EDBT 2026 Demo / reviewers in the wild / expert
Chaohao Li
dblp:220/2509
· DBLP profile ↗
14ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0001-5975-3937ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 5 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DCAD: Dual-Condition Adaptive Consistency Model for IoT Privacy-Preserving Video Anomaly Detection
Shaopeng Zhou, Chaohao Li, Haonan Yan, Longlong Zhu, Chunming Wu 0001, Bin Wang 0062 |
ICIC (2) | 2 |
| 2025 | BTCD: Enabling Balanced Toxic Content Detection by Collaborating VLMs and CNNs
Yuantao Jia, Haonan Yan, Zhangyu Gu, Shaopeng Zhou, Chaohao Li |
PRCV (6) | 8 |
| 2025 | Imprints: Mitigating Watermark Removal Attacks With Defensive WatermarksabstractWatermark is essential for protecting the intellectual property of private images. However, a wide range of watermark removal attacks, especially many AI-powered ones, can automatically predict and remove watermarks, posing serious concerns. In this paper, we present the design ofImprints, a defensive watermarking framework that fortifies watermarks against watermark removal attacks. By formulating an optimization problem that deters watermark removal attacks, we design image-independent/dependent defensive watermark models for effective batch/customized protection. We further enhance the watermark to be transferable to unseen watermark removal attacks and robust to editing distortions. Extensive experiments verify thatImprintsoutperforms existing baselines in terms of its immunity to 8 state-of-the-art watermark removal attacks and 3 commercial black-box watermark removal software. The source code is available athttps://github.com/Imprints-wm/Imprints. Xiaofu Chen, Jiangyi Deng, Yanjiao Chen, Chaohao Li, Cong Liu 0006, Wenyuan Xu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | EL-FDL: Improving Image Forgery Detection and Localization via Ensemble Learning
Jingge Wang, Haonan Yan, Shaopeng Zhou, Chaohao Li |
ICANN (2) | 6 |
| 2024 | Toward Pitch-Insensitive Speaker Verification via SoundfieldabstractAutomatic speaker verification systems (ASVs) verify a person’s identity by his/her voice and have been widely deployed for user authentication. However, existing ASVs are based on traditional audio spectral features and hence, perform poorly in verifying pitch-changed utterances from speakers with cold or sore throat. In this article, we propose soundfield tracker(SOFTER), a soundfield-based speaker verification system that can verify speakers regardless of the pitch changes.SOFTERis based on the observation that soundfield features reflect the speaker’s vocal tract, mouth, head, torso, etc., which are less affected by the pitch changes in speech signals.SOFTERcan be integrated into off-the-shelf smartphones without any hardware modifications. One major challenge is that the soundfield is sensitive to the distance between the speaker and the phone. To solve this problem, we propose a two-stage mechanism combining distance sensing and soundfield reconstruction, which enables to reconstruct the soundfield to a setting similar to the one in the enrollment phase, thus, the speaker can be verified from any distance to the phone. We compareSOFTERwith six state-of-the-art academic and commercial ASVs on two data sets of 134 speakers and 31000 speech samples. Results show thatSOFTERhas an equal error rate (EER) of 2.18% and 1.61% on the two data sets, respectively. Moreover,SOFTERoutperforms other ASVs by at least 24.67% on average in verifying pitch-varying or pathological speech samples, denoting an evidence ofSOFTER’s effectiveness in both normal and unhealthy user conditions. Xinfeng Li, Zhicong Zheng, Chen Yan 0001, Chaohao Li, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Watch Your Speed: Injecting Malicious Voice Commands via Time-Scale ModificationabstractExisting adversarial example (AE) attacks against automatic speech recognition (ASR) systems focus on adding deliberate noises to input audio. In this paper, we propose a new attack that purely speeds up or slows down original audio instead of adding perturbations, and we call it Time-Scale Modification Adversarial Example (TSMAE). By investigating the impact of speed variation on 100, 000 pieces of audio clips, we found that misrecognition manifests in three categories: delete, substitution, and insertion. These are the accumulated results caused by the misrecognition of both the acoustic and language models inside an ASR system. Despite the challenges, i.e., ASR systems are typically black-box and reveal no gradient information, we managed to launch one-segment untargeted and targetedTSMAEattacks based on particle swarm optimization algorithms. Our untargeted attacks only require modifying the speed of one segment (e.g., 20 ms), and our targeted attacks can generate meaningful yet benign audio to cause an ASR system to output a malicious output, e.g., “open the door”. We validate the feasibility ofTSMAEon two open-source ASR models (e.g., DeepSpeech and Sphinx) and four commercial ones (e.g., IBM, Google, Baidu, and iFLYTEK). Results show that our untargeted attack can successfully attack all 6 ASR models with one segment modification, and our targeted attack is robust to various factors, such as model versions and speech sources. Finally, both attacks can bypass existing open-source defense methods, and our insights call attention to the defense’s focus from coping with perturbation to emerging adversarial example attacks. Xiaoyu Ji 0001, Qinhong Jiang, Chaohao Li, Zhuoyang Shi, Wenyuan Xu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Volttack: Control IoT Devices by Manipulating Power Supply VoltageabstractThis paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing and actuating. Particularly, we discover a vulnerability in power supply modules and propose Volttack attacks. To launch a Volttack attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Eventually, Volttack attacks may cause the sensor measurement irrelevant to reality or maneuver the actuator in a way disregarding the desired command. To understand Volttack, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensor or actuator modules. Derived from these findings, we implement and validate Volttack on off-the-shelf products: 6 sensors and 3 actuators, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The consequences of manipulating the sensor measurement or actuation include doubled car braking distance and a natural gas leak. The root cause of such a vulnerability stems from the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks. Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Wenyuan Xu 0001 |
SP | 5 |
| 2023 | DeHiREC: Detecting Hidden Voice Recorders via ADC Electromagnetic RadiationabstractUnauthorized covert voice recording brings a remarkable threat to privacy-sensitive scenarios, such as confidential meetings and private conversations. Due to the miniaturization and disguise characteristics, hidden voice recorders are difficult to be noticed in their surroundings. In this paper, we present DeHiREC, the first proof-of-concept system that can detect offline hidden voice recorders from their electromagnetic radiations (EMR). We first characterize the unique patterns of the emanated EMR signals and then locate the EMR source, i.e., the analog-to-digital converter (ADC) module embedded in the mixed signal system-on-chips (MSoCs). Since these unintentional EMR signals can be extremely noisy and weak, accurately detecting them can be challenging. To address this challenge, we first design an EMR Catalyzing method to stimulate the EMR signals actively and then employ an adaptive-folding algorithm to improve the signal-to-noise ratio (SNR) of the sensed EMRs. Once the sensed EMR variation corresponds to our active stimulation, we can determine that there exists a hidden voice recorder. We evaluate the performance of DeHiREC on 13 commercial voice recorders under various impacts, including interference from other devices. Experimental results reveal that DeHiREC is effective in detecting all 13 voice recorders and achieves an overall success rate of 92.17% and a recall rate of 86.14% at a distance of 0.2 m. Ruochen Zhou, Xiaoyu Ji 0001, Chen Yan 0001, Yi-Chao Chen 0001, Wenyuan Xu 0001, Chaohao Li |
SP | 6 |
| 2023 | Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice Attacks
Xinfeng Li, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Zhenning Zhang, Wenyuan Xu 0001 |
USENIX Security Symposium | 4 |
| 2021 | Anti-Replay: A Fast and Lightweight Voice Replay Attack Detection SystemabstractDue to the open nature of voice and voice interface, attackers can easily record the user's voice commands and spoof the voice recognition systems by replaying them. Existing voice replay attack detection methods mainly rely on extra hardware to determine the sound source or require excessively computing resources for training the classifier with a large number of acoustic features. Hence, we propose Anti-Replay, a fast and lightweight detection system for voice replay attacks. To overcome the challenge of redundant classification feature vectors and complex calculation, we first investigate the spectrum difference between live-human voice and the replayed audio caused by the non-linear distortion of the attacker's microphones and speakers and then extract 72-dimensional feature vectors. Then we employ a single deep convolutional neural network classifier (SE-ResNet50) to enhance the robustness of our classification model. Finally, we evaluate the performance of Anti-Replay on the datasets of ASVspoof2017 and ASVspoof2019. Results show that Anti-Replay can achieve an equal error rate (EER) of 2.38% and 0.82% on two datasets, respectively. Meanwhile, the training time and the model size of Anti-Replay have decreased by 56% and 84% compared with the baseline model (i.e., CQCC-GMM). Zhuoyang Shi, Chaohao Li, Zizhi Jin, Weinong Sun, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICPADS | 2 |
| 2021 | SenCS: Enabling Real-time Indoor Proximity Verification via Contextual SimilarityabstractIndoor proximity verification has become an increasingly useful primitive for the scenarios where access is granted to the previously unknown users when they enter a given area (e.g., a hotel room). Existing solutions either rely on homogeneous sensing modalities shared by two parties or require additional human interactions. In this article, we propose a context-based indoor proximity verification scheme, called SenCS, to enable real-time autonomous access for mobile devices, utilizing the available heterogeneous sensors at the user side and at the room side. The intuition is that only when the user is within a room can sensors from both sides observe the same events in the room. Yet such a solution is challenging, because the events may not provide enough entropy within the required time and the heterogeneity in sensing modalities may not always agree on the sensed events. To overcome the challenges, we exploit the time intervals between successively human actions to create heterogeneous contextual fingerprints (HCF) at a millisecond level. By comparing the contextual similarity between the HCF s from both the room and user sides, SenCS accomplishes the indoor proximity verification. Through proof-of-concept implementation and evaluations on 30 participants, SenCS achieves an accuracy of 99.77% and an equal error rate (EER) of 0.23% across various hardware configurations. Chaohao Li, Xiaoyu Ji 0001, Bin Wang 0062, Kai Wang 0073, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 1 |
| 2020 | Authenticating Smart Home Devices via Home Limited ChannelsabstractNowadays, most Internet of Things devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks such as spoofing and eavesdropping attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this article, we design a key-free communication method for such devices in a smart home. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for outside-house attackers. Utilizing HLCs, we propose HlcAuth, a challenge-response mechanism to authenticate the communications between smart devices without keys. The advantages of HlcAuth are low cost, lightweight as well as key-free, and requiring no human intervention. According to the security analysis, HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. We further evaluate HlcAuth in four different physical scenarios, and results show that HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers, i.e., guaranteeing a high-level usability and security for in-house communications. Finally, we implement HlcAuth in both single-room and multi-room scenarios. Xiaoyu Ji 0001, Chaohao Li, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001 |
ACM Trans. Internet Things | 2 |
| 2018 | HlcAuth: Key-free and Secure Communications via Home-Limited ChannelabstractNowadays most IoT devices in smart homes rely on radio frequency channels for communication, making them exposed to various attacks. Existing methods using encryption keys may be inapplicable on these resource-constrained devices that cannot afford the computationally expensive encryption operations. Thus, in this paper we design a key-free communication method for such devices. In particular, we introduce the Home-limited Channel (HLC) that can be accessed only within a house yet inaccessible for an outside-house attacker. Utilizing HLCs, we propose a challenge-response mechanism to authenticate the communications inside a house. The advantages of the HlcAuth protocol are low cost, lightweight as well as key-free, and requiring no human intervention. We show that HlcAuth can defeat replay attacks, message-forgery attacks, and man-in-the-middle (MiTM) attacks, among others. HlcAuth achieves 100% true positive rate (TPR) within 4.2m for in-house devices while 0% false positive rate (FPR) for outside attackers. Chaohao Li, Xiaoyu Ji 0001, Juchuan Zhang, Yanmiao Zhang, Wenyuan Xu 0001 |
AsiaCCS | 1 |
| 2018 | Blue Note: How Intentional Acoustic Interference Damages Availability and Integrity in Hard Disk Drives and Operating SystemsabstractIntentional acoustic interference causes unusual errors in the mechanics of magnetic hard disk drives in desktop and laptop computers, leading to damage to integrity and availability in both hardware and software such as file system corruption and operating system reboots. An adversary without any special purpose equipment can co-opt built-in speakers or nearby emitters to cause persistent errors. Our work traces the deeper causality of these risks from the physics of materials to the I/O request stack in operating systems for audible and ultrasonic sound. Our experiments show that audible sound causes the head stack assembly to vibrate outside of operational bounds; ultrasonic sound causes false positives in the shock sensor, which is designed to prevent a head crash. The problem poses a challenge for legacy magnetic disks that remain stubbornly common in safety critical applications such as medical devices and other highly utilized systems difficult to sunset. Thus, we created and modeled a new feedback controller that could be deployed as a firmware update to attenuate the intentional acoustic interference. Our sensor fusion method prevents unnecessary head parking by detecting ultrasonic triggering of the shock sensor. Connor Bolton, Sara Rampazzi, Chaohao Li, Andrew Kwong, Wenyuan Xu 0001, Kevin Fu |
IEEE Symposium on Security and Privacy | 3 |