Yan Long 0002

dblp:38/4289-2 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
9since 2021 · last 2025
0000-0002-3429-7127ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 5 first-author · 9 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2025 RF-Eye-D: Probing Feasibility of CMOS Camera Watermarking with Radio-Frequency Injection
abstract
This work explores how to physically watermark images generated by CMOS cameras using deliberately injected radio-frequency signals. CMOS camera imaging is ubiquitous in embedded systems such as smartphones, AR/VR headsets, drones, and other IoT platforms to capture photos and videos. In restricted environments, a property owner may wish to prevent unauthorized camera recordings depending on spatio-temporal context. Indelible watermarks can deter unauthorized recording. A key research challenge is how to find a reasonably general mechanism to surreptitiously inject watermarks without access to the camera. Existing methods typically rely on software-based watermarking or metadata generation, assuming cooperation from camera owners. However, adversaries can trivially disable metadata or watermarking functions to evade forensic analysis. To address this gap, our work explores an unconventional approach of watermarking non-cooperative cameras by injecting radio-frequency interference in the environment to affect the analog sensing process and inject defender-controlled patterns in the image output. Our analysis explains how the rolling shutter and Bayer filter hardware convert radio-frequency signals into color stripes with variable widths. Building upon model-based simulation, our prototype design encodes and extracts imperceptible watermarks with a bandwidth of up to 50 bits per image. Proof-of-concept evaluations in lab environments show that the proposed technique could support watermarking images with diverse background scenes and reveal future challenges of improving watermark bandwidth and injection distance.
Hui Zhuang, Yan Long 0002, Kevin Fu
RAID2
2025 ARMOUR US: Android Runtime Zero-permission Sensor Usage Monitoring from User Space
abstract
Peer Reviewed
Yan Long 0002, Jiancong Cui, Yuqing Yang 0003, Tobias Alam, Zhiqiang Lin 0001, Kevin Fu
WISEC1
2024 GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards
Qinhong Jiang, Yanze Ren, Yan Long 0002, Chen Yan 0001, Yumai Sun, Xiaoyu Ji 0001, Kevin Fu, Wenyuan Xu 0001
NDSS3
2024 EM Eye: Characterizing Electromagnetic Side-channel Eavesdropping on Embedded Cameras
Yan Long 0002, Qinhong Jiang, Chen Yan 0001, Tobias Alam, Xiaoyu Ji 0001, Wenyuan Xu 0001, Kevin Fu
NDSS1
2024 From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle Takeover
abstract
This paper studies vulnerabilities at the intersection of wearable devices and automated control systems. Particularly, we focus on exploiting smart glasses as an entry point and unveil the threats of taking over security-critical automated control chains without user verification or interaction. These vulnerabilities can be especially pertinent in scenarios where security mechanisms only depend on entry point security with minimal user verification (relying on complete trust over previous nodes in automated control chains). We have validated the effects of our attacks on real-world systems (e.g., Tesla vehicles) that are controlled by software and automation tools such as Apple Shortcuts or IFTTT. We show how our contactless, speaker-independent, and electromagnetic interference based attacks can control functionalities such as unlocking doors and initiating remote start of Tesla vehicles, even though the victim’s phone is in a lock-screen status. Our findings not only demonstrate the potential for unauthorized control over automated, connected systems but also highlight the urgent need for more robust security measures in the integration of wearable technology with broader automation frameworks.
Xingli Zhang 0004, Yazhou Tu, Yan Long 0002, Liqun Shan, Mohamed A Elsaadani, Kevin Fu, Zhiqiang Lin 0001, Xiali Hei 0001
SP3
2023 Characterizing and Mitigating Touchtone Eavesdropping in Smartphone Motion Sensors
abstract
Smartphone motion sensors provide cybersecurity attackers with a stealthy way to eavesdrop on nearby acoustic information. Eavesdropping on touchtones emitted by smartphone speakers when users input numbers into their phones exposes sensitive information such as credit card information, banking PINs, and social security card numbers to malicious applications with access to only motion sensor data. This work characterizes this new security threat of touchtone eavesdropping by providing an analysis based on physics and signal processing theory. We show that advanced adversaries who selectively integrate data from multiple motion sensors and multiple sensor axes can achieve over 99% accuracy on recognizing 12 unique touchtones. We further design, analyze, and evaluate several mitigations which could be implemented in a smartphone update. We found that some apparent mitigations such as low-pass filters can undesirably reduce the motion sensor data to benign applications by 83% but only reduce an advanced adversary’s accuracy by less than one percent. Other more informed designs such as anti-aliasing filters can fully preserve the motion sensor data to support benign application functionality while reducing attack accuracy by 50.1%.
Connor Bolton, Yan Long 0002, Jun Han 0001, Josiah D. Hester, Kevin Fu
RAID2
2023 Side Eye: Characterizing the Limits of POV Acoustic Eavesdropping from Smartphone Cameras with Rolling Shutters and Movable Lenses
abstract
Our research discovers how the rolling shutter and movable lens structures widely found in smartphone cameras modulate structure-borne sounds onto camera images, creating a point-of-view (POV) optical-acoustic side channel for acoustic eavesdropping. The movement of smartphone camera hardware leaks acoustic information because images unwittingly modulate ambient sound as imperceptible distortions. Our experiments find that the side channel is further amplified by intrinsic behaviors of Complementary Metal-oxide–Semiconductor (CMOS) rolling shutters and movable lenses such as in Optical Image Stabilization (OIS) and Auto Focus (AF). Our paper characterizes the limits of acoustic information leakage caused by structure-borne sound that perturbs the POV of smartphone cameras. In contrast with traditional optical-acoustic eavesdropping on vibrating objects, this side channel requires no line of sight and no object within the camera’s field of view (images of a ceiling suffice). Our experiments test the limits of this side channel with a novel signal processing pipeline that extracts and recognizes the leaked acoustic information. Our evaluation with 10 smartphones on a spoken digit dataset reports 80.66%, 91.28%, and 99.67% accuracies on recognizing 10 spoken digits, 20 speakers, and 2 genders respectively. We further systematically discuss the possible defense strategies and implementations. By modeling, measuring, and demonstrating the limits of acoustic eavesdropping from smartphone camera image streams, our contributions explain the physics-based causality and possible ways to reduce the threat on current and future devices.
Yan Long 0002, Pirouz Naghavi, Blas Kojusner, Kevin R. B. Butler, Sara Rampazzi, Kevin Fu
SP1
2023 Private Eye: On the Limits of Textual Screen Peeking via Eyeglass Reflections in Video Conferencing
abstract
Personal video conferencing has become a new norm after COVID-19 caused a seismic shift from in-person meetings and phone calls to video conferencing for daily communications and sensitive business. Video leaks participants’ on-screen information because eyeglasses and other reflective objects unwittingly expose partial screen contents. Using mathematical modeling and human subjects experiments, this research explores the extent to which emerging webcams might leak recognizable textual and graphical information gleaming from eyeglass reflections captured by webcams. The primary goal of our work is to measure, compute, and predict the factors, limits, and thresholds of recognizability as webcam technology evolves in the future. Our work explores and characterizes the viable threat models based on optical attacks using multi-frame super resolution techniques on sequences of video frames. Our models and experimental results in a controlled lab setting show it is possible to reconstruct and recognize with over 75% accuracy on-screen texts that have heights as small as 10 mm with a 720p webcam. We further apply this threat model to web textual contents with varying attacker capabilities to find thresholds at which text becomes recognizable. Our user study with 20 participants suggests present-day 720p webcams are sufficient for adversaries to reconstruct textual content on big-font websites. Our models further show that the evolution towards 4K cameras will tip the threshold of text leakage to reconstruction of most header texts on popular websites. Besides textual targets, a case study on recognizing a closed-world dataset of Alexa top 100 websites with 720p webcams shows a maximum recognition accuracy of 94% with 10 participants even without using machine-learning models. Our research proposes near-term mitigations including a software prototype that users can use to blur the eyeglass areas of their video streams. For possible long-term defenses, we advocate an individual reflection testing procedure to assess threats under various settings, and justify the importance of following the principle of least privilege for privacy-sensitive scenarios.
Yan Long 0002, Chen Yan 0001, Shilin Xiao, Shivan Prasad, Wenyuan Xu 0001, Kevin Fu
SP1
2022 Side Auth: Synthesizing Virtual Sensors for Authentication
abstract
While the embedded security research community aims to protect systems by reducing analog sensor side channels, our work argues that sensor side channels can be beneficial to defenders. This work introduces the general problem of synthesizing virtual sensors from existing circuits to authenticate physical sensors’ measurands. We investigate how to apply this approach and present a preliminary analytical framework and definitions for sensors side channels. To illustrate the general concept, we provide a proof-of-concept case study to synthesize a virtual inertial measurement unit from a camera motion side channel. Our work also provides an example of applying this technique to protect facial recognition against silicon mask spoofing attacks. Finally, we discuss downstream problems of how to ensure that side channels benefit the defender, but not the adversary, during authentication.
Yan Long 0002, Kevin Fu
NSPW1
2020 Automating decontamination of N95 masks for frontline workers in COVID-19 pandemic: poster abstract
abstract
In response to the N95 mask shortage caused by the COVID-19 pandemic, the US CDC has recognized moist-heat as one of the most effective and accessible methods for decontaminating N95 masks for reuse. However, it is challenging to reliably deploy this technique in healthcare settings due to a lack of specialized equipment capable of ensuring proper decontamination conditions. To this end, we developed a wireless sensor platform for moist-heat decontamination process verification, capable of monitoring hundreds of masks simultaneously in commercially available heating systems. Our easy-to-use, low-power, low-cost, scalable platform can be broadly deployed to protect front-line healthcare workers by lowering their risk of infection from reused N95 masks.
Yan Long 0002, Alexander Curtiss, Sara Rampazzi, Josiah D. Hester, Kevin Fu
SenSys1
2019 The Catcher in the Field: A Fieldprint based Spoofing Detection for Text-Independent Speaker Verification
abstract
Verifying the identity of voice inputs is important as voices are increasingly used for sensitive operations. Traditional methods focus on differentiating individuals via the spectrographic features of voices (e.g., voiceprint), yet cannot cope with spoofing attacks, whereby a malicious attacker synthesizes the voice with almost the same voiceprint of a victim or simply replays it. This paper proposes CaField, a text-independent speaker verification method to detect loudspeaker-based voice spoofing attacks with the goal of achieving two seemingly conflicting requirements: usability and security. The key insight of CaField is to construct "fieldprint'' with the acoustic biometrics embedded in sound fields, i.e., a physical field of acoustic energy created as the sound propagates over the air, as analogous to "voiceprint''. We find that fieldprints can be distinctive between speakers (either humans or loudspeakers), and thus we may detect the speakers being used for spoofing attacks from the authentic users. Our evaluation on a dataset of 20 people and 8 loudspeakers shows that by relying on two on-board microphones to sample sound fields while users talk to the smartphones, CaField achieves a detection accuracy of 99.16% and an equal error rate (EER) of 0.85% across multiple sessions and various voice inputs. CaField supports low audio sample rates at 8~kHz and is robust to various factors including phone displacement, user posture, recording environment, etc.
Chen Yan 0001, Yan Long 0002, Xiaoyu Ji 0001, Wenyuan Xu 0001
CCS2