EDBT 2026 Demo / reviewers in the wild / expert
Wenfan Song
dblp:303/7324
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0003-1769-8540ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Anti-Spoofing and Mask-Supported Face Authentication Using mmWave Without On-Site RegistrationabstractFace authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and susceptible to masks and vulnerable to spoofing attacks. This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans faces by moving a commodity mmWave radar along a specific trajectory. The signals bounced off the face carry facial biometric and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well when users wear masks. To en- hance security, we develop a liveness detection method and an amplitude modulation-based method to defend against spoofing attacks and replay attacks. We enhance the basic version of mmFace [1] by improving its performance under mask occlusion and replay attack resilience. Besides, we explore a distance-resistant structure feature to suppress the impact of unstable face- to-device distance. To avoid on-site registration, we propose a novel virtual registration approach based on the cross-modal transformation from photos to mmWave. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments demonstrate mmFace's accuracy in FA and effectiveness in attack detection. Wenfan Song, Weiye Xu 0001, Jianwei Liu 0008, Yuanqing Zheng, Xinhuai Wang, Jinsong Han |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Replay-Resistant Few-Shot Disk Authentication Using Electromagnetic FingerprintabstractExternal disks (henceforth referred to as disks) are commonly used data storage peripherals for hosts. Verifying the legitimacy of these disks is essential to mitigate security risks, such as privacy breaches and virus propagation, before initiating interactions with a host. To address this challenge, we proposeDiskPrint, a novel replay-resistant, few-shot disk authentication system that relies on unintentional electromagnetic (EM) emanations from the internal components of disks. The core idea ofDiskPrintis that EM signals emitted during data writing operations can reveal unique hardware discrepancies among different disks. Building on electromagnetic theory, we develop a theoretical model that links EM signals to the underlying electronic components of the disk, demonstrating the feasibility of extracting distinctive disk fingerprints from these emanations. We also propose a set of signal enhancement techniques aimed at mitigating EM interface noise and improving the signal-to-noise ratio (SNR) of the EM measurements. To further strengthen the security ofDiskPrint, we introduce a device-agnostic, replay-resistant approach by incorporating randomness into the leaked EM signals. Real-world experiments with 60 disks, spanning both hard disk drives (HDDs) and solid-state drives (SSDs) from seven brands and 14 different models, indicate thatDiskPrintachieves an authentication success rate exceeding 99.6% with only three registration samples. A robustness analysis confirms its stability over time, while a security evaluation shows its resilience against various attack scenarios. Jianwei Liu 0008, Wenfan Song, Jiantao Yuan, Guanding Yu, Jinsong Han |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Replay-resistant Disk Fingerprinting via Unintentional Electromagnetic EmanationsabstractExternal disks (abbr., disks) are common data storage peripherals for hosts. Verifying the disk’s legitimacy is crucial to prevent security issues on a host like privacy leakage and virus propagation before interaction setup. To address this issue, we propose DiskPrint, a novel non-intrusive and replay-resistant disk authentication system that relies on unintentional electromagnetic (EM) emanations from disks’ internal components. The core idea of DiskPrint is that EM signals emitted during data writing can reflect hardware discrepancies among different disks. Based on electromagnetic principles, we establish a theoretical model associating EM signals with built-in electronic components to demonstrate the feasibility of extracting disk fingerprints from such EM emanations. We also propose a series of signal enhancement methods to remove the EM interface and improve the signal-to-noise ratio (SNR) of the EM measurements. To boost the security of DiskPrint, we propose a device-agnostic replay-resistant method by introducing randomness into leaked EM signals. Real-world experiments with 60 disks including hard disk drives (HDDs) and solid state drives (SSDs) from seven brands and 14 models indicate that DiskPrint achieves a 99%+ authentication success rate. Robustness analysis demonstrates DiskPrint’s stability over time. Security study shows its ability to defend against various attacks. Wenfan Song, Jianwei Liu 0008, Jinsong Han |
RAID | 1 |
| 2023 | Secure User Verification and Continuous Authentication via Earphone IMUabstractBiometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods or inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namelyMandiPass.MandiPassleverages inertial measurement units, which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. It provides not only one-time verification function but also continuous authentication function. Both the two functions are secure and user-friendly. We theoretically validate the feasibility ofMandiPassand develop a series of deep learning techniques for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show thatMandiPasscan achieve low equal error rate, even under various harsh environments. Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | Mask does not matter: anti-spoofing face authentication using mmWave without on-site registrationabstractFace authentication (FA) schemes are universally adopted. However, current FA systems are mainly camera-based and hence susceptible to face occlusion (e.g., facial masks) and vulnerable to spoofing attacks (e.g., 3D-printed masks). This paper exploits the penetrability, material sensitivity, and fine-grained sensing capability of millimeter wave (mmWave) to build an anti-spoofing FA system, named mmFace. It scans the human face by moving a commodity off-the-shelf (COTS) mmWave radar along a specific trajectory. The mmWave signals bounced off the human face carry the facial biometric features and structure features, which allows mmFace to achieve reliable liveness detection and FA. Due to the penetrability of mmWave, mmFace can still work well even if users wear masks. We explore a distance-resistant facial structure feature to suppress the impact of unstable face-to-device distance. To avoid inconvenient on-site registration, we also propose a novel virtual registration approach based on the core idea of cross-modal transformation from photos to mmWave signals. We implement mmFace with various antenna configurations and prototype two typical modes of mmFace. Extensive experiments show that mmFace can realize accurate FA as well as reliable liveness detection. Weiye Xu 0001, Wenfan Song, Jianwei Liu 0008, Yuanqing Zheng, Jinsong Han, Xinhuai Wang, Kui Ren 0001 |
MobiCom | 2 |
| 2021 | MandiPass: Secure and Usable User Authentication via Earphone IMUabstractBiometric plays an important role in user authentication. However, the most widely used biometrics, such as facial feature and fingerprint, are easy to capture or record, and thus vulnerable to spoofing attacks. On the contrary, intracorporal biometrics, such as electrocardiography and electroencephalography, are hard to collect, and hence more secure for authentication. Unfortunately, adopting them is not user-friendly due to their complicated collection methods and inconvenient constraints on users. In this paper, we propose a novel biometric-based authentication system, namely MandiPass. MandiPass leverages inertial measurement units (IMU), which have been widely deployed in portable devices, to collect intracorporal biometric from the vibration of user's mandible. The authentication merely requires user to voice a short ‘EMM’ for generating the vibration. In this way, MandiPass enables a secure and user-friendly biometric-based authentication. We theoretically validate the feasibility of MandiPass and develop a two-branch deep neural network for effective biometric extraction. We also utilize a Gaussian matrix to defend against replay attacks. Extensive experiment results with 34 volunteers show that MandiPass can achieve an equal error rate of 1.28%, even under various harsh environments. Jianwei Liu 0008, Wenfan Song, Leming Shen, Jinsong Han, Kui Ren 0001 |
ICDCS | 2 |