Juchuan Zhang

dblp:220/2463 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
6since 2021 · last 2024
0000-0001-7319-7535ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 3 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2024 CapSpeaker: Injecting Commands to Voice Assistants Via Capacitors
abstract
Recent studies have exposed that voice assistants can be manipulated by various voice commands without being noticed, however, existing attacks require a nearby speaker to play the attack commands. In this paper, we demonstrate that even without a speaker, we can use capacitors inside electronic devices to produce malicious voice commands, i.e., we convert capacitors into speakers and call itCapSpeaker. The underlying principle ofCapSpeakeris the inverse piezoelectric effect, i.e., varying the voltage across a capacitor to make it vibrate and thus emit acoustic noises. Forcing capacitors to emit target voice commands is challenging because (1) capacitors' response frequency is out of the range of audible voices. (2) We can not directly control the voltage across capacitors to manipulate their emit sounds. To overcome these challenges, we propose a PWM-based modulation scheme to embed the malicious audio onto a high-frequency carrier, e.g., above 20 kHz, and we create malware to induce the designed voltage across the capacitors such thatCapSpeakerplays the chosen malicious commands. Our evaluation of 7 commercial devices demonstrates thatCapSpeakeris feasible to inject voice commands, e.g., ”open the door”, at a distance of up to 10.5 cm.
Xiaoyu Ji 0001, Juchuan Zhang, Yancheng Jiang, Shui Jiang, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.3
2024 MagView++: Data Exfiltration via CPU Magnetic Signals Under Video Decoding
abstract
Air-gapped networks achieve security by using physical isolation to keep the computers and network from the Internet. However, magnetic covert channels based on CPU utilization have been proposed to help secret data to exfiltrate from the Faraday-cage and the air gap. Despite the success of such covert channels, they suffer from the high risk of being detected by the transmitter computer and the challenge of installing malware into such a computer. In this article, we proposeMagView++, where sensitive information is embedded in other data such as video and can be transmitted over the internal network. When any computer uses the data such as playing the video, the sensitive information will leak through the magnetic signals. The “separation” of information embedding and leaking, combined with the fact that the data can be exfiltrated from any computer in a distributed manner, overcomes these limitations. We demonstrate that CPU utilization for video decoding can be effectively controlled by changing the video frame type, reducing the quantization parameter, and changing the timestamp of the frame, without video quality degradation. We prototypeMagView++and achieve 8.9 bps throughput with 0.0057 BER when using a smartphone as the receiver, and 59 bps throughput with 0.0025 BER when using a dedicated devices with high sampling rate as the receiver. Experiments under various environments are conducted to show the robustness ofMagView++. Limitations and possible countermeasures are also discussed.
Xiaoyu Ji 0001, Juchuan Zhang, Shan Zou, Yi-Chao Chen 0001, Gang Qu 0001, Wenyuan Xu 0001
IEEE Trans. Mob. Comput.2
2022 OutletGuarder: Detecting DarkSide Ransomware by Power Factor Correction Signals in an Electrical Outlet
abstract
Ransomware is a kind of computer malware that has spread widely in recent years, such as DarkSide, which spread around the world recently. It’s reported that DarkSide extorted ${\$}$ 90 million in nine months. It extorts ransom from users by encrypting user files and other methods, causing huge economic losses to users, including commercial organizations and individuals. Existing ransomware detection methods include the hostbased methods and the network-based methods. However, these methods are either hard to deploy or have the possibility to be evaded. In this paper, we propose OutletGuarder, a non-intrusive detection method against DarkSide ransomware based on the signal generated by the Power Factor Correction module of the host computer’s power supply in electrical outlets, which carries the power consumption information of the host computer during the execution of DarkSide. By utilizing the power consumption variation among different programs, especially the power consumption caused by frequent encryption and I/O operations during the execution of DarkSide, OutletGuarder achieves a detection F1 Score of 97.50%. The impact of classification models and untrained programs, as well as the model transferability and robustness are evaluated.
Shan Zou, Juchuan Zhang, Shui Jiang, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001
ICPADS2
2022 Device Fingerprinting with Magnetic Induction Signals Radiated by CPU Modules
abstract
With the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally measured device fingerprints, such as device ID, software or hardware-based characteristics. In this article, we propose DeMiCPU , a stimulation-response-based device fingerprinting technique that relies on externally measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power-supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.7% precision and recall on average, and 99.8% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6~s. The performance can be further improved to 99.9% with multi-round fingerprinting. In addition, we implement a prototype of DeMiCPU docker, which can effectively reduce the requirement of test points and enlarge the fingerprinting area.
Xiaoyu Ji 0001, Yushi Cheng, Juchuan Zhang, Yuehan Chi, Wenyuan Xu 0001, Yi-Chao Chen 0001
ACM Trans. Sens. Networks3
2021 CapSpeaker: Injecting Voices to Microphones via Capacitors
abstract
Voice assistants can be manipulated by various malicious voice commands, yet existing attacks require a nearby speaker to play the attack commands. In this paper, we show that even when no speakers are available, we can play malicious commands by utilizing the capacitors inside electronic devices, i.e., we convert capacitors into speakers and call it CapSpeaker. Essentially, capacitors can emit acoustic noises due to the inverse piezoelectric effect, i.e., varying the voltage across a capacitor can make it vibrate and thus emit acoustic noises. Forcing capacitors to play malicious voice commands is challenging because (1) the frequency responses of capacitors as speakers have poor performance in the range of audible voices, and (2) we have no direct control over the voltage across capacitors to manipulate their emitting sounds. To overcome the challenges, we use a PWM-based modulation scheme to embed the malicious audio onto a high-frequency carrier, e.g., above 20 kHz, and we create malware that can induce the right voltage across the capacitors such that CapSpeaker plays the chosen malicious commands. We conducted extensive experiments with 2 LED lamps (a modified one and a commercial one) and 5 victim devices (iPhone 4s, iPad mini 5, Huawei Nova 5i, etc.). Evaluation results demonstrate that CapSpeaker is feasible at a distance up to 10.5 cm, triggering a smartphone to receive voice commands, e.g., "open the door''.
Xiaoyu Ji 0001, Juchuan Zhang, Shui Jiang, Jishen Li, Wenyuan Xu 0001
CCS2
2021 OutletSpy: cross-outlet application inference via power factor correction signal
abstract
Trade secrets such as intellectual properties are the inherent values for firms. Although companies have exploited strict access management policies and isolated their networks from the public Internet, trade secrets are still vulnerable to side-channel attacks. Side-channels can reveal the computing processes of computers in forms of various physical signals such as light, electromagnetism, and even heat. Such side-channels can bypass the isolation mechanism and therefore bring about severe threats. However, existing side-channels can only perform well within a short-distance (e.g., less than 1 meter) due to the high attenuation of signals. In this paper, we seek to utilize the built-in power lines in a building and construct a power side-channel that enables remote, i.e., cross-outlet attack against trade secrets. To this end, we investigate the power factor correction (PFC) module inside the power supply units of commodity computers and find that the PFC signals observed from an outlet can precisely reveal the power consumption information of all the connected devices, even from the outlets in adjacent rooms. Based upon this insight, we design and implement OutletSpy, a power side-channel attack that can infer application launching from a remote outlet and therefore enjoys the stealthiness property. We validate and evaluate OutletSpy with a dataset under different background APPs, time variations and different locations. The experiment results show OutletSpy can infer the application launching with 98.25% accuracy.
Juchuan Zhang, Xiaoyu Ji 0001, Yuehan Chi, Yi-Chao Chen 0001, Bin Wang 0062, Wenyuan Xu 0001
WISEC1
2020 MagView: A Distributed Magnetic Covert Channel via Video Encoding and Decoding
abstract
Air-gapped networks achieve security by using the physical isolation to keep the computers and network from the Internet. However, magnetic covert channels based on CPU utilization have been proposed to help secret data to escape the Faraday-cage and the air-gap. Despite the success of such cover channels, they suffer from the high risk of being detected by the transmitter computer and the challenge of installing malware into such a computer. In this paper, we propose MagView, a distributed magnetic cover channel, where sensitive information is embedded in other data such as video and can be transmitted over the air-gapped internal network. When any computer uses the data such as playing the video, the sensitive information will leak through the magnetic covert channel. The "separation" of information embedding and leaking, combined with the fact that the covert channel can be created on any computer, overcomes these limitations. We demonstrate that CPU utilization for video decoding can be effectively controlled by changing the video frame type and reducing the quantization parameter without video quality degradation. We prototype MagView and achieve up to 8.9 bps throughput with BER as low as 0.0057. Experiments under different environment are conducted to show the robustness of MagView. Limitations and possible countermeasures are also discussed.
Juchuan Zhang, Xiaoyu Ji 0001, Wenyuan Xu 0001, Yi-Chao Chen 0001, Yuting Tang, Gang Qu 0001
INFOCOM1
2020 Authenticating Smart Home Devices via Home Limited Channels
abstract
Nowadays, most Internet of Things devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks such as spoofing and eavesdropping attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this article, we design a key-free communication method for such devices in a smart home. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for outside-house attackers. Utilizing HLCs, we propose HlcAuth, a challenge-response mechanism to authenticate the communications between smart devices without keys. The advantages of HlcAuth are low cost, lightweight as well as key-free, and requiring no human intervention. According to the security analysis, HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. We further evaluate HlcAuth in four different physical scenarios, and results show that HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers, i.e., guaranteeing a high-level usability and security for in-house communications. Finally, we implement HlcAuth in both single-room and multi-room scenarios.
Xiaoyu Ji 0001, Chaohao Li, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001
ACM Trans. Internet Things4
2019 DeMiCPU: Device Fingerprinting with Magnetic Signals Radiated by CPU
abstract
With the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally-measured device fingerprints, such as device ID, software or hardware-based characteristics. In this paper, we propose DeMiCPU, a stimulation-response-based device fingerprinting technique that relies on externally-measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.1% precision and recall on average, and 98.6% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6 s. In addition, the performance can be further improved to 99.9% with multi-round fingerprinting.
Yushi Cheng, Xiaoyu Ji 0001, Juchuan Zhang, Wenyuan Xu 0001, Yi-Chao Chen 0001
CCS3
2018 HlcAuth: Key-free and Secure Communications via Home-Limited Channel
abstract
Nowadays most IoT devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this paper we design a key-free communication method for such devices. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for an outside-house attacker. Utilizing HLCs, we propose a challenge-response mechanism to authenticate the communications inside a house. The advantages of the HlcAuth protocol are low cost, lightweight as well as key-free, and requiring no human intervention. We show that HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers.
Chaohao Li, Xiaoyu Ji 0001, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001
AsiaCCS4
2018 FBSleuth: Fake Base Station Forensics via Radio Frequency Fingerprinting
abstract
Fake base station (FBS) crime is a type of wireless communication crime that has appeared recently. The key to enforcing the laws on regulating FBS based crime is not only to arrest but also to convict criminals effectively. Much work on FBS discovering, localization, and tracking can assist the arresting, but the problem of collecting evidence accurately to support a proper conviction has not been addressed yet.
Zhou Zhuang, Xiaoyu Ji 0001, Taimin Zhang, Juchuan Zhang, Wenyuan Xu 0001, Zhenhua Li 0001, Yunhao Liu 0001
AsiaCCS4