EDBT 2026 Demo / reviewers in the wild / expert
Daniel M. Mittleman
dblp:202/4701
· DBLP profile ↗
22ranked-venue papers
0as first author
17since 2021 · last 2026
0000-0003-4277-7419ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 10 since 2021Security and privacy · 8 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Picosecond-Scale Secret Key Generation in Free Space
Burak Bilgin, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Michael P. Lilly, Daniel M. Mittleman, Edward W. Knightly |
INFOCOM | 6 |
| 2026 | MetaHeart: Metasurface enabled biometrics camouflage
Dora Zivanovic, Jy-Chin Liao, Zhambyl Shaikhanov, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Daniel M. Mittleman, Edward W. Knightly |
Comput. Commun. | 7 |
| 2026 | Metasurface-in-the-Middle Attack: EM Wavefront Manipulation Threats and CountermeasuresabstractMetasurfaces enable controllable manipulation of electromagnetic waves and have been shown to be valuable for wireless communications in many diverse ways. In this paper, we explore the notion that these useful components could also provide opportunities for a malicious agent. In particular, we define and experimentally demonstrate for the first time a “MetaSurface-in-the-Middle” (MSITM) attack. In this attack, the adversary Eve places a metasurface in the path of a directive transmission between Alice and Bob and targets to re-direct a portion of the signal towards herself, without being detected. Specifically, we show how Eve can design a metasurface that induces abrupt phase changes at the interface of the metasurface to controllably diffract directional links and establish furtive eavesdropping links. We explore the theoretical foundations of the MSITM attack and demonstrate that an effective metasurface can be prototyped in under 5 min at a minimal cost. We experimentally demonstrate the attack in a THz time-domain system and perform a set of over-the-air experiments. Our results indicate that the MSITM attack yields an acute vulnerability that can significantly reduce empirical secrecy capacity while leaving a minimal energy footprint, making the attack challenging to detect. Zhambyl Shaikhanov, Fahid Hassan, Hichem Guerboukha, Daniel M. Mittleman, Edward W. Knightly |
IEEE Trans. Netw. | 4 |
| 2025 | RIS-Assisted NOMA with Partial CSI and Mutual Coupling: A Machine Learning ApproachabstractNon-orthogonal multiple access (NOMA) is a promising multiple access technique. Its performance depends strongly on the wireless channel property, which can be enhanced by reconfigurable intelligent surfaces (RISs). In this paper, we jointly optimize base station (BS) precoding and RIS configuration with unsupervised machine learning (ML), which looks for the optimal solution autonomously. In particular, we propose a dedicated neural network (NN) architecture RISnet inspired by domain knowledge in communication. Compared to state-of-the-art, the proposed approach combines analytical optimal BS precoding and ML-enabled RIS, has a high scalability to control more than 1000 RIS elements, has a low requirement for channel state information (CSI) in input, and addresses the mutual coupling between RIS elements. Beyond the considered problem, this work is an early contribution to domain knowledge enabled ML, which exploit the domain expertise of communication systems to design better approaches than general ML methods. Bile Peng, Karl-Ludwig Besser, Shanpu Shen, Finn Siegismund-Poschmann, Ramprasad Raghunath, Daniel M. Mittleman, Vahid Jamali, Eduard A. Jorswieck |
GLOBECOM | 6 |
| 2025 | Downlink Multi-User Sub-THz Communication with a Programmable Metasurface
Fahid Hassan, Zhambyl Shaikhanov, Jeffrey Lei, Hichem Guerboukha, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Michael P. Lilly, Daniel M. Mittleman, Edward W. Knightly |
INFOCOM | 9 |
| 2025 | Spoofing Eavesdroppers with Audio MisinformationabstractWireless eavesdropping on phone conversations has become a major security and safety concern, especially with advancements toward 5G and beyond featuring higher frequencies and higher sensing resolution. As demonstrated recently, attackers can remotely detect even micron-scale acoustic vibrations emanating from a smartphone's earpiece via off-the-shelf millimeter-wave radar for audio information eavesdropping, all without the victim ever noticing. Here, we present a new architecture, MiSINFO, that not only thwarts such attacks but also enables the victim to counter-attack by spoofing of eavesdroppers with audio misinformation. With emerging attacks targeting the physical medium, i.e., acoustic signals, which cannot be protected by digital encryption and are the weakest segment of the communication chain, MiSINFO aims to systematically modify the eavesdroppers' fundamental sensing observations, concealing native signals while encoding alternate synthetic data. MiSINFO incorporates a low-profile, reconfigurable metasurface and double-inference principles to dynamically generate artificial audio-vibration signatures, injecting deceptive misinformation. We design, implement, and experimentally evaluate MiSINFO. Our results reveal that eavesdroppers detect none of the original words emitted by the speaker, while the injected misinformation is reconstructed with a low average word error rate of 2.29%. Our work represents the first such eavesdropping countermeasure which not only prevents attackers from accurately decoding the true signal but also uses a false signal to fool them into believing that they have succeeded. This approach transforms defensive measures from merely reactive to proactively deceptive, giving the defender an advantage and the capability to delude attackers into trusting false information. Zhambyl Shaikhanov, Mahmoud Al-Madi, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Daniel M. Mittleman, Edward W. Knightly |
SP | 6 |
| 2025 | Demo: Fooling Eavesdroppers via On-Phone Metasurface and Spoofed Audio InformationabstractWireless eavesdropping on phone conversations has become a major security concern as attackers repurpose advanced wireless capabilities in 5G and beyond featuring higher frequencies and higher sensing resolution. Recent studies have demonstrated that attackers can exploit off-the-shelf millimeter-wave radars to covertly detect even micron-scale vibrations of smartphones caused by the earpiece during the phone conversation, eavesdropping on audio information without the victim ever noticing. In our IEEE S&P'25 paper, we present a new architecture that not only thwarts such attacks but also injects false signatures to fool eavesdroppers into believing they have succeeded. Here, we demonstrate the eavesdropping countermeasure technique that enables the user to hide his private acoustic signals and simultaneously inject an alternative signal via a low-profile, reconfigurable metasurface. We present a metasurface-based audio encoding method that generates artificial audio-vibration signatures to send deceptive audio information to eavesdroppers. We showcase experimental audio samples from both the attack and the proposed countermeasure, which transforms defensive strategies from merely reactive to proactively deceptive. Zhambyl Shaikhanov, Mahmoud Al-Madi, Jy-Chin Liao, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Daniel M. Mittleman, Edward W. Knightly |
WISEC | 7 |
| 2025 | RISnet: A Domain-Knowledge Driven Neural Network Architecture for RIS Optimization With Mutual Coupling and Partial CSIabstractspace-division multiple access (SDMA) plays an important role in modern wireless communications. Its performance depends on the channel properties, which can be improved by reconfigurable intelligent surfaces (RISs). In this work, we jointly optimize SDMA precoding at the base station (BS) and RIS configuration. We tackle difficulties of mutual coupling between RIS elements, scalability to more than 1000 RIS elements, and high requirement for channel estimation. We first derive an RIS-assisted channel model considering mutual coupling, then propose an unsupervised machine learning (ML) approach to optimize the RIS with a dedicated neural network (NN) architectureRISnet, which has good scalability, desired permutation-invariance, and a low requirement for channel estimation. Moreover, we leverage existing high-performance analytical precoding scheme to propose a hybrid solution of ML-enabled RIS configuration and analytical precoding at BS. More generally, this work is an early contribution to combine ML technique and domain knowledge in communication for NN architecture design. Compared to generic ML, the problem-specific ML can achieve higher performance, lower complexity and permutation-invariance. Bile Peng, Karl-Ludwig Besser, Shanpu Shen, Finn Siegismund-Poschmann, Ramprasad Raghunath, Daniel M. Mittleman, Vahid Jamali, Eduard A. Jorswieck |
IEEE Trans. Wirel. Commun. | 6 |
| 2024 | One-Shot Localization with Random WavefrontsabstractThe next generation of wireless networks will utilize highly directional beams to overcome the path loss at high frequencies, requiring angle inference during link establishment. Furthermore, the integration of location-based services into the wireless infrastructure is rapidly increasing, bringing in a significant demand for an integrated fast localization scheme. In this work, we present a first-of-its-kind one-shot angular localization method that is carried out with a re-configurable architecture that unlocks ISAC functionality. Specifically, we use an electrically tunable metasurface with broadband response to generate wavefronts that are randomized across the angular space with diverse wideband amplitude and phase observations, corresponding to a collection of angle-unique one-shot beacons. Our results show down to 0.26° mean absolute error at 20 dB SNR, an order of magnitude improvement over the recently proposed one-shot solutions based on leaky-wave antennas (LWAs), in addition to having wider area coverage and less stringent bandwidth requirements. Burak Bilgin, Jy-Chin Liao, Hou-Tong Chen, Chun-Chieh Chang, Sadhvikas Addamane, Michael P. Lilly, Daniel M. Mittleman, Edward W. Knightly |
MobiCom | 7 |
| 2024 | MetaFly: Wireless Backhaul Interception via Aerial Wavefront ManipulationabstractWireless backhaul links, already ubiquitous and expanding further with 5G and beyond, are employed for many critical functions, such as financial trading on Wall Street. In this work, we demonstrate for the first time that such links are acutely vulnerable to a new class of aerial metasurface attacks. In particular, we show how an adversary Eve designs and employs MetaFly to covertly manipulate the electromagnetic wavefront of the signals and remotely eavesdrop on highly directional backhaul links. Exploring the foundation of the attack, we demonstrate Eve’s strategy for generating eavesdropping diffraction beams by inducing pre-defined phase profiles at the aerial metasurface interface. We also show how Eve’s flight navigation approach can dynamically shape radiation patterns based on drone mobility via a wavefront-tailored flight refinement principle. We prototype MetaFly and demonstrate Eve’s lightweight, low-cost, transmissive, and power-free aerial metasurface. We implement the attack and perform a suite of over-the-air experiments in both a large indoor atrium and outdoor rooftops in a large metropolitan area. The results reveal that armed with MetaFly, Eve can intercept backhaul transmissions with nearly zero bit error rate while maintaining minimal impact on legitimate communication. Zhambyl Shaikhanov, Sherif Badran, Hichem Guerboukha, Josep Miquel Jornet, Daniel M. Mittleman, Edward W. Knightly |
SP | 5 |
| 2024 | Guest Editorial: Introduction to the Special Issue on Electromagnetic Signal and Information Theory for CommunicationsabstractTo accommodate extremely high data rates, provide high reliability, improve coverage, and meet traffic demands in future wireless communication networks, novel technologies have emerged that exploit electromagnetic waves, large multiple-antenna systems, intelligent reflective surfaces, hardware innovations, new network architectures, and higher frequency bands. Considering advances in information theory and devices, fundamental questions arise for system designers on how to develop synergies between theory and practice. Current design and analysis methods are predominantly based on scalar-quantity, far-field, planar-wavefront, monochromatic, and other non-physically consistent assumptions, which can lead to significant mismatches with systems designed based on realistic propagation models. Kumar Vijay Mishra, Rodrigo C. de Lamare, Michail Matthaiou, Gerhard Kramer, Edward W. Knightly, Daniel M. Mittleman |
IEEE J. Sel. Areas Commun. | 6 |
| 2024 | Security and Angle-Frequency Coupling in Terahertz WLANsabstractThis paper presents the first security study of THz networks employing antennas with the angle-frequency coupling property. Using Leaky Wave Antennas (LWAs) as a representative, we explore the unique security properties due to the frequency-dependent radiation. We show via both analytical models and over-the-air experiments that LWA links exhibit non-uniform secrecy capacity across sub-channels, yielding advantages to an eavesdropper at edge frequencies. Yet, because different frequencies emit towards different angles, the eavesdropper is thwarted from easily intercepting an entire wideband transmission. The experiments diverge from the analytical model in that the model underpredicts the eavesdropper’s advantage at angles smaller than the target user and subsequent asymmetric performance across angles. Nonetheless, both the model and measurements show that increasingly wide bandwidth and correspondingly wide beams have only a modest marginal security penalty. Further, we find the LWA link secrecy not only depends on the target user angle (due to nonlinearity of LWA’s frequency-angle coupling), but also the beamwidth of the frequency components that constitute the collective LWA transmission. Chia-Yi Yeh, Yasaman Ghasempour, Yasith Amarasinghe, Daniel M. Mittleman, Edward W. Knightly |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | Securing Angularly Dispersive Terahertz Links With CodingabstractWith the large bandwidths available in the terahertz regime, directional transmissions can exhibit angular dispersion, i.e., frequency-dependent radiation direction. Unfortunately, angular dispersion introduces new security threats as increased bandwidth necessarily yields a larger signal footprint in the spatial domain and potentially benefits an eavesdropper. This paper is the first study of secure transmission strategies on angularly dispersive links. Based on information theoretic foundations, we propose a transmission strategy that channelizes the wideband transmission in frequency, and performs secure coding across frequency channels. With model-driven evaluations and over-the-air experiments, we show that the proposed method exploits the properties of angular dispersion to realize secure wideband transmissions, despite the increased signal footprint and even for practical irregular beams with side lobes and asymmetry. In contrast, without the proposed cross-channel coding strategy, angularly dispersive links can suffer from significant security degradation when bandwidth increases. In addition, we find that the security degradation due to bandwidth increment for angularly dispersive links is secondary compared to other factors including the selected secrecy rate or the directivity of the link. Nonetheless, we find that a higher angular dispersion level, i.e., a larger angular spread with the same bandwidth, results in a higher security degradation as bandwidth increases. Chia-Yi Yeh, Alejandro Cohen, Rafael Gregorio Lucas D'Oliveira, Muriel Médard, Daniel M. Mittleman, Edward W. Knightly |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Quasi-optical 3D localization using asymmetric signatures above 100 GHzabstractThe spectrum above 100 GHz has the potential to enable accurate 3D wireless localization due to the large swath of available spectrum. Yet, existing wide-band localization systems utilize the time of arrival measurements requiring strict time synchronization. In this paper, we present 123-LOC, a novel non-coherent system for one-shot dual-polarized 3D localization above 100 GHz. Our key idea is to create unique asymmetric THz fingerprints in 3D so that a wireless node can jointly infer its angular position and distance by taking hints from the measured power-spectrum profile. We introduce a dual-polarized dual-slit waveguide structure that emits out signals into free-space with a key feature that the beam pattern depends on the frequency of the signal and the geometry of the slit. To distinguish the emissions from the two slits, we use polarization diversity and manipulate the aperture geometry of the two slits so that they transmit slightly different angular-spectral signatures. Our over-the-air experiments demonstrate that 123-LOC achieves an average angle estimation error of 1° together with millimeter-scale ranging resolution, solely through non-coherent power measurements. Atsutse Kludze, Rabi Shrestha, Chowdhury Miftah, Edward W. Knightly, Daniel M. Mittleman, Yasaman Ghasempour |
MobiCom | 5 |
| 2022 | Metasurface-in-the-Middle Attack: From Theory to ExperimentabstractMetasurfaces enable controllable manipulation of electromagnetic waves and have been shown to improve wireless communications in many diverse ways. In this paper, we define and experimentally demonstrate for the first time a "MetaSurface-in-the-Middle'' (MSITM) attack. In this attack, the adversary Eve places a metasurface in the path of a directive transmission between Alice and Bob and targets to re-direct a portion of the signal towards herself, without being detected. In particular, we show how Eve can design a metasurface that induces abrupt phase changes at the interface of the metasurface to controllably diffract directional links and establish furtive eavesdropping links. We explore the theoretical foundations of the MSITM attack and demonstrate that an effective metasurface can be prototyped in under 5 min at the cost of several cents. We experimentally demonstrate the attack in a THz time-domain system and perform a set of over-the-air experiments. Our results indicate that the MSITM attack yields an acute vulnerability that can significantly reduce empirical secrecy capacity while leaving a minimal energy footprint, making the attack challenging to detect. Zhambyl Shaikhanov, Fahid Hassan, Hichem Guerboukha, Daniel M. Mittleman, Edward W. Knightly |
WISEC | 4 |
| 2022 | Adversarial Metasurfaces: Metasurface-in-the-Middle AttackabstractMetasurfaces enable controllable manipulation of electromagnetic waves and have been shown to improve wireless communications in many diverse ways. Investigating adversarial metasurfaces, we define and experimentally demonstrate for the first time a "MetaSurface-in-the-Middle'' (MSITM) attack in our paper \citeshaikhanov2022MSITM. In the attack, the adversary Eve places a metasurface in the path of a directive transmission between Alice and Bob and targets to re-direct a portion of the signal towards herself, without being detected. Here, we demonstrate the rapid fabrication of the MSITM employing only standard office supplies such as a printer, paper, foil, and laminator. We show that an effective metasurface can be prototyped in under $5$ min at the cost of several cents. We also demo the attack implementation in the THz network, presenting a video of the MSITM attacker establishing a diffractive eavesdropping link while maintaining the legitimate Alice-Bob link. Our results indicate that the attack yields an acute eavesdropping vulnerability while leaving a minimal energy footprint, making the attack challenging to detect. Zhambyl Shaikhanov, Fahid Hassan, Hichem Guerboukha, Daniel M. Mittleman, Edward W. Knightly |
WISEC | 4 |
| 2022 | Angularly Dispersive Terahertz Links with Secure Coding: From Theoretical Foundations to ExperimentsabstractWith the large bandwidths available in the terahertz regime, directional transmissions can exhibit angular dispersion, i.e., frequency-dependent radiation direction. Unfortunately, angular dispersion introduces new security threats as increased bandwidth necessarily yields a larger signal footprint in the spatial domain and potentially benefits an eavesdropper. This paper is the first study of secure transmission strategies on angularly dispersive links. Based on information theoretic foundations, we propose to channelize the wideband transmission in frequency, and perform secure coding across frequency channels. With over-the-air experiments, we show that the proposed method exploits the properties of angular dispersion to realize secure wideband transmissions, despite the increased signal footprint and even for practical irregular beams with side lobes and asymmetry. In contrast, without the proposed cross-channel coding strategy, angularly dispersive links can suffer from significant security degradation when bandwidth increases. Chia-Yi Yeh, Alejandro Cohen, Rafael Gregorio Lucas D'Oliveira, Muriel Médard, Daniel M. Mittleman, Edward W. Knightly |
WISEC | 5 |
| 2020 | Single shot single antenna path discovery in THz networksabstractTHz communication has the potential to realize an order of magnitude increase in data rates due to the availability of wide THz-scale spectral bands. Unfortunately, establishing and managing highly directional beams in THz networks is challenging as links lack the "pseudo-omni" reception capability of lower bands and the product of AP-client beam resolution is high due to narrow beams of only a few degrees. In this paper, we present One-shot Path discovEry with a THz RAinbow (OPERA), a novel system that identifies dominant paths between the AP and all clients in order to efficiently steer directional beams. The key idea is to embed path direction into the inherent characteristics of signals traveling along each path. To do so, we exploit a single leaky wave antenna and create a THz Rainbow. A THz Rainbow transmission consists of distinct signals with unique spectral characteristics across the angular domain. Leveraging the spatial-spectral signatures in the THz Rainbow, all receivers can correlate the measured signal with the known transmission signatures to discover the sender's path directions in one-shot. Our experiments demonstrate that OPERA achieves average direction estimates within 2° of ground truth for LOS and reflected paths. Yasaman Ghasempour, Chia-Yi Yeh, Rabi Shrestha, Daniel M. Mittleman, Edward W. Knightly |
MobiCom | 4 |
| 2020 | LeakyTrack: non-coherent single-antenna nodal and environmental mobility tracking with a leaky-wave antennaabstractRadio frequency signals have the potential to convey rich information about a node's motion and surroundings. Unfortunately, extracting such information is challenging, previously requiring accurate phase measurement, large antenna array structures, or extensive training. In this paper, we present LeakyTrack, a novel system that enables non-coherent and training-free motion sensing with a single antenna. The key idea is to create unique spectrally coded signals at different spatial directions so that geometric properties of the receiving node, as well as any potential objects in the environment, leave spectral footprints on the collected signal. To do so, we exploit a THz leaky-wave antenna and realize a color-coded scan in which signals with distinct spectral characteristics simultaneously emit across the angular domain. LeakyTrack infers nodal and environmental motion by analyzing the received spectral profile. We evaluate the performance of LeakyTrack via extensive over-the-air experiments. Yasaman Ghasempour, Chia-Yi Yeh, Rabi Shrestha, Yasith Amarasinghe, Daniel M. Mittleman, Edward W. Knightly |
SenSys | 5 |
| 2020 | Security in terahertz WLANs with Leaky wave antennasabstractThis paper presents the first security study of THz networks with Leaky Wave Antennas (LWAs). We employ a mix of analytical models and over-the-air experiments to explore the unique security properties of LWA links. We show via both models and experiments that the LWA's angle-frequency coupling leads to non-uniform secrecy capacity across sub-channels yielding advantages to an eavesdropper at edge frequencies. Yet, because different frequencies emit energy at different angles, the eavesdropper is thwarted from easily intercepting an entire wideband transmission. The experiments diverge from the analytical model in that the model underpredicts the eavesdropper's advantage at angles smaller than the target user and subsequent asymmetric performance across angles. Nonetheless, both the model and measurements show that increasingly wide bandwidth and correspondingly wide beams have only a modest marginal security penalty. Chia-Yi Yeh, Yasaman Ghasempour, Yasith Amarasinghe, Daniel M. Mittleman, Edward W. Knightly |
WISEC | 4 |
| 2007 | Finite-Element Method Simulations of Guided Wave Phenomena at Terahertz FrequenciesabstractAs the science and engineering associated with terahertz time-domain spectroscopy and imaging evolves past the use of conventional free-space optics, the continued development of waveguides for terahertz pulses is increasingly relevant. The ability to model and simulate terahertz wave propagation aids in the development, visualization, and understanding of novel terahertz devices and phenomena. We discuss the use of the finite-element method, a powerful computational tool for the modeling of guided wave phenomena and devices at terahertz frequencies. Jason A. Deibel, Matthew Escarra, Nicholas Berndsen, Kanglin Wang, Daniel M. Mittleman |
Proc. IEEE | 5 |
| 2000 | Imaging with THZ PulsesabstractA real-time imaging system based on terahertz (THz) time-domain spectroscopy has been demonstrated. This technique offers a range of unique imaging modalities due to the broad bandwidth, sub-picosecond duration, and phase-sensitive detection of the THz pulses. This paper provides an introduction of the state-of-the art in THz imaging. It also focuses on expanding the potential of this new and exciting field through two major efforts. The first concentrates on improving the experimental sensitivity of the system. We are exploring an interferometric arrangement to provide a background-free reflection imaging geometry. The second applies novel digital signal processing algorithms to extract useful information from the THz pulses. The possibility exists to combine spectroscopic characterization and/or identification with pixel-by-pixel imaging. Timothy Dorney, Jon Johnson, Daniel M. Mittleman, Richard G. Baraniuk |
ICIP | 3 |