EDBT 2026 Demo / reviewers in the wild / expert
Sihan Yu
dblp:256/2098
· DBLP profile ↗
9ranked-venue papers
4as first author
7since 2021 · last 2024
0000-0001-8798-3051ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 2 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | FreeEM: Uncovering Parallel Memory EMR Covert Communication in Volatile EnvironmentsabstractMemory Electromagnetic Radiation (EMR) allows attackers to manipulate the DRAM of infiltrated systems to leak sensitive secret information. Although most of the existing works have demonstrated its feasibility, practical concerns, such as the ideal electromagnetic environment and stationary attacking layout, make the covert channel attack less convincing, especially in vulnerable sites such as offices and data centers. This work removes the above impractical assumptions to uncover the potential of memory EMR by proposing the first parallel EMR covert communication protocol. Our design reshapes the current "1-to-1" covert communication mode to "n-to-1" mode via a novel pattern-based 2-dimensional symbol encoding scheme, allowing multiple victim computers to simultaneously perform data exfiltration to one attacker (the receiver) without mutual interference. Meanwhile, this novel scheme design also enables the very first mobile attacker, i.e., a smartphone connected to a software-defined radio (SDR) dongle, to capture parallel memory EMR signals in a volatile environment. Extensive experiments are conducted to verify the performance in a volatile environment with different parameter configurations, distances, motion modes, shielding materials, orientations, hardware configurations, and SDR platforms. Our experimental results demonstrate that FreeEM can support up to 4 parallel memory EMR transmissions to achieve an overall throughput of 625Kbps and a decoding accuracy of 96.88%. The maximum communication distance can reach up to 20 meters. Sihan Yu, Jingjing Fu, Chenxu Jiang, ChunChih Lin, Zhenkai Zhang 0002, Long Cheng 0005, Ming Li 0006, Xiaonan Zhang 0001, Linke Guo |
MobiSys | 1 |
| 2024 | Behaviors Speak More: Achieving User Authentication Leveraging Facial Activities via mmWave SensingabstractHuman faces have been widely adopted in many applications and systems requiring a high-security standard. Although face authentication is deemed to be mature nowadays, many existing works have demonstrated not only the privacy leakage of facial information but also the success of spoofing attacks on face biometrics. The critical reason behind this is the failure of liveness detection in biometrics. This work advances most biometric-based user authentication schemes by exploring dynamic biometrics (human facial activities) rather than traditional static biometrics (human faces). Inspired by observations from psychology, we propose the mmFaceID to leverage humans' dynamic facial activities when performing word reading for achieving robust, highly accurate, and effective user authentication via mmWave sensing. By addressing a series of technical challenges of capturing micro-level facial muscle movements using a mmWave sensor, we build a neural network to reconstruct facial activities via estimated expression parameters. Then, unique features can be extracted to enable robust user authentication regardless of relative distances and orientations. We conduct comprehensive experiments on 23 participants to evaluate mmFaceID in terms of distances/orientations, length of word lists, occlusion, and language backgrounds, demonstrating an authentication accuracy of 94.7%. We also extend our evaluation in a real IoT scenario. By speaking real IoT commends, the average authentication accuracy can reach up to 92.28%. Chenxu Jiang, Sihan Yu, Jingjing Fu, ChunChih Lin, Huadi Zhu, Ming Li 0006, Linke Guo |
SenSys | 2 |
| 2023 | Signal Emulation Attack and Defense for Smart Home IoTabstractInternet of Things (IoT) is transforming every corner of our daily life and plays important roles in the smart home. Depending on different requirements on wireless transmission, dedicated wireless protocols have been adopted on various types of IoT devices. Recent advances in Cross-Technology Communication (CTC) enable direct communication across those wireless protocols, which will greatly improve the spectrum utilization efficiency. However, it incurs serious security concerns on heterogeneous IoT devices. In this paper, we identify a new physical-layer attack, cross-technology signal emulation attack, where a WiFi device eavesdrops a ZigBee packet on the fly, and further manipulates the ZigBee device by emulating a ZigBee signal. To defend against this attack, we propose two defense strategies with the help of a commonly found WiFi router. Particularly, the passive defense strategy focuses on misleading the ZigBee signal eavesdropping, while the proactive approach develops a real-time detection mechanism on distinguishing between a common ZigBee signal and an emulated signal. We implement the complete attacking process and defense strategies with TI CC26x2R LaunchPad, USRP-N210 platform, and a self-designed prototype. Extensive experiments have demonstrated the existence of the attack, and the feasibility, effectiveness, and accuracy of the proposed defense strategies. Xiaonan Zhang 0001, Sihan Yu, Hansong Zhou, Pei Huang 0005, Linke Guo, Ming Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Defending against Cross-Technology Jamming in Heterogeneous IoT SystemsabstractThe wide deployment of IoT devices has resulted in a critical shortage of spectrum resources. Many IoT devices coexist on the same spectrum band, where the network performance is always degraded. As a promising solution, the Cross-Technology Communication (CTC) enables the direct communication among heterogeneous IoT devices. Unfortunately, the emerging cross-technology attacks have demonstrated their high success rates in terms of spoofing the end IoT devices or jamming the communication channels. In this paper, we investigate a novel cross-technology jamming issue for a distributed heterogeneous IoT system. Compared with traditional jamming methods, the cross-technology jammer has a much higher jamming power, wider jamming bandwidth, and stronger stealthiness, all of which deserve a complete re-thinking of defensive mechanisms. Therefore, we propose a hybrid anti-jamming scheme that jointly considers frequency hopping and power control techniques. Specifically, we model the anti-jamming process as a Markov Decision Process (MDP) and adopt Deep Q-Network (DQN) to find the optimal strategy. Extensive real-world experiments show that the goodput (payload data) of our anti-jamming scheme can achieve up to 2X and 1.39X than the passive and random anti-jamming approaches, respectively. In particular, our anti-jamming scheme provides 78% of goodput with the presence of a cross-technology jammer, outperforming existing passive and random anti-jamming scheme designs at 37.6% and 54.1%. Sihan Yu, ChunChih Lin, Xiaonan Zhang 0001, Linke Guo |
ICDCS | 1 |
| 2022 | Physical-Level Parallel Inclusive Communication for Heterogeneous IoT DevicesabstractThe proliferation of Internet of Things (IoT) has transformed the way people interact with the world. Various kinds of wireless protocols have been developed to support diverse types of IoT communications. Unfortunately, the lack of spectrum resources puts a hard limit on managing the large-scale heterogeneous IoT system. Although previous works alleviate this strain by coordinating transmission power, time slots, and sub-channels, they may not be feasible in future IoT applications with dense deployments. In this paper, we explore a physical-level parallel inclusive communication paradigm for the coexistence of Wi-Fi and ZigBee, which leverages novel bits embedding approaches on the OQPSK protocol to enable both Wi-Fi and ZigBee IoT devices to decode the same inclusive signals at the same time but with each one’s different data. By carefully crafting the inclusive signals using legacy Wi-Fi protocol, the overlapping spectrum can be simultaneously re-used by both protocols, expecting a maximum data rate (250kbps) for ZigBee devices and up to 3.75Mbps for a Wi-Fi pair over only a 2MHz bandwidth. The achieved spectrum efficiency outperforms a majority of CTC schemes and parallel communication designs. Compared with existing works on parallel communication, our proposed system is the first one that achieves an entire software-level design, which can be readily implemented on Commercial Off-The-Shelf (COTS) devices without any hardware modification. Based on extensive real-world experiments on both USRP and COTS device platforms, we demonstrate the feasibility, generality, and efficiency of the proposed new paradigm. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo |
INFOCOM | 1 |
| 2022 | Wearable-User Authentication via Cross-Technology Interference in Heterogeneous EnvironmentsabstractThe increasing deployment of wireless sensors enables a broad spectrum of health-related wearable applications. Due to the sensitivity of collected personal health information, these wearables should be authenticated together with their users as “wearable-user pairs” to ensure that they are attached to legitimate users. However, various devices are equipped with dedicated sensing abilities and wireless protocols corresponding to data characteristics in practice. Traditional authentication methodologies may not work in this heterogeneous environment because of protocol incompatibility. For example, how to verify a new ZigBee-enabled monitor when the existing trusted device is Wi-Fi-enabled? Therefore, to achieve authentication across protocols, in this article, we leverage the unique cross-technology interference (CTI), triggered by heterogeneous wireless transmissions, along with human physiological activity measurements (e.g., respiration patterns) to design an authentication scheme between wearables and users. Specifically, the authentication from an unknown ZigBee wearable to a trusted Wi-Fi device is achieved by monitoring the channel state information (CSI) changes according to human respiration. Our approach not only successfully recognizes a legitimate wearable-user pair but also blocks illegal access from adversaries. Extensive experiments have been conducted to demonstrate both the security and feasibility of the proposed scheme. The designed mechanism can achieve over 92% authentication accuracy with human subjects. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo, Ming Li 0006 |
IEEE Internet Things J. | 3 |
| 2022 | IS-WARS: Intelligent and Stealthy Adversarial Attack to Wi-Fi-Based Human Activity Recognition SystemsabstractThe non-intrusive human activity recognition has been envisioned as a key enabler for many emerging applications requiring interactions between humans and computing systems. To accurately recognize different human behaviors, ubiquitous wireless signals are widely adopted, e.g., Wi-Fi signals, whose Channel State Information (CSI) can precisely reflect human movements. Unfortunately, nearly all Wi-Fi-based recognition systems assume a clean wireless environment, i.e., no interference will compromise the developed algorithms, which, apparently, is not feasible in practice. Even worse, for systems using Wi-Fi 2.4GHz signals, the widely existing interference from coexisting protocols, such as ZigBee, Bluetooth, and LTE-Unlicensed, can easily compromise the recognition process, posing a hard limit on further enhancing the accuracy. Therefore, this work uncovers a new signal adversarial attack against Wi-Fi-based human activity recognition systems, by intentionally injecting interference using coexisting protocol signals. The contaminated Wi-Fi signal will distort CSI estimation and finally output a false recognition result. Different from traditional jamming attacks, this new adversarial attack is intelligent and stealthy in terms of avoiding being detected from traffic analysis. Along with both theoretical analysis and extensive real-world experiments, we have shown this newly-identified attack can easily compromise many existing Wi-Fi-based human recognition systems while still bypassing existing schemes for malicious signal detection. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | AuthCTC: Defending Against Waveform Emulation Attack in Heterogeneous IoT EnvironmentsabstractWidely deployed IoT devices have raised serious concerns for the spectrum shortage and the cost of multi-protocol gateway deployment. Recent emerging Cross-Technology Communication (CTC) technique can alleviate this issue by enabling direct communication among heterogeneous wireless devices, such as WiFi, Bluetooth, and ZigBee on 2.4 GHz. However, this new paradigm also brings security risks, where an attacker can use CTC to launch wireless attacks against IoT devices. Due to limited computational capability and different wireless protocols being used, many IoT devices are unable to use computationally-intensive cryptographic approaches for security enhancement. Therefore, without proper detection methods, IoT devices cannot distinguish signal sources before executing command signals. In this paper, we first demonstrate a new defined physical layer attack in the CTC scenario, named as waveform emulation attack, where a WiFi device can overhear and emulate the ZigBee waveform to attack ZigBee IoT devices. Then, to defend against this new attack, we propose a physical layer defensive mechanism, named as AuthCTC, to verify the legitimacy of CTC signals. Specifically, at the sender side, an authorization code is embedded into the packet preamble by leveraging the dynamically changed cyclic prefix. A WiFi-based detector is used to verify the authorization code at the receiver side. Extensive simulations and experiments using off-the-shelf devices are conducted to demonstrate both the feasibility of the attack and the effectiveness of our defensive mechanism. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Long Cheng 0005, Kuang-Ching Wang |
AsiaCCS | 1 |
| 2020 | Energy Harvesting Long-Range Marine CommunicationabstractThis paper proposes a self-sustaining broadband long-range maritime communication as an alternative to the expensive and slow satellite communications in offshore areas. The proposed system, named Marinet, consists of many buoys. Each of the buoys has two units: an energy harvesting unit and a wireless communication unit. The energy harvesting unit generates electrical energy from ocean waves to support the operation of the wireless communication unit. The wireless communication unit on each buoy operates in a TV white space frequency band and connects to each other and wired high-speed gateways on land or islands to form a mesh network. The resulting mesh network provides wireless access services to marine users in their range. A prototype of the energy harvesting unit and the wireless communication unit are built and tested in the field. In addition, to ensure Marinet will maintain stable communications in rough sea states, an ocean-link-state prediction algorithm is designed. The algorithm predicts ocean link-states based on ocean wave movements. A realistic ocean simulator is designed and used to evaluate how such a link-state prediction algorithm can improve routing algorithm performance. Ali Hosseini-Fahraji, Pedram Loghmannia, Kexiong Curtis Zeng, Xiaofan Li 0006, Sihan Yu, Sihao Sun, Yaling Yang, Majid Manteghi |
INFOCOM | 5 |