not suitable for fast-pay scenarios. Theoretically, a shorter waiting time period increases the success possibility of a double-spending attack. To address this problem, we propose BTCFast scheme to support fast BTC tx. BTCFast is a novel, decentralized, escrow-based scheme on top of the programmable smart contract (PSC)-enabled blockchains (e.g. Ethereum, EOS). We develop a smart contract (PayJudger) to work as a trusted payment judger, which guarantees the tx fairness. In addition, we devise a proof-of-work (PoW)-based payment judgment mechanism for PayJudger to resolve a BTC payment dispute. Our theoretical and experimental results show that BTCFast can reduce the waiting time to be less than 1 second with comparable security as the current approach (i.e., waiting for six confirmations) with no extra operation fee. Tian Xie 0001, Guan-Hua Tu, Alex X. Liu |
ICDCS | 2 |
| 2020 | Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureabstractIMS (IP Multimedia Subsystem) is an essential framework for providing 4G/5G multimedia services. It has been deployed worldwide to support two call services: VoLTE (Voice over LTE) and VoWi-Fi (Voice over Wi-Fi). VoWi-Fi enables telephony calls over the Wi-Fi network to complement VoLTE. In this work, we uncover that the VoWi-Fi signaling session can be hijacked to maliciously manipulate the IMS call operation. An adversary can easily make ghost calls to launch a stealthy call DoS (Denial of Service) attack against specific cellular users. Only phone numbers, but not any malware or network information, are required from the victims. This sophisticated attack harnesses a design defect of the IMS call state machine, but not simply flooding or a crash trigger. To stealthily detect attackable phones at run time, we exploit a vulnerability of the 4G network infrastructure, call information leakage, which we explore using machine learning. We validate these vulnerabilities in operational 4G networks of 4 top-tier carriers across Asia and North America countries with 7 phone brands. Our result shows that the call DoS attack can prevent the victims from receiving incoming calls up to 99.0% time without user awareness. We finally propose and evaluate recommended solutions. Yu-Han Lu, Chi-Yu Li 0001, Yao-Yu Li, Sandy H. Hsiao, Tian Xie 0001, Guan-Hua Tu, Wei-Xun Chen |
MobiCom | 5 |
| 2020 | SecWIR: securing smart home IoT communications via wi-fi routers with embedded intelligenceabstractSmart home Wi-Fi IoT devices are prevalent nowadays and potentially bring significant improvements to daily life. However, they pose an attractive target for adversaries seeking to launch attacks. Since the secure IoT communications are the foundation of secure IoT devices, this study commences by examining the extent to which mainstream security protocols are supported by 40 of the best selling Wi-Fi smart home IoT devices on the Amazon platform. It is shown that 29 of these devices have either no security protocols deployed, or have problematic security protocol implementations. Seemingly, these vulnerabilities can be easily fixed by installing security patches. However, many IoT devices lack the requisite software/hardware resources to do so. To address this problem, the present study proposes a SecWIR (Secure Wi-Fi IoT communication Router) framework designed for implementation on top of the users' existing home Wi-Fi routers to provide IoT devices with a secure IoT communication capability. However, it is way challenging for SecWIR to function effectively on all home Wi-Fi routers since some routers are resource-constrained. Thus, several novel techniques for resolving this implementation issue are additionally proposed. The experimental results show that SecWIR performs well on a variety of commercial off-the-shelf (COTS) Wi-Fi routers at the expense of only a small reduction in the non-IoT data service throughput (less than 8%), and small increases in the CPU usage (4.5%~7%), RAM usage (1.9 MB~2.2 MB), and the IoT device access delay (24 ms~154 ms) while securing 250 IoT devices. Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Mi Zhang 0002 |
MobiSys | 4 |
| 2018 | How Voice Service Threatens Cellular-Connected IoT Devices in the Operational 4G LTE NetworksabstractLTE networks are rolling out cellular Internet-of- Things (IoT) services. Cellular-connected IoT devices are becoming increasingly popular and the number is forecasted to grow almost fourfold from 2015 to 2021. Since they share the same infrastructure with non-IoT devices such as smartphones, we may expect no big differences between them in terms of voice/data service accounting/charging (e.g., paying for what you get) and security risks. However, our study shows that cellular IoT users may pay more than what they get, as well as are vulnerable to voice signaling spams and thus suffer from an overcharging attack which leads to financial loss or denial of service. We validate our proof-of- concept attack in a major U.S. cellular network operator which takes higher than 35% market share. We finally propose a solution to address the identified security vulnerabilities. Tian Xie 0001, Chi-Yu Li 0001, Jiliang Tang, Guan-Hua Tu |
ICC | 1 |