Wenbo Ding 0003

dblp:22/10126-3 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
3since 2021 · last 2024
0009-0001-0867-2245ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2024 Command Hijacking on Voice-Controlled IoT in Amazon Alexa Platform
abstract
Voice Personal Assistants (VPA) are becoming popular entry points to control connected devices in an IoT environment, e.g., by invoking Amazon Alexa voice-apps (called skills) to turn on/off lights through voice commands. Amazon Alexa platform allows third-party developers to build skills and publish them to marketplaces, which greatly extends the functionalities of VPA. Despite the many convenient features, there are increasing security and safety concerns about VPA-controlled IoT systems. Previous research demonstrated the prevalence of potentially malicious or problematic skills in the marketplace. However, existing works mainly focus on non-IoT skills (e.g., skills under the Kids and Health categories). The security and safety risks of IoT skills are largely under-explored.
Wenbo Ding 0003, Song Liao, Long Cheng 0005, Xianghang Mi, Ziming Zhao 0001, Hongxin Hu
AsiaCCS1
2024 Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models
Keyan Guo, Ayush Utkarsh, Wenbo Ding 0003, Isabelle Ondracek, Ziming Zhao 0001, Guo Freeman, Nishant Vishwamitra, Hongxin Hu
USENIX Security Symposium3
2021 IoTSafe: Enforcing Safety and Security Policy with Real IoT Physical Interaction Discovery
Wenbo Ding 0003, Hongxin Hu, Long Cheng 0005
NDSS1
2018 On the Safety of IoT Device Physical Interaction Control
abstract
Emerging Internet of Things (IoT) platforms provide increased functionality to enable human interaction with the physical world in an autonomous manner. The physical interaction features of IoT platforms allow IoT devices to make an impact on the physical environment. However, such features also bring new safety challenges, where attackers can leverage stealthy physical interactions to launch attacks against IoT systems. In this paper, we propose a framework called IoTMon that discovers any possible physical interactions and generates all potential interaction chains across applications in the IoT environment. IoTMon also includes an assessment of the safety risk of each discovered inter-app interaction chain based on its physical influence. To demonstrate the feasibility of our approach, we provide a proof-of-concept implementation of IoTMon and present a comprehensive system evaluation on the Samsung SmartThings platform. We study 185 official SmartThings applications and find they can form 162 hidden inter-app interaction chains through physical surroundings. In particular, our experiment reveals that 37 interaction chains are highly risky and could be potentially exploited to impact the safety of the IoT~environment.
Wenbo Ding 0003, Hongxin Hu
CCS1