EDBT 2026 Demo / reviewers in the wild / expert
Qiuye He
dblp:295/6500
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2024
0000-0003-1315-1994ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Precise Wireless Camera Localization Leveraging Traffic-Aided Spatial AnalysisabstractWireless cameras nowadays commonly employ motion sensors to identify that something is occurring in their fields of vision before starting to record and notifying the property owner of the activity. In this paper, we discover that the motion sensing action can disclose the location of the camera through a novel wireless camera localization technique we call MotionCompass. By creating motion stimuli and sniffing wireless traffic for a response to that stimuli, a user can obtain the motion trajectories within the motion detection zone and then use them to calculate the camera's location. We also extend the camera localization algorithm to pinpoint cameras in always-active mode. We develop an Android app to implement MotionCompass. Our extensive experiments using the developed app and 18 popular wireless cameras demonstrate that for cameras with one motion sensor, MotionCompass can attain a mean localization error of around 5 cm with less than 140 seconds. We also discuss defenses against MotionCompass. Our localization technique builds upon existing work that detects the existence of hidden cameras, to pinpoint their exact location. Qiuye He, Song Fang 0001, Yao Liu 0007 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Revisiting Wireless Breath and Crowd Inference Attacks With Defensive DeceptionabstractBreathing rates and crowd counting can be used to verify the human presence, especially the former one can disclose a person’s physiological status. Many studies have demonstrated success in applying channel state information (CSI) to estimate the breathing rates of stationary individuals and count the number of people in motion. Due to the invisibility of radio signals, the ubiquitous deployment of wireless infrastructures, and the elimination of the line-of-sight (LOS) requirement, such wireless inference techniques can surreptitiously work and violate user privacy. However, little research has been conducted specifically in mitigating misuse of those techniques. This paper proposes new proactive countermeasures against all existing CSI-based vital signs and crowd counting inference methods. Specifically, we set up ambush locations with carefully designed wireless signals, allowing eavesdroppers to infer a false breathing rate or person count specified by the transmitter. The true breathing rate or person count is thus protected. Experimental results on software-defined radio platforms with 5 participants demonstrate the effectiveness of the proposed defenses. An eavesdropper can be misled into believing any desired breathing rate with an error of less than 1.2 bpm when the user lies on a bed in a bedroom, and 0.9 bpm when the user sits in a chair in an office room. Additionally, our proposed defense mechanisms can deceive an attacker into believing there are moving individuals in an empty room with a 100% success rate, using both Support Vector Machine (SVM) and Decision Tree (DT) classifiers. Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | When Free Tier Becomes Free to Enter: A Non-Intrusive Way to Identify Security Cameras with no Cloud SubscriptionabstractWireless security cameras may deter intruders. Accompanying the hardware, consumers may pay recurring monthly fees for recording videos to the cloud, or use the free tier offering motion alerts and sometimes live streams via the camera app. Many users may purchase the hardware without buying the subscription to save money, which inherently reduces their efficacy. We discover that the wireless traffic generated by a camera responding to stimulating motion may disclose whether or not video is being streamed. A malicious user such as a burglar may use such knowledge to target homes with a ''weak camera'' that does not upload video or turn on live view mode. In such cases, criminal activities would not be recorded though they are performed within the monitoring area of the camera. Accordingly, we describe a novel technique called WeakCamID that creates motion stimuli and sniffs resultant wireless traffic to infer the camera state. We perform a survey involving a total of 220 users, finding that all users think cameras have a consistent security guarantee regardless of the subscription status. Our discovery breaks such ''common sense''. We implement WeakCamID in a mobile app and experiment with 11 popular wireless cameras to show that WeakCamID can identify weak cameras with a mean accuracy of around 95% and within less than 19 seconds. Qiuye He, Song Fang 0001, Yao Liu 0007 |
CCS | 2 |
| 2023 | Phantom-CSI Attacks against Wireless Liveness DetectionabstractAll systems monitoring human behavior in real time are, by their nature, attractive targets for spoofing. For example, misdirecting live-feed security cameras or voice-controllable Internet-of-Things (IoT) systems (e.g., Amazon Alexa and Google Assistant) has immediately intuitive benefits, so there is a consequent need for detecting liveness of the human(s) whose behavior is being monitored. Emerging research lines have focused on analyzing changes in prevalent wireless signals to detect video or voice spoofing attacks, as wireless-based techniques do not require the user to carry any additional device or sensor for liveness detection. Video/voice streaming and coexisting wireless signals convey different aspects of the same overall contextual information related to human activities, and the presence of spoofing attacks on the former breaks this relationship, so the latter performs well as liveness detection to augment the former. However, we recognize and herein evaluate how to spoof the latter as well to defeat this liveness detection. In our attack, an adversary can easily create phantom wireless signals and synchronize them with spoofed video/voice signals, such that the legitimate user can no longer distinguish real from fake human activity. Real-world experimental results on top of software-defined radio platforms validate the possibility of generating fake CSI flows and demonstrate that with the phantom-CSI attack, the true positive rates (TPRs) of wireless liveness detection systems for video and voice decrease from 100% spoofing detection to just 4.4% and 0, respectively. Qiuye He, Song Fang 0001 |
RAID | 1 |
| 2023 | Proactive Anti-Eavesdropping With Trap Deployment in Wireless NetworksabstractDue to the open nature of the wireless medium, wireless communications are especially vulnerable to eavesdropping attacks. This article designs a new wireless communication system to deal with eavesdropping attacks. The proposed system can enable a legitimate receiver to get desired messages and meanwhile an eavesdropper to hear “fake” but meaningful messages by combining confidentiality and deception, thereby confusing the eavesdropper and achieving additional concealment that further protects exchanged messages. Towards this goal, we propose techniques that can conceal exchanged messages by utilizing wireless channel characteristics between the transmitter and the receiver, as well as techniques that can attract an eavesdropper to gradually approach a trap region, where the eavesdropper can get fake messages. We also provide both theoretical and empirical analysis of the established secure channel between the transmitter and the receiver. We develop a prototype system using Universal Software Defined Radio Peripherals (USRPs). Experimental results show that an eavesdropper at a trap location can receive fake information with a bit error rate (BER) close to 0, and the transmitter with multiple antennas can successfully deploy a trap area. Qiuye He, Song Fang 0001, Tao Wang 0026, Yao Liu 0007, Shangqing Zhao |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisabstractSensitive numbers play an unparalleled role in identification and authentication. Recent research has revealed plenty of side-channel attacks to infer keystrokes, which require either a training phase or a dictionary to build the relationship between an observed signal disturbance and a keystroke. However, training-based methods are unpractical as the training data about the victim are hard to obtain, while dictionary-based methods cannot infer numbers, which are not combined according to linguistic rules like letters are. We observe that typing a number creates not only a number of observed disturbances in space (each corresponding to a digit), but also a sequence of periods between each disturbance. Based upon existing work that utilizes inter-keystroke timing to infer keystrokes, we build a novel technique called WINK that combines the spatial and time domain information into a spatiotemporal feature of keystroke-disturbed wireless signals. With this spatiotemporal feature, WINK can infer typed numbers without the aid of any training. Experimental results on top of software-defined radio platforms show that WINK can vastly reduce the guesses required for breaking certain 6-digit PINs from 1 million to as low as 16, and can infer over 52% of user-chosen 6-digit PINs with less than 100 attempts. Edwin Yang, Qiuye He, Song Fang 0001 |
CCS | 2 |
| 2022 | HoneyBreath: An Ambush Tactic Against Wireless Breath Inference
Qiuye He, Edwin Yang, Song Fang 0001, Shangqing Zhao |
MobiQuitous | 1 |
| 2021 | MotionCompass: pinpointing wireless camera via motion-activated trafficabstractWireless security cameras are integral components of security systems used by military installations, corporations, and, due to their increased affordability, many private homes. These cameras commonly employ motion sensors to identify that something is occurring in their fields of vision before starting to record and notifying the property owner of the activity. In this paper, we discover that the motion sensing action can disclose the location of the camera through a novel wireless camera localization technique we call MotionCompass. In short, a user who aims to avoid surveillance can find a hidden camera by creating motion stimuli and sniffing wireless traffic for a response to that stimuli. With the motion trajectories within the motion detection zone, the exact location of the camera can be then computed. We develop an Android app to implement MotionCompass. Our extensive experiments using the developed app and 18 popular wireless security cameras demonstrate that for cameras with one motion sensor, MotionCompass can attain a mean localization error of around 5 cm with less than 140 seconds. This localization technique builds upon existing work that detects the existence of hidden cameras, to pinpoint their exact location and area of surveillance. Qiuye He, Song Fang 0001, Yao Liu 0007 |
MobiSys | 2 |