EDBT 2026 Demo / reviewers in the wild / expert
Boyan Ding
dblp:194/3928
· DBLP profile ↗
12ranked-venue papers
2as first author
7since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 2 first-author · 7 since 2021Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Sign-to-911: Emergency Call Service for Sign Language Users with Assistive AR GlassesabstractSign-to-911 offers a compact mobile system solution to fast and runtime American Sign Language (ASL) and English translations. It is designated as 911 call services for ASL users with hearing disabilities upon emergencies. It enables bidirectional translations of ASL-to-English and English-to-ASL. The signer wears the AR glasses, runs Sign-to-911 on his/her smartphone and glasses, and interacts with a 911 operator. The design of Sign-to-911 departs from the popular deep learning based solution paradigm, and adopts simpler traditional AI/machine learning (ML) models. The key is to exploit ASL linguistic features to simplify the model structures and improve accuracy and speed. It further leverages recent component solutions from graphics, vision, natural language processing, and AI/ML. Our evaluation with six ASL signers and 911 call records has confirmed its viability. Yunqi Guo, Boyan Ding, Congkai Tan, Weichong Ling, Zhaowei Tan, Jennifer Miyaki, Hongzhe Du, Songwu Lu |
MobiCom | 3 |
| 2023 | CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data Plane
Zhaowei Tan, Boyan Ding, Songwu Lu |
NSDI | 3 |
| 2022 | Breaking Cellular IoT with Forged Data-plane Signaling: Attacks and CountermeasureabstractWe devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (a.k.a. both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. The attacker can forge both uplink and downlink data-plane signaling messages that pass the current security checks used by the receiver. With the capability of forging messages, the attacker can launch attacks that exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, connection reset, and multicast disabling. Our testbed evaluation and operational network validation have confirmed the attack viability. To combat the threat, we further propose a new defense solution within the 3GPP C-IoT standard framework. It leverages the synchronized timer clock information to protect the data-plane signaling messages with low overhead. Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu |
ACM Trans. Sens. Networks | 2 |
| 2021 | Sonica: an open-source NB-IoT prototyping platformabstractIn this demo, we describe Sonica, an open-source NB-IoT prototype platform. Both radio access and core network components are designed and implemented with the features and characteristics of NB-IoT into account. With its eNB and core network (EPC) components, Sonica can function as an NB-IoT testbed which interacts with commercial off-the-shelf NB-IoT devices. Moreover, Sonica provides a flexible framework that supports quick prototyping for MAC/PHY layers. Boyan Ding, Zhaowei Tan, Songwu Lu |
MobiCom | 1 |
| 2021 | Experience: a five-year retrospective of MobileInsightabstractThis paper reports our five-year lessons of developing and using MobileInsight, an open-source community tool to enable software-defined full-stack, runtime mobile network analytics inside our phones. We present how MobileInsight evolves from a simple monitor to a community toolset with cross-layer analytics, energy-efficient real-time user-plane analytics, and extensible user-friendly analytics at the control and user planes. These features are enabled by various novel techniques, including cross-layer state machine tracking, missing data inference, and domain-specific cross-layer sampling. Their powerfulness is exemplified with a 5-year longitudinal study of operational mobile network latency using a 6.4TB dataset with 6.1 billion over-the-air messages. We further share lessons and insights of using MobileInsight by the community, as well as our visions of MobileInsight's past, present, and future. Yuanjie Li, Chunyi Peng 0001, Zhehui Zhang, Zhaowei Tan, Haotian Deng 0001, Qianru Li 0002, Yunqi Guo, Kai Ling, Boyan Ding, Hewu Li, Songwu Lu |
MobiCom | 10 |
| 2021 | Data-plane signaling in cellular IoT: attacks and defenseabstractIn this paper, we devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (aka both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. Such attacks exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, and connection reset. Our testbed evaluation and operational network validation have confirmed the viability. We further propose a new defense solution within the 3GPP C-IoT standard framework. Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu |
MobiCom | 2 |
| 2021 | SecureSIM: rethinking authentication and access control for SIM/eSIMabstractThe SIM/eSIM card stores critical information for a mobile user to access the 4G/5G network. In this work, we uncover three vulnerabilities of the current SIM practice. We show that the PIN-based access control may expose the in-SIM data to an adversary through both hardware and software. Once exposed, such in-SIM information can be used to reconstruct various keys used for device authentication, data encryption, etc. They thus enable a number of attacks, including traffic eavesdropping, man-in-the-middle attack, impersonation, etc. The fundamental problem is that, the current SIM design does not offer proper authentication and fine-grained access control to hundreds of in-SIM files for various in-card applets and off-card units. We next propose a new solution that offers both authentication and fine-grained access control. Our implementation and evaluation have confirmed the viability of our proposal. Boyan Ding, Yunqi Guo, Zhaowei Tan, Songwu Lu |
MobiCom | 2 |
| 2020 | A SDR-based verification platform for 802.11 PHY layer security authentication
Jun Liu 0063, Boyan Ding, Tao Wang 0004 |
World Wide Web | 3 |
| 2019 | GPLM: An 802.11ac-Capable Low-MAC Architecture for FPGA-based SDR Systemsabstract802.11 is a widely-used wireless communication standard today and is still under constant evolution. Two major enhancements of the standard, 802.11n and 802.11ac, boost the performance and quality of service, with the former getting support in nearly all commercial devices today and the latter gaining prevalence. However, there is currently no software-defined radio (SDR) system that is capable to support the whole 802.11ac protocol stack, especially the MAC layer, in real-time, limiting research and testing on these latest innovations. This paper presents GPLM, a Low-MAC architectural design for FPGA-based SDR systems that supports 802.11ac. We identify challenges imposed by new features in 802.11ac MAC layer, and make careful architectural choices to ensure both standard compliance and flexibility. The design and implementation of critical modules and the employment of software hardware co-design are detailed in this paper. Paired up with an existing work on the PHY layer implementation of 802.11ac, the implementation of GPLM is validated from various aspects. Boyan Ding, Jun Liu 0063, Tao Wang 0004 |
WCNC | 1 |
| 2018 | CR-GRT: A Novel SDR Platform Optimized for Real-time Cognitive Radio ApplicationsabstractCognitive radio (CR) technology aims to provide real-time sensing and efficient dynamic spectrum access to improve the efficiency of spectrum resource usage. However, none of the existing SDR platforms is capable of supporting CR applications while maintaining high performance and programmability. In this paper, we propose CR-GRT, an SDR platform designed for cognitive radio applications. CR-GRT supports real-time sensing, analysis, decision-making and dynamic adjustment. It also provides interfaces for extensibility. Based on CR-GRT, we implement a comprehensive sensing strategy using both PHY and MAC information. The evaluation result shows that CR-GRT has advantages in high performance and programmability. Jun Liu 0063, Boyan Ding, Tao Wang 0004 |
MSWiM | 4 |
| 2017 | GRT 2.0: An FPGA-based SDR Platform for Cognitive Radio Networks (Abstract Only)
Tao Wang 0004, Boyan Ding, Tianfu Jiang, Jun Liu 0063, Songwu Lu |
FPGA | 4 |
| 2017 | The Tick Programmable Low-Latency SDR SystemabstractTick is a new SDR system that provides programmability and ensures low latency at both PHY and MAC. It supports modular design and element-based programming, similar to the Click router framework [23]. It uses an accelerator-rich architecture, where an embedded processor executes control flows and handles various MAC events. User-defined accelerators offload those tasks, which are either computation-intensive or communication-heavy, or require fine-grained timing control, from the processor, and accelerate them in hardware. Tick applies a number of hardware and software co-design techniques to ensure low latency, including multi-clock-domain pipelining, field-based processing pipeline, separation of data and control flows, etc. We have implemented Tick and validated its effectiveness through extensive evaluations as well as two prototypes of 802.11ac SISO/MIMO and 802.11a/g full-duplex. Tao Wang 0004, Zengwen Yuan, Chunyi Peng 0001, Zhaowei Tan, Boyan Ding, Yuanjie Li, Jun Liu 0063, Songwu Lu |
MobiCom | 7 |