Huadi Zhu

dblp:282/6169 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2025
0000-0001-6512-9145ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2025 SnoopDog: Detecting USB Bus Sniffers Using Responsive EMR
abstract
The lack of encryption and authentication mechanisms in USB standards renders USB traffic susceptible to sniffing attacks. This paper presents an initial effort to detect USB bus sniffing through the development of a detection system, SnoopDog. It does not require hardware redesign of USB devices or modifications to the kernel or USB protocol stack. The system utilizes a probe-and-detect strategy. The host PC generates bait traffic with a dummy endpoint address. While benign devices discard this traffic due to the address mismatch, a sniffer captures the data, consequently emitting responsive electromagnetic radiation (EMR). To determine whether a USB device is a sniffer, SnoopDog calculates the correlation between the bait traffic and the responsive EMR signals captured near the target device. A high correlation indicates the presence of a sniffer. Recognizing that sniffer's EMR signals can be weak, we introduce a novel temporal folding scheme to improve the signal-to-noise ratio (SNR). To evaluate the performance, we build a prototype of SnoopDog and conduct comprehensive evaluations under a variety of settings, where SnoopDog delivers a promising detection accuracy with minor system overhead.
Srinivasan Murali, YoungTak Cho, Huadi Zhu, Pan Li 0001, Ming Li 0006
ACSAC3
2025 Continuous User Authentication for Extended Reality Using Pupil Reflexive Mechanisms as a Biometric
abstract
With the rapid adoption of extended reality (XR) technologies in both consumer and enterprise domains, continuous and unobtrusive user authentication has become increasingly important. Existing authentication methods are often intrusive, static, or insufficiently secure for immersive environments. In this work, we propose a novel passive authentication framework that leverages users' real-time pupil light reflex (PLR) in response to visual stimuli rendered in XR. By treating screen brightness as a natural, time-varying challenge and modeling the user's pupil response as the biometric signal, our system learns to extract identity-specific features that are invariant to environmental content. We implement our prototype on two commercial XR headsets and evaluate it through a user study involving eight participants across diverse XR applications. Our system achieves an equal error rate (EER) of 0.093 with a 2-minute prediction window. These results demonstrate the feasibility of pupillary dynamics as a behavioral biometric for secure, continuous authentication in immersive environments. This study lays the foundation for future work on scalable, multimodal, and adaptive biometric authentication in XR.
Shuaikang Hou, Muyao Tang, Srinivasan Murali, Huadi Zhu
MobiHoc4
2024 GPSBuster: Busting out Hidden GPS Trackers via MSoC Electromagnetic Radiations
abstract
The escalating threat of hidden GPS tracking devices poses significant risks to personal privacy and security.Featured by their miniaturization and misleading appearances, GPS devices can be easily disguised in their surroundings making their detection extremely challenging.In this paper, we propose a novel side-channel-driven detection system, GPSBuster, leveraging electromagnetic radiation (EMR) emitted by GPS trackers.Our feasibility studies and hardware analysis reveal that unique EMR patterns associated with the tracker's operation, stemming from the quartz oscillator, local oscillator, and mixer in the Mixed-Signal on Chip (MSoC) system.Nevertheless, as a side-channel leakage, EMRs can be extremely weak and suffer from the ambient noise interference, rendering the detection impractical.To address these challenges, we develop the signal processing techniques with noise removals and a dual-dimensional folding mechanism to accumulate the spectrum energy and protrude the EMR patterns with high Signal-to-Noise Ratios (SNR).Our detection prototype, built with a portable HackRF One device, allows users to perform a scan-to-detect manner and achieves an overall success rate of 98.4% on top-10 selling GPS trackers under various testing cases.The maximum detection range is 0.61m.
Zhenxiong Yan, Wenqiang Jin, Zhenyu Ning, Daibo Liu, Zheng Qin 0001, Yu Liu 0021, Huadi Zhu, Ming Li 0006
CCS8
2024 Avara: A Uniform Evaluation System for Perceptibility Analysis Against Adversarial Object Evasion Attacks
Xinyao Ma, Chaoqi Zhang 0006, Huadi Zhu, L. Jean Camp, Ming Li 0006, Xiaojing Liao
CCS3
2024 Bere: A Novel Video Recommender System for Virtual Reality Using Human Behavioral Signals
abstract
While video recommendation has been studied extensively in regular PC and smartphone settings, such a topic has been rarely discussed in the virtual reality (VR) context so far. On the other hand, as the popularity of VR videos continues to soar, its recommendation will play a crucial part in providing suggestions and guiding users through a deluge of available content. Given this unmet need, in this work, we present Bere, a video recommender system tailored for VR. Our approach leverages viewers' behavioral responses as they engage with VR videos to infer their preferences and thus make future recommendations. We integrate these new behavioral user-video interaction measures into the mainstream recommendation framework and renovate the graph learning-based paradigm to accommodate the new changes. The recommender system is further empowered with a novel domain adaptation approach named CMCCDA to address the data scarcity problem for model training. We also develop an energy-efficient adaptive encoding scheme to reduce the energy consumption on the VR device. We collect a behavioral dataset for video recommendation in VR and demonstrate through extensive evaluation that Bere significantly outperforms state-of-the-art schemes by up to 68.0% in precision and up to 28.8% in ranking quality.
Huadi Zhu, Chaowei Wang, Venkateshwar Reddy Darmanola, Wenqiang Jin, Ming Li 0006
MobiCom1
2024 Behaviors Speak More: Achieving User Authentication Leveraging Facial Activities via mmWave Sensing
abstract
Human faces have been widely adopted in many applications and systems requiring a high-security standard. Although face authentication is deemed to be mature nowadays, many existing works have demonstrated not only the privacy leakage of facial information but also the success of spoofing attacks on face biometrics. The critical reason behind this is the failure of liveness detection in biometrics. This work advances most biometric-based user authentication schemes by exploring dynamic biometrics (human facial activities) rather than traditional static biometrics (human faces). Inspired by observations from psychology, we propose the mmFaceID to leverage humans' dynamic facial activities when performing word reading for achieving robust, highly accurate, and effective user authentication via mmWave sensing. By addressing a series of technical challenges of capturing micro-level facial muscle movements using a mmWave sensor, we build a neural network to reconstruct facial activities via estimated expression parameters. Then, unique features can be extracted to enable robust user authentication regardless of relative distances and orientations. We conduct comprehensive experiments on 23 participants to evaluate mmFaceID in terms of distances/orientations, length of word lists, occlusion, and language backgrounds, demonstrating an authentication accuracy of 94.7%. We also extend our evaluation in a real IoT scenario. By speaking real IoT commends, the average authentication accuracy can reach up to 92.28%.
Chenxu Jiang, Sihan Yu, Jingjing Fu, ChunChih Lin, Huadi Zhu, Ming Li 0006, Linke Guo
SenSys5
2023 Continuous Authentication Using Human-Induced Electric Potential
abstract
Most terminal devices authenticate users only once at the time of initial login, leaving the terminal unprotected during an active session when the original user leaves it unattended. To address this issue, continuous authentication has been proposed by automatically locking the terminal after a period of inactivity. However, it does not fully eliminate the risk of unauthorized access before the session expires. Recent research has also investigated the feasibility of using physiological and behavioral patterns as biometrics. This study presents a novel two-factor continuous authentication that explores a new form of signal called human-induced electric potential captured by wearables in contact with the user’s body. By analyzing this signal, we can determine the time of user-terminal interactions and compare it with information recorded by the terminal’s OS. If the original user remains on the same terminal, the two-source readings would match. Additionally, the proposed scheme includes an extra layer of protection by extracting terminal’s physical fingerprints from the human-induced electric potential to defend against advanced mimicry attacks. To test the effectiveness of our design, a low-cost wearable prototype is developed. Through extensive experiments, it is found that the proposed scheme has a low error rate of 2.3%, with minimal computational and energy requirements.
Srinivasan Murali, Wenqiang Jin, Vighnesh Sivaraman, Huadi Zhu, Tianxi Ji, Pan Li 0001, Ming Li 0006
ACSAC4
2023 SoundLock: A Novel User Authentication Scheme for VR Devices Using Auditory-Pupillary Response
Huadi Zhu, Mingyan Xiao, Demoria Sherman, Ming Li 0006
NDSS1
2022 SpeechQoE: A Novel Personalized QoE Assessment Model for Voice Services via Speech Sensing
abstract
Quality of Experience (QoE) assessment is a long-lasting but yet-to-be-resolved task. Existing approaches, especially for conversational voice services, are restricted to leveraging network-centric parameters. However, their performances are hardly satisfactory due to the failure to consider comprehensive QoE-related factors. Moreover, they develop a one-for-all model that is uniform for all individuals and thus incapable of handling user diversity in QoE perception. This paper proposes a personalized QoE assessment model, namely SpeechQoE. It exploits speaker's speech signals to infer individual's perceived quality in voice services. SpeechQoE fundamentally addresses the drawback of conventional models. Instead of enumerating and incorporating unlimited QoE-related factors, SpeechQoE takes as input speech signals that inherently bear rich information needed for QoE assessment of the speaker. SpeechQoE employs an efficient few-shot learning framework to adapt the model to a new user quickly. We additionally design a lightweight data synthetic scheme to minimize the overhead of data collection needed for model adaption. A modular integration with a conventional parametric model is further implemented to avoid issues caused by the clean-slate data-driven approach. Our experiments show that SpeechQoE achieves an accuracy of 91.4% in QoE assessment which outperforms the state-of-the-art solutions by a clear margin. As another contribution of this work, we build a dataset that would be the first source of annotated audio tracks for QoE assessment of conversational calls.
Chaowei Wang, Huadi Zhu, Ming Li 0006
SenSys2
2021 Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic Emanations
abstract
This study presents Periscope, a novel side-channel attack that exploits human-coupled electromagnetic (EM) emanations from touchscreens to infer sensitive inputs on a mobile device. Periscope is motivated by the observation that finger movement over the touchscreen leads to time-varying coupling between these two. Consequently, it impacts the screen's EM emanations that can be picked up by a remote sensory device. We intend to map between EM measurements and finger movements to recover the inputs. As the significant technical contribution of this work, we build an analytic model that outputs finger movement trajectories based on given EM readings. Our approach does not need a large amount of labeled dataset for offline model training, but instead a couple of samples to parameterize the user-specific analytic model. We implement Periscope with simple electronic components and conduct a suite of experiments to validate this attack's impact. Experimental results show that Periscope achieves a recovery rate over 6-digit PINs of 56.2% from a distance of 90 cm. Periscope is robust against environment dynamics and can well adapt to different device models and setting contexts.
Wenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming Li 0006
CCS3