EDBT 2026 Demo / reviewers in the wild / expert
Lei Yang 0025
dblp:50/2484-25
· DBLP profile ↗
104ranked-venue papers
16as first author
51since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 93 · 13 first-author · 48 since 2021Systems, architecture and hardware · 6 · 3 first-authorSecurity and privacy · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Scaling Mobile IoT Connectivity with eSIM: A Temporal Event Modeling Approach
Sicong Liao, Lei Yang 0025, Xuan Song 0001 |
INFOCOM | 4 |
| 2026 | SIGN-RF: Self-Adaptive Neural Fields for Scalable Urban Radio Reconstruction
Shen Wang 0014, Junyang Liu, Donghui Dai, Lei Yang 0025 |
INFOCOM | 5 |
| 2026 | From FSD to FSC: Enabling Full Smart-Communication in Autonomous Vehicles Through Full Self-Driving Models
Zhicheng Wang 0019, Shihan Zhao, Donghui Dai, Lei Yang 0025, Feng Huang 0006, Li-Ta Hsu, Weisong Wen |
INFOCOM | 4 |
| 2026 | Augmented Communication Reliability for UHF RFID Systems via Polar-Coded EPCs
Donghui Dai, Jingyu Tong, Lei Yang 0025 |
SECON | 5 |
| 2026 | Emotion-Aware Personalization: Resonating Short-Video Recommendations via Multi-Modal Affective Computing
Donghui Dai, Zhicheng Wang 0019, Shen Wang 0014, Lei Yang 0025 |
SECON | 5 |
| 2026 | Deep-Soil Acoustic Backscatter Networking for Electrical Substation Grounding AssessmentabstractElectrical substation grounding integrity is fundamental to power system safety, yet its long-term performance is strongly influenced by soil conditions that are difficult to monitor continuously. Existing underground sensing approaches are largely ineffective due to severe signal attenuation in soil, strong electromagnetic interference, and frequent exposure to high-voltage strikes. In this work, we present SoilCapsule, a distributed, battery-free, capsule-style acoustic backscatter sensing system for substation grounding assessment. SoilCapsule harvests ultrasonic energy for computation, sensing, and communication, making it inherently resilient to high-voltage strikes. We design, prototype, and experimentally evaluate the complete end-to-end system. Experimental results show that the proposed grid-to-soil power delivery approach can energize sensors buried at a depth of 100 cm while requiring only 6.17 ppm of the transmit power needed by conventional surface-to-soil schemes to achieve comparable depth. Finally, a field deployment of 20 SoilCapsule sensors in an operational medium-sized electrical substation demonstrates the feasibility of long-term grounding monitoring in real-world environments. Shanyue Wang, Lei Yang 0025 |
SIGCOMM | 4 |
| 2026 | From Magnetic to Optical: NFC-to-Camera Side-Channel Communication via Standard-Compliant Barcodes
Donghui Dai, Lei Yang 0025 |
IEEE Internet Things J. | 3 |
| 2026 | Battery-Free Monitoring of Micron-Level Vibrations With Sub-Hertz Frequency Accuracy: Toward Robust and Accurate Industrial SensingabstractAccurately monitoring micron-level vibrations with sub-hertz frequency estimation error is critical for early fault detection in industrial equipment. Existing solutions either rely on powered sensors or suffer from limited accuracy in passive operation, restricting scalability and long-term deployment. We presentVibro-Stethos, a fully battery-free sensing system that accurately captures micron-level vibrations with sub-hertz frequency estimation error. It employs a dual-junction fieldeffect transistor (JFET) analog frontend to convert vibration into impedance modulation and encodes this onto passive RFID backscatter. An embedded RFID chip enables selective tag activation and provides path-invariant reference amplitude normalization. A Graph Attention Network (GAT)-based model adaptively fuses features from spatially distributed tags, enabling robust fault classification under tag sparsity and placement variation. Extensive evaluation demonstrates that Vibro-Stethos achieves amplitude measurement errors within 2$\mu$m, frequency estimation errors below 0.1 Hz, and vibration fault classification accuracy of 93.7%. Real-world deployments on transformers further confirm its diagnostic capability. Vibro-Stethos offers a practical, robust, and accurate battery-free solution for pervasive industrial vibration monitoring. Yuanhao Feng, Donghui Dai, Jinyang Huang, Panlong Yang, Xiang-Yang Li 0001, Feiyu Han, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 7 |
| 2026 | Toward Scalable Reconfigurable Intelligent Surfaces Using Commercial RFIDsabstractReconfigurable Intelligent Surfaces (RISs) have emerged as cost-effective technologies for improving wireless signal transmission. Conventional RIS designs, however, face challenges such as bulkiness, high production costs, limited scalability, and complex installation due to their reliance on wired connections. In this work, we introduce MetaMosaic, a novel RIS platform that repurposes 920 MHz RFID tags into battery-free unit cells, enabling an affordable, scalable, and flexible one-bit phase-modulated RIS. The system is engineered for compatibility with 2.4 GHz Wi-Fi communications while being controlled at 920 MHz. Our design incorporates two central innovations: the transformation of commercial RFID tags into functional unit cells and the development of a tailored neural radiance field to guide efficient reconfiguration. To further enhance global search capability and support multi-hotspot alignment, we extend the system with a genetic algorithm (GA)-based optimization strategy. Compared with the vanilla MetaMosaic, the GA-based MetaMosaic achieves an additional 3.1 dB signal strength improvement and enables simultaneous enhancement for up to five target points. Extensive testing across ten diverse environments demonstrates that MetaMosaic consistently boosts signal strength, with a mean gain of 19 dB over non-RIS setups. This outperforms current leading RIS systems by a 3-fold improvement. Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 7 |
| 2026 | WiT: Wireless Tracking With Dual-Modality TransformersabstractDeep learning-based wireless indoor localization has emerged as a promising solution to real-world deployment challenges. However, existing research still relies heavily on high-quality training samples and is susceptible to environmental dynamics. To address these issues, we introduce WiT, a dual-modality model that integrates Radio Frequency (RF) signals and Inertial Measurement Unit (IMU) readings to robustly track the location of mobile devices. WiT enhances accuracy through cross-modality validation, mitigating the impact of environmental fluctuations. We implement a history-enabled tracking method to resolve synchronization issues among different modalities. Additionally, we propose a semi-supervised training approach to reduce the demand for ground truth labels. We train and validate WiT on a large-scale dataset comprising approximately 1.7 million samples across 54 scenarios. Our results demonstrate that WiT outperforms state-of-the-art solutions, achieving improvements of at least 30% on the Radio Frequency Identification (RFID), Wi-Fi, and Bluetooth Low Energy (BLE) modalities. Furthermore, integrating both IMU and BLE modalities yields nearly a 50% improvement in accuracy compared to single-modality input. Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Repurposing Optical Mice for Acoustic Eavesdropping
Zhimin Mei, Donghui Dai, Jingyu Tong, Lei Yang 0025 |
INFOCOM | 5 |
| 2025 | Commercial RFIDs as Reconfigurable Intelligent Surfaces
Jingyu Tong, Zhicheng Wang 0019, Donghui Dai, Zhenlin An, Lei Yang 0025 |
INFOCOM | 6 |
| 2025 | Poster: Bridging Autonomy and Connectivity: Enabling Smart Vehicle Communication via Full Self-Driving ModelsabstractAutonomous vehicles rely on Full Self-Driving (FSD) models for perception and trajectory planning. However, their wireless communication systems face significant challenges in dynamic environments, particularly evident in beamforming dependent vehicle-to-satellite links. Motivated by the powerful sensing capabilities of autonomous vehicles, we introduce Full Smart-Communication (FSC), a unified framework that reuses intermediate outputs from FSD pipelines—such as planned trajectories, occupancy maps, and 3D posture estimates—to model the spatio-temporal radio environment. To avoid accessing raw sensor data directly, FSC leverages processed semantic and kinematic information to anticipate channel conditions and proactively compute beamforming parameters ahead of time. Tested in realistic driving datasets, FSC improves signal strength by up to 15 dB. FSC bridges the gap between autonomous perception and robust communication, enabling proactive, low-latency, and energy-efficient connectivity. Zhicheng Wang 0019, Shihan Zhao, Donghui Dai, Lei Yang 0025 |
MobiCom | 4 |
| 2025 | Deciphering Micro-Scale, Sub-Hertz Mechanical Vibrations in Industry 4.0: A Battery-Free Sensing ApproachabstractIn industrial systems, monitoring micro-scale vibrations is crucial for assessing the operational health of equipment. Existing solutions typically rely on battery-powered sensors or are constrained by LoS requirements. To address these limitations, we propose Vibro-Stethos, a micro-scale,sub-herz vibration sensing system based on battery-free tags. It innovatively utilizes the resistance characteristic of JFET in the ohmic region to convert the voltage generated by PZT vibrations into antenna’s impedance, enabling the modulation of vibration information into the backscatter signal. An integrated RFID chip enhances identifiability and controllability. Additionally, a GCN-based vibration fault recognition model ensures accurate identification of vibration states regardless of tag placement. Experimental results demonstrate that Vibro-Stethos achieves an amplitude error of 2μm and a frequency error of 0.1Hz, with a sensing range of up to 5 meters. It can also recognize seven types of vibration states with 89.3% accuracy and has proven robust and effective in real plant deployments. Yuanhao Feng, Donghui Dai, Jingyu Tong, Lei Yang 0025 |
PerCom | 6 |
| 2025 | Combating Voice Spoofing Attacks on Wearables via Speech Movement SequencesabstractVoice assistants, increasingly integrated into wearable devices with limited human-computer interaction modalities, are susceptible to voice spoofing attacks. Such attacks exploit pre-recorded or synthesized voice commands to trick the assistants into executing actions unauthorized by legitimate users. In this work, we propose GyroTalk, a novel approach extracts individual and reliable features from speech movement sequences of users, using built-in gyroscopes in wearables, to differentiate between legitimate users and malicious attackers. GyroTalk is inspired by two critical insights. First, speech, as a highly intricate motor task, necessitates the synchronized coordination of multiple respiratory, laryngeal, lingual and mandibular muscles. These collective muscle movements propagate throughout the body, providing unique movement signatures. Second, the distinctive speech movement sequences of individual speakers, essential for generating specific words, can be grabbed by embedded IMU of wearables. We conduct a comprehensive evaluation of GyroTalk across various COTS Android devices, including smart phones, watches and glasses. Our experimental results demonstrate that GyroTalk can achieve a mean FAR of 2.23% and a FRR of 2.48%, even in the face of complicated voice spoofing attacks. Shan Chang, Luo Zhou, Wei Liu 0138, Hongzi Zhu, Xinggang Hu, Lei Yang 0025 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Frequency-Aware Neural Radio-Frequency Radiance FieldsabstractAlthough Maxwell discovered the physical laws of electromagnetic waves about 160 years ago, accurately modeling the propagation of RF signals in large and complex electrical environments remains a persistent challenge. This complexity arises from the interactions between the RF signal and various obstacles, including reflection and diffraction. Inspired by the success of neural networks in mapping the optical field in computer vision, we introduce the neural radio-frequency radiance field, or$\mathbf{NeRF}^{2}$. This represents a continuous volumetric scene function that effectively models RF signal propagation. Remarkably, after only a sparse amount of training with signal measurements,$\mathbf{NeRF}^{2}$can accurately predict the nature and origin of signals received at any location, assuming the transmitter's position is known. Additionally, we propose the frequency-aware$\mathbf{NeRF}^{2}$to enhance channel prediction performance for wideband signals using an RF prism module. Compared to the vanilla$\mathbf{NeRF}^{2}$, the frequency-aware$\mathbf{NeRF}^{2}$achieves a 4 dB improvement in SNR for FDD OFDM channel estimation and is nearly 3.5 × faster. Functioning as a physical-layer neural network,$\mathbf{NeRF}^{2}$also supports application-layer artificial neural networks (ANNs) by generating synthetic training datasets. Our empirical results demonstrate that augmented sensing enhances the accuracy of AoA estimation, achieving an approximate 50% improvement. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | A Five-Year Retrospective of Cellular Reliability Evolution: The Encouraging, Disappointing, and Further EnhancementsabstractWith recent advances on cellular technologies pushing the boundary of cellular performance, cellular reliability has become a key concern of their adoption and deployment. To fully understand cellular reliability, we work with a major Android phone vendor, Xiaomi, to conduct a long-term (2020-2024) and large-scale (involving 123M users) measurement study in China, with coarse-grained general statistics and fine-grained sampling diagnostics. Our measurement reveals contrasting evolution trends of cellular failures in different stages of the data connection: in the past five years, failures after connection establishment decrease remarkably (by 29%), while failures during connection setup exhibit a sharp increase (by 38%). Our analysis illustrates that the contrast stems from the joint impact of multiple stakeholders, including ISPs’ increasing deployment of 5G base stations, 5G infrastructure upgrade from NSA (Non-Standalone) to SA (Standalone) mode, software defects coming from Android’s adaptation to new cellular technologies, and so forth. Our work provides actionable insights for improving cellular reliability at scale. More importantly, we have built on our insights to develop enhancements that effectively address cellular reliability issues with remarkable real-world impact—our optimizations have reduced 38% cellular connection failures for 5G phones and 31% failure recovery time across all phones. Yunhao Liu 0001, Hongyi Wang 0009, Yang Li 0092, Zhenhua Li 0001, Guoquan Zhang, Lei Yang 0025 |
IEEE Trans. Netw. | 6 |
| 2024 | Enabling Cross-Medium Wireless Networks with Miniature Mechanical AntennasabstractWithin the burgeoning 6G wireless network landscape, there is an intensified push toward achieving all-encompassing accessibility through integrated solutions spanning a multitude of domains. Notwithstanding recent advancements, the conventional relay-centric communication paradigms grapple with scalability and optimal performance issues. In this paper, we introduce MeAnt ---a versatile IoT platform uniquely architected to foster seamless cross-medium communication by leveraging the compact design of piezoelectric-based mechanical antennas (Piezo-MAs). By capitalizing on the propagation attributes of medium-frequency radios emitted from Piezo-MAs, MeAnt promises communication across diverse environments such as air, water, soil, concrete, and even biological tissue, all while maintaining a compact antenna footprint. Moreover, in light of challenges such as potential interference from AM broadcasts and the intrinsic unidirectional nature of Piezo-MAs, we have developed a finely crafted full-stack communication protocol. Comprehensive tests underscore the system's proficiency, demonstrating a penetration depth of up to 10 m in cross-medium environments and realizing a throughput of 8.7 kbps. Zhenlin An, Donghui Dai, Jingyu Tong, Shuijie Long, Lei Yang 0025 |
MobiCom | 6 |
| 2024 | Mirror Never Lies: Unveiling Reflective Privacy Risks in Glass-laden Short VideosabstractIn the era of ubiquitous short-video sharing, an overlooked yet significant privacy risk has arisen: the accidental disclosure of confidential information through reflective surfaces, such as mirrors, glass, or even polished metal. Such reflections can inadvertently disclose sensitive personal details to a broad audience without the awareness of content creators. Our examination of 100 top-rated TikTok short videos reveals that, on average, 37.2% of frames in each video feature identifiable reflective surfaces, posing potential privacy risks. In this work, we introduce a framework designed to scrutinize reflective privacy risks in glass-laden short videos. At the heart of the framework is the development of a reflection-specific neural radiance field, termed RP-NeRF, which enables reflection-aware ray tracing for precise extraction and reconstruction of the reflective scenes from the surfaces they appear on. A detailed field study on the framework indicates that the precision in detecting human presence and recognizing objects from the reconstructed reflective images reaches as high as 90.8% and 89.6%, respectively, even when dealing with a reflective surface that boasts 90% transparency and a mere 4% reflectance rate. These findings highlight the urgent need for greater awareness and advanced solutions to safeguard privacy in our digital age, especially in light of the significant impact of short-video sharing. Shen Wang 0014, Donghui Dai, Lei Yang 0025 |
MobiCom | 4 |
| 2024 | Binary Optical Machine Learning: Million-Scale Physical Neural Networks with Nano NeuronsabstractDeep learning excels in advanced inference tasks using electronic neural networks (ENN), but faces energy consumption and limited computation speed challenges. To mitigate this, optical neural networks (ONNs) were developed, utilizing light for computations. However, their high manufacturing costs limited accessibility. In this work, we first introduce the binary optical neural network (BONN) - a streamlined ONN variant with binarized weights, which significantly reduces fabrication complexities and costs. Specifically, we address (i) the development of a binarization weight function aligned with backward-error propagation, and (ii) a simulation-based training for extra-large neural networks housing millions of neurons. We prototype six BONNs, each comprising four 0.8 × 0.8mm2 layers with one million 800 nm diameter neurons. Costs are cut to 0.13 USD per layer, marking a substantial decrease of 769× from previous ONNs. Experimental results reveal BONNs consume 2, 405× less power than leading ENNs while maintaining an average recognition accuracy of 74% across six datasets. Xueyuan Yang, Zhenlin An, Qingrui Pan, Lei Yang 0025, Dangyuan Lei, Yulong Fan |
MobiCom | 4 |
| 2024 | In-Sensor Machine Learning: Radio Frequency Neural Networks for Wireless SensingabstractGrowing interest in wireless sensing, a cornerstone of the Artificial Intelligence of Things (AIoT), stems from its ability to gauge target states through nearby wireless signals. However, the escalating count of AIoT nodes escalates redundant data flow and exacerbates energy usage in AI cloud infrastructures. This amplifies the urgency for machine learning techniques that function in proximity to, or directly within, sensors. In light of this, we present the Radio-Frequency Neural Network (RFNN), a novel architecture that uses cost-effective transmissive intelligent surfaces to mimic the functions of a traditional neural network near (or in) sensors, transforming sensory nodes into intelligent terminals primed for machine learning. We first devised a unique training algorithm to mitigate the issues arising from unmodelable error-backward propagation; secondly, we incorporated contrastive learning to address the issue of blind labels stemming from environmental uncertainties. Our RFNN prototype, resonating at a 5 GHz WiFi bandwidth, has been honed across nine varied sensing tasks. The rigorous evaluation shows that it achieves a mean accuracy of 91.5% while consuming only 67.2 μJ of energy. This positions RFNN as a match in inferencing prowess to its electronic neural network counterparts but with significantly diminished energy demands. Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025 |
MobiHoc | 5 |
| 2024 | POSTER: A One-size-fits-all Solution for Cross-Technology Communication via TransformerabstractCross-Technology Communication (CTC) is an emerging technology that enables physical-layer direct communication from a WiFi sender to other Internet of Things (IoT) receivers via waveform emulation. Previous research has primarily relied on the reverse engineering to identify the suitable WiFi payloads capable of emulating waveforms similar to desired IoT packets (e.g., ZigBee). However, this approach has several limitations, including irreversibility, scalability challenges, symbol misalignment, and an over-reliance on empirical methods. In this work, we present XiTuXi, a one-size-fits-all solution to automatically achieve the CTC by taking advantage of the neural machine translation (NMT). Inspired by the task comparability between CTC and homophony-based cross-linguistic communication, we employ a well-known NMT model called Transformer to learn the rationale behind translating bit sequences for CTC without human intervention. Specifically, we introduce forward engineering as a solution to tackle the challenge of acquiring training datasets. By utilizing XiTuXi, we effortlessly achieved CTC across 30 protocol combinations (including 802.11b, g, n, ax, ah → Zig-Bee, Bluetooth, LoRa, and Sigfox), ultimately freeing experts from the tedious tasks they faced previously. Sicong Liao, Jingyu Tong, Zhimin Mei, Donghui Dai, Yuanhao Feng, Qiongzheng Lin, Lei Yang 0025 |
MobiSys | 7 |
| 2024 | Understanding Localization by a Tailored GPTabstractConventional deep learning approaches for indoor localization often suffer from their reliance on high-quality training samples and display limited adaptability across varied scenarios. To address these challenges, we repurpose the Transformer model, celebrated for its profound contextual insights, to explore the underlying principles of indoor localization. Our microbenchmark results compellingly demonstrate the superiority of our approach, showing improvements of 30% to 70% across a diverse set of 50 scenarios compared to other state-of-the-art methods. In conclusion, we propose a specialized Generative Pre-training Transformer (GPT) variant, termed LocGPT, configured with 36 million parameters that are tailored to facilitate transfer learning. By fine-tuning this pre-trained model, we achieve near-par accuracy using merely half the conventional dataset, thereby heralding a pioneering stride in transfer learning within the indoor localization domain. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiSys | 5 |
| 2024 | RFID+: Spatially Controllable Identification of UHF RFIDs via Controlled Magnetic Fields
Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
NSDI | 5 |
| 2024 | Pushing the Boundaries of High-Precision AoA Estimation With Enhanced Phase Estimation ProtocolabstractThe emergence of high-precision indoor backscatter tag tracking in GPS-deprived environments has advanced applications from virtual reality to factory automation. Despite this, the high-precision tracking range remains limited to just a few meters, restricting the use of backscatters to the vicinity of checkpoints in warehouses, even though they possess a communication range of 50 m. We have identified that this limited localization range primarily originates from the butterfly effect in localization systems, where a slight phase measurement error gradually escalates into a substantial localization error. This article introduces two innovative phase estimation protocols to address the intrinsic challenges in achieving high-accuracy phase estimation over long-distance communication. The first, consistent phase estimator (CPE), resolves the$\boldsymbol {\pi }$-ambiguity commonly encountered with commercial radio-frequency identification readers. Building on this, CPE+ is designed to cancel flicker noise, neutral white noise, and restore spatial and temporal imbalances. Our experimental results demonstrate that CPE+ extends the range of accurate Angle of Arrival (AoA) estimation and centimeter-level localization from 8 to 15 m in stationary scenarios. It maintains decimeter-level accuracy across the entire 50-m communication range for CPE+ with two or more gateways. In dynamic scenarios, the error of CPE+ increases with tag speed, reaching a median localization error of 11.7 cm at 5 m for tag speeds of 50 cm/s. Zhenlin An, Qingrui Pan, Qiongzheng Lin, Lei Yang 0025 |
IEEE Internet Things J. | 6 |
| 2024 | Harnessing NFC to Generate Standard Optical Barcodes for NFC-Missing SmartphonesabstractMobile payments have grown significantly recently, driven by their contactless feature that minimizes COVID-19 transmission risks. While NFC offers more security and convenience than barcodes and benefits those with amblyopia, many smartphones lack NFC due to module shortages or security decisions. In this work, we present${\sf MagCode}$, an innovative method connecting NFC readers with cameras, allowing users to enjoy NFC payment security using prevalent camera technology. At the heart of${\sf MagCode}$is the harmless magnetic interference on the CMOS image sensor of a smartphone placed nearby the NFC reader, resulting in a group of barcode-like stripes appearing on the captured images. We take advantage of these stripes to encode the data and achieve simplex communication from an NFC reader to an NFC-denied or NFC-disabled smartphone. In particular, we developed a comprehensive suite of protocols spanning from the physical layer to the transport layer, and we rigorously tested our proof-of-concept prototype on 11 different smart devices. Our extensive evaluations showcase a maximum throughput of 2.58 kbps–surpassing magnetometer-based alternatives by a factor of 58–and demonstrate an average data exchange time of 1.3 seconds for mobile payment transactions between an NFC reader and a smartphone. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | The Power of Precision: High-Resolution Backscatter Frequency Drift in RFID IdentificationabstractPhysical-layer identification uses manufacturing variations to create unique identifiers for each device. A decade ago, this concept was applied to RFID tags using backscatter frequency drift (BFD), a specific kind of ‘fingerprint’ determined by the difference between the actual backscatter signal received and the expected backscatter link frequency (BLF). However, BFD has been undervalued due to its low performance in tag identification, achieving less than 30% accuracy. In this study, we reevaluate BFD, focusing on the issue of frequency resolution as the cause of its poor performance. The problem doesn't lie in the BFD's uniqueness, but in the inferior way we measure the frequency of a backscatter signal, which is limited by the current air interface protocol. This situation is akin to trying to identify human fingerprints using low-quality imaging. We propose a practical solution to improve the frequency resolution from kilohertz to sub-hertz, without requiring hardware or protocol changes. Our findings show that this high-resolution BFD approach significantly enhances the distinguishability to 99.4% and the identification accuracy to 94% when tested on a dataset of 7,135 RFID tags across nine models. Qingrui Pan, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Transfer Beamforming via Beamforming for TransferabstractAlthough billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in the two major performance limitations (i.e., short reading range and high miss reading rate) resulting from the current harvesting inefficiency. The classic beamforming technique is regarded as the most promising solution to address the issue. However, applying it to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new paradigm calledtransfer beamforming(${\sf TBF}$), namely, the beamforming strategies can be transferred from reference tags with known positions to power up other unknown neighbor tags of interest. In short, transfer beamforming (is accomplished) via (launching) beamforming (to reference tags first) for (the purpose of) transfer. To do so, we adopt the semi-active tags as the reference tags, which can be powered up with a normal reader in a wide range. Then the beamforming is initiated and transferred to power up the low-sensitive but cost-effective passive tags surrounded by reference tags. A prototype evaluation of${\sf TBF}$with 8 transmitting antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our comprehensive evaluation reveals that${\sf TBF}$can improve the power transmission by 6.9 dB and boost the inventory speed by 2× compared with state-of-art methods. Xueyuan Yang, Zhenlin An, Lei Yang 0025 |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | Transfer Beamforming via Beamforming for TransferabstractAlthough billions of battery-free backscatter devices (e.g., RFID tags) are intensively deployed nowadays, they are still unsatisfying in performance limitations (i.e., short reading range and high miss-reading rate) resulting from power harvesting inefficiency. However, applying classic beamforming technique to backscatter systems meets the deadlock start problem, i.e., without enough power, the backscatter cannot wake up to provide channel parameters; but, without channel parameters, the system cannot form beams to provide power. In this work, we propose a new beamforming paradigm called transfer beamforming (TBF), namely, beamforming strategies can be transferred from reference tags with known positions to power up unknown neighbor tags of interest. Transfer beamforming (is accomplished) via (launching) beamforming (to reference tags firstly) for (the purpose of) transfer. To do so, we adopt semi-active tags as reference tags, which can be easily powered up with a normal reader. Then beamforming is initiated and transferred to power up passive tags surrounded by reference tags. A prototype evaluation of TBF with 8 antennas presents a 99.9% inventory coverage rate in a crowded warehouse with 2,160 RFID tags. Our evaluation reveals that TBF improves the power transmission by 6.9 dB and boosts the inventory speed by 2 × compared with state-of-art methods. Xueyuan Yang, Zhenlin An, Lei Yang 0025 |
INFOCOM | 4 |
| 2023 | MagCode: NFC-Enabled Barcodes for NFC-Disabled SmartphonesabstractMobile payment has achieved explosive growth in recent years due to its contactless feature, which lowers the infection risk of COVID-19. In the market, near-field communication (NFC) and barcodes have become the de facto standard technologies for mobile payment. The NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopia group. Unfortunately, NFC functionality is unavailable in nearly half of smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 4 |
| 2023 | MagCode: Bringing NFC Feature to All SmartphonesabstractMobile payments have experienced a significant surge in recent years, primarily due to their contactless feature that mitigates the risk of COVID-19 transmission. In this landscape, NFC-based payment outperforms barcode-based payment in terms of security, usability, and convenience. It is especially more user-friendly for the amblyopic community. Unfortunately, NFC functionality is unavailable in nearly half of the smartphones in the market nowadays due to the shortage of NFC modules or being disabled for security reasons. Donghui Dai, Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 4 |
| 2023 | Radio Frequency Neural Networks for Wireless SensingabstractWireless sensing has attracted considerable attention because it can sense the state of the targets by analyzing the surrounding wireless signals, which has become the key role of the artificial intelligence of things (AIoT). As the number of sensory nodes increases, large amounts of redundant data are exchanged between sensory terminals and the AI cloud. To process such large amounts of data efficiently and decrease power consumption, a machine-learning approach that operates close to or inside sensors must be developed. To this end, we present the radio-frequency neural network (RFNN), a physical neural network taking advantage of a group of transmissive intelligent surfaces (i.e., metasurfaces) to mimic the computations of a fully-connected neural network. The design is spurred by the capability of RFNNs to perform expensive multiplication and additions at the speed of light, with ultra-low power consumption. We prototype RFNN at 5 GHz for WiFi sensing regarding nine wireless sensing tasks. Extensive evaluations demonstrate the comparably equivalent inference ability as the conventional electronic neural networks while consuming less energy. Jingyu Tong, Zhenlin An, Sicong Liao, Lei Yang 0025 |
MobiCom | 5 |
| 2023 | NeRF2: Neural Radio-Frequency Radiance FieldsabstractAlthough Maxwell discovered the physical laws of electromagnetic waves 160 years ago, how to precisely model the propagation of an RF signal in an electrically large and complex environment remains a long-standing problem. The difficulty is in the complex interactions between the RF signal and the obstacles (e.g., reflection, diffraction, etc.). Inspired by the great success of using a neural network to describe the optical field in computer vision, we propose a neural radio-frequency radiance field, NeRF2, which represents a continuous volumetric scene function that makes sense of an RF signal's propagation. Particularly, after training with a few signal measurements, NeRF2 can tell how/what signal is received at any position when it knows the position of a transmitter. As a physical-layer neural network, NeRF2 can take advantage of the learned statistic model plus the physical model of ray tracing to generate a synthetic dataset that meets the training demands of application-layer artificial neural networks (ANNs). Thus, we can boost the performance of ANNs by the proposed turbo-learning, which mixes the true and synthetic datasets to intensify the training. Our experiment results show that turbo-learning can enhance performance with an approximate 50% increase. We also demonstrate the power of NeRF2 in the field of indoor localization and 5G MIMO. Zhenlin An, Qingrui Pan, Lei Yang 0025 |
MobiCom | 4 |
| 2023 | Revisiting Backscatter Frequency Drifts for Fingerprinting RFIDs: A Perspective of Frequency ResolutionabstractPhysical-layer identification is to exploit inherent randomness introduced during manufacturing to endow a unique fingerprint to a physical entity. A classic fingerprint, called backscatter frequency drift (BFD), was explored a decade ago for the physical-layer identification of RFID tags. The BFD is defined as the offset between the frequency of the backscatter signal actually received from a tag and the requested backscatter link frequency (BLF). As a context-free fingerprint, the BFD is being seriously underestimated due to its terrible performance in tag classification or identification (e.g., accuracy < 30%). In this work, we revisit BFD from the perspective of frequency resolution to pinpoint the reason behind its underperformance. Namely, the low accuracy is not because BFD is insufficiently unique in nature but rather due to the low-resolution measurement of the frequency of a backscatter signal, which is mainly constrained by the current air interface protocol. This challenge is analogous to the recognition of human fingerprints via low-resolution and blurry imaging devices. To address this issue, we propose a practical solution to improve the frequency resolution from kHz to sub-Hz, without any modification of hardware or protocols. The results demonstrate the distinguishability of high-resolution BFD is significantly increased to 99.4% and the identification accuracy is raised to 94% when in the face of 7,135 RFID tags of nine models. Qingrui Pan, Zhenlin An, Lei Yang 0025 |
SECON | 4 |
| 2023 | XiTuXi: Sealing the Gaps in Cross-Technology Communication by Neural Machine TranslationabstractCross-Technology Communication (CTC) is an emerging technology that enables physical-layer direct communication from a WiFi sender to other Internet of Things (IoT) receivers via waveform emulation. The previous works use the reverse engineering to find the appropriate WiFi payload that can emulate the waveform similar to the desired IoT packet in the format of the IoT protocol (e.g., ZigBee). Unfortunately, the reverse engineering approach suffers from many limitations, such as being non-reversible and unscalable, misaligning symbols, and over-relying on empiricism. In this work, we present XiTuXi, a one-size-fits-all solution to automatically achieve the CTC by taking advantage of the neural machine translation (NMT), inspired by the task comparability between CTC and homophony-based cross-linguistic communication. We employ a well-known NMT model called Transformer to learn the bit-sequence to bit-sequence translation rationale behind the CTC without human intervention. Particularly, we introduce the forward engineering to address the dilemma of acquiring training datasets. By using XiTuXi, we achieved the CTC with 30 protocol combinations (ie., 802.11b, g, n, ax, ah Å ZigBee, Bluetooth, LoRa, and Sigfox) effortlessly, which ultimately liberates the experts from previous tedious tasks. Sicong Liao, Zhenlin An, Qingrui Pan, Jingyu Tong, Lei Yang 0025 |
SenSys | 6 |
| 2023 | Inducing Wireless Chargers to Voice Out for Inaudible Command AttacksabstractRecent works demonstrated that speech recognition systems or voice assistants can be manipulated by malicious voice commands, which are injected through various inaudible media, such as ultrasound, laser, and electromagnetic interference (EMI). In this work, we explore a new kind of inaudible voice attack through the magnetic interference induced by a wireless charger. Essentially, we show that the microphone components of smart devices suffer from severe magnetic interference when they are enjoying wireless charging, due to the absence of effective protection against the EMI at low frequencies (100 kHz or below). By taking advantage of this vulnerability, we design two inaudible voice attacks, HeartwormAttack and ParasiteAttack, both of which aim to inject malicious voice commands into smart devices being wirelessly charged. They make use of a compromised wireless charger or accessory equipment (called parasite) to inject the voice, respectively. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and 6 types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of two proposed attacks with commercial charging settings. Donghui Dai, Zhenlin An, Lei Yang 0025 |
SP | 3 |
| 2023 | Localizing RFIDs in Pixel DimensionsabstractRadio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things (IoT). Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7∘ and 2.9∘ at azimuth and elevation angle estimation, respectively. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈1.3 cm at 96 dpi) in a 640× 480 image. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008, Ping Li 0020 |
ACM Trans. Sens. Networks | 3 |
| 2022 | LSAB: Enhancing Spatio-Temporal Efficiency of AoA Tracking Systems
Qingrui Pan, Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
INFOCOM | 4 |
| 2022 | Inducing wireless chargers to voice outabstractRecent advances have demonstrated that voice assistants or speech recognition systems can be manipulated by malicious and inaudible voice commands. However, the previously proposed attacks require an acoustical generator (e.g., a speaker or a capacitor) to trigger mechanical vibrations at a microphone diaphragm. In this work, we investigate a new type of inaudible command attack using wireless chargers. Specifically, the magnetic interference generated by a wireless charger can induce an inaudible sound at a nearby microphone, without triggering any mechanical vibrations, even if the microphone is equipped with a Faraday cage and an internal electromagnetic interference filter already. By taking advantage of this new insight, we will present a novel inaudible command attack demo that can inject inaudible voice commands into smart devices that are being charged or near to a charger. We conduct extensive experiments with 17 victim devices (iPhone, Huawei, Samsung, etc.) and six types of voice assistants (Siri, Google STT, Bixby, etc.). Evaluation results demonstrate the feasibility of the proposed attack with commercial charging settings. Donghui Dai, Zhenlin An, Lei Yang 0025 |
MobiCom | 3 |
| 2022 | Constructing smart buildings with in-concrete backscatter networksabstractGiven the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule-a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively. Zhenlin An, Jingyu Tong, Donghui Dai, Lei Yang 0025 |
MobiCom | 5 |
| 2022 | RF-DNA: large-scale physical-layer identifications of RFIDs via dual natural attributesabstractPhysical-layer identification aims to identify wireless devices during RF communication by exploiting the imperfections of their radio circuitry, i.e., hardware fingerprint. Previous work proposed several hardware fingerprints for RFIDs (e.g., TIE, ABD, PSD, etc). However, these proposed fingerprints suffer from either unscalability or acquisition inefficiency. This work presents RF-DNA, a new hardware fingerprint composed of millions of Dual Natural Attributes (DNA) organized in a helical structure, where a pair of DNA represents a tag's intrinsic response at some frequency. We take advantage of the frequency agnostic phenomenon that a commercial RFID tag can respond within a wider band than the regulated, to acquire 10X more features than previous fingerprints. At the heart of this work are the context-free acquisition approach to extracting DNA from backscatter signals; and the accurate DNA matching algorithm for verifying a tag's identity. A total of 160,000 RF-DNA instances were collected from 16,000 tags using a customized automatic acquisition system. We subsequently carried out large-scale experiments to test the identification accuracy of RF-DNA and previously proposed fingerprints. Our comprehensive evaluation reveals that RF-DNA can achieve a mean accuracy of 95.98%. In contrast, those of previous fingerprints fall to 60% below when in face of thousands of tags. Qingrui Pan, Zhenlin An, Xueyuan Yang, Lei Yang 0025 |
MobiCom | 5 |
| 2022 | VOGUE: Secure User Voice Authentication on Wearable Devices using GyroscopeabstractVoice assistants are popular to wearable devices with limited input and output capabilities, however vulnerable to voice attacks, which cheat a voice assistant by playing forged voice commands without user awareness. In this paper, we propose VOGUE, which captures unique yet stable pattern of speech movement sequences of speakers with embedded gyroscope in wearable devices, to distinguish between registered legal user and malicious attackers (human or machines). The design of VOGUE is based on two key observations. First, speech, as a type of highly complex motor task, inherently requires coordinated actions of many orofacial, laryngeal, pharyngeal, and respiratory muscles, and the collective movements of muscles propagate to distant body segments. Second, to generate a certain word, the speech movement sequence of a speaker is known to be distinctive, and can be captured by inertial sensors. We implement VOGUE on three kinds of COTS android devices including smart glasses, watches and phones, and conduct comprehensive evaluation on the performances. Experimental results show that VOGUE achieves a mean false-acceptance rate (FAR) and false- rejection rate (FRR) of 2.23% and 2.48%, respectively, even under sophisticated voice impersonation attacks. Shan Chang, Xinggang Hu, Hongzi Zhu, Wei Liu 0138, Lei Yang 0025 |
SECON | 5 |
| 2022 | Empowering smart buildings with self-sensing concrete for structural health monitoringabstractGiven the increasing number of building collapse tragedies nowadays (e.g., Florida condo collapse), people gradually recognize that long-term and persistent structural health monitoring (SHM) becomes indispensable for civilian buildings. However, current SHM techniques suffer from high cost and deployment difficulty caused by the wired connection. Traditional wireless sensor networks fail to serve in-concrete communication for SHM because of the complexity of battery replacement and the concrete Faraday cage. In this work, we collaborate with experts from civil engineering to create a type of promising self-sensing concrete by introducing a novel functional filler, called EcoCapsule- a battery-free and miniature piezoelectric backscatter node. We overcome the fundamental challenges in in-concrete energy harvesting and wireless communication to achieve SHM via EcoCapsules. We prototype EcoCapsules and mix them with other raw materials (such as cement, sand, water, etc) to cast the self-sensing concrete, into which EcoCapsules are implanted permanently. We tested EcoCapsules regarding real-world buildings comprehensively. Our results demonstrate single link throughputs of up to 13 kbps and power-up ranges of up to 6 m. Finally, we demonstrate a long-term pilot study on the structural health monitoring of a real-life footbridge. Lubing Han, Zhenlin An, Lei Yang 0025, Siqi Ding |
SIGCOMM | 4 |
| 2022 | RF-Dial: Rigid Motion Tracking and Touch Gesture Detection for Interaction via RFID TagsabstractWith the rising of demands for novel human-computer interaction approaches in the 2D plane, a number of intelligent devices come into being. For example, Microsoft Surface Dial supports simple clicks and rotations for the interaction with computer. However, these approaches are dedicated devices, and they might require batteries or have limited functions. In this paper, we propose RF-Dial to realize a light-weight, battery-free and functional 2D human-computer interaction solution via commercial off-the-shelf (COTS) passive RFID tags. What RF-Dial shines is that it can easily turn an ordinary object, e.g., a board eraser, into an intelligent interaction device. By deploying a tag array on the side face of the object together with a dipole tag on the top face, RF-Dial cannot only track the rigid motion of the object but also detect the touch gesture of a user on the surface of the object, including translation, rotation, click, press and hold, and swipe. To do the motion tracking, RF-Dial builds a phase-based model that captures the translation and the rotation of the tagged object simultaneously, by jointly exploiting the information of phase variations and the topology of the tag array. To detect the touch gesture, RF-Dial builds an RSSI-based model that uses the impact of the touching finger on the tag antenna’s impedance to estimate the touch position in real time, which is robust to environmental factors like position or orientation. We implemented a prototype of RF-Dial with commodity RFID devices. Extensive experiments show that RF-Dial achieves an accurate rigid motion tracking, with a small error of 0.6cm for the translation tracking, and a small error of 1.9 degrees for the rotation estimation. Besides, RF-Dial can also detect the touch gesture accurately, as the 90 percent of touch position errors are less than 2.09mm. Yanling Bu, Lei Xie 0004, Yinyin Gong, Lei Yang 0025, Jia Liu 0008, Sanglu Lu |
IEEE Trans. Mob. Comput. | 5 |
| 2022 | Tagcaster: Activating Wireless Voice of Electronic Toll Collection Systems With Zero Start-Up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged-fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in the existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented, and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations, and two-thirds of volunteer drivers rate it with a score of 4+ out of 5. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004 |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | LSAB: Enhancing Spatio-temporal Efficiency of AoA Tracking SystemsabstractEstimating the angle-of-arrival (AoA) of an RF source by using a large-sized antenna array is a classical topic in wireless systems. However, AoA tracking systems are not yet used for Internet of Things (IoT) in the real world due to their unaffordable cost. Many efforts, such as a time-sharing array, emulated array, and sparse array, were recently made to cut the cost. This work introduces a log-spiral antenna belt ( LSAB ), a new novel sparse “planar array” that could estimate the AoA of an IoT device in 3D space by using a few antennas connected to a single timeshare channel. Unlike the conventional arrays, LSAB deploys antennas on a log-spiral-shaped belt in a non-linear manner, following the theory of minimum resolution redundancy newly discovered in this work. One physical 8 × 8 uniform planar array (UPA) and four logical sparse arrays, including LSAB , were prototyped to validate the theory and evaluate the performance of sparse arrays. The extensive benchmark demonstrates that the performance of LSAB was comparable to that of a UPA, with similar degree of resolution; and LSAB could provide over 40% performance improvement than existing sparse arrays. We also prototyped a second LSAB adapted to an RFID system for localizing RFID tags at centimeter-level accuracy. Qingrui Pan, Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
ACM Trans. Sens. Networks | 3 |
| 2021 | Turbocharging Deep Backscatter Through Constructive Power Surges with a Single RF SourceabstractBackscatter networks are becoming a promising solution for embedded sensing. In these networks, backscatter sensors are deeply implanted inside objects or living beings and form a deep backscatter network (DBN). The fundamental challenges in DBNs are the significant attenuation of the wireless signal caused by environmental materials (e.g., water and bodily tissues) and the miniature antennas of the implantable backscatter sensors, which prevent existing backscatter networks from powering sensors beyond superficial depths. This study presents RiCharge, a turbocharging solution that enables powering up and communicating with DBNs through a single augmented RF source, which allows existing backscatter sensors to serve DBNs at zero startup cost. The key contribution of RiCharge is the turbocharging algorithm that utilizes RF surges to induce constructive power surges at deep backscatter sensors in accordance with the FCC regulations, for overcoming the turn-on voltage barrier. RiCharge is implemented in commodity devices, and the evaluation result reveals that RiCharge can use only a single RF source to power up backscatter sensors at 60 m distance in the air (i.e., 10x longer than a commercial off-the-shelf reader) and 50 cm-depth under water (i.e., 2x deeper than the previous record). Zhenlin An, Qiongzheng Lin, Qingrui Pan, Lei Yang 0025 |
INFOCOM | 4 |
| 2021 | One tag, two codes: identifying optical barcodes with NFCabstractBarcodes and NFC have become the de facto standards in the field of automatic identification and data capture. These standards have been widely adopted for many applications, such as mobile payments, advertisements, social sharing, admission control, and so on. Recently, considerable demands require the integration of these two codes (barcode and NFC code) into a single tag for the functional complementation. To achieve the goal of "one tag, two codes" (OTTC), this work proposes CoilCode, which takes advantage of the printed electronics to fuse an NFC coil antenna into a QR code on a single layer. The proposed code could be identified by cameras and NFC readers. With the use of the conductive inks, QR code and NFC code have become an essential part of each other: the modules of the QR code facilitate the NFC chip in harvesting energy from the magnetic field, while the NFC antenna itself represents bits of the QR code. Compared to the prior dual-layer OTTC, CoilCode is more compact, cost-effective, flimsy, flexible, and environment-friendly, and also reduces the fabrication complexity considerably. We prototyped hundreds of CoilCodes and conducted comprehensive evaluations (across 4 models of NFC chips and 8 kinds of NFC readers under 13 different system configurations). CoilCode demonstrates high-quality identification results for QR code and NFC functions on a wide range of inputs and under different distortion effects. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Dongliang Zheng, Guiqing Wu, Shan Chang |
MobiCom | 4 |
| 2021 | Revitalizing Ultrasonic Positioning Systems for Ultrasound-Incapable Smart DevicesabstractAn ultrasonic positioning system (UPS) has demonstrated its high accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today’s smart devices, which lack ultrasonic sensors and were considered as being “deaf” to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone’s nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are downconverted to a low-frequency by exploiting the nonlinearity effect at the receiver’s microphone. This underlying property functions as an implicit ultrasonic downconverter without inflicting harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | RFID Harmonic for Vibration SensingabstractConventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome to deploy. Recently research community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by low reading rate and long wavelength, current RFID based solutions can only sense low-frequency (e.g., below 100 Hz) mechanical vibrations with larger amplitude (e.g., >5 mm). To address the issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensingand a newrecovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows (i) TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100 Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500 Hz. (ii) TagSound can achieve a Hz-level frequency estimation even when the vibration amplitude is only 2 mm. Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang, Qiongzheng Lin |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Identifying UHF RFIDs in Range of Readers With WiFiabstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operate at the spectrum between 840~920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
IEEE/ACM Trans. Netw. | 2 |
| 2020 | Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This study is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology and cross-frequency communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g., charged- fees and traffic forecast) to drivers at tollbooths. The key innovation in this work is the engineering of Tagcaster over off-the-shelf ETC systems using shadow carrier and baseband whitening without the need for hardware nor firmware changes. This feature allows zero-cost rapid deployment in existing ETC infrastructure. Two prototypes of Tagcaster are designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g., Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ> 2) and stable AM broadcasting service with a 30 m coverage range. Tagcaster remarkably improves user experience at ETC stations and two- thirds volunteer drivers rate it with a score of 4+ out of 5. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Lei Xie 0004 |
INFOCOM | 3 |
| 2020 | General-purpose deep tracking platform across protocols for the internet of thingsabstractIn recent years, considerable effort has been recently exerted to explore the high-precision RF-tracking systems indoors to satisfy various real-world demands. However, such systems are tailored for a particular type of device (e.g., RFID, WSN or Wi-Fi). With the rapid development of the Internet of Things (IoT), various new wireless protocols (e.g., LoRa, Sigfox, and NB-IoT) have been proposed to accommodate different demands. The coexistence of multiple types of IoT devices forces users to deploy multiple tracking systems in a warehouse or a smart home where various IoT devices are running, which causes huge additional costs in installation and maintenance. To address this issue, this work presents iArk, which is a general-purpose tracking platform for all types of IoT devices working at the ultra high frequency band. Our innovation lies in the design of the "K+1"-model hardware, the protocol free middleware, and the multipath resistant learnware. By the virtue of decoupling from wireless protocols, iArk also allows researchers to concentrate on developing a new tracking algorithm without considering the protocol diversity. To date, the platform can support five mainstream types of IoT devices (i.e., NB-IoT, LoRa, RFID, Sigfox and Zigbee) and is scalable to other types with minimal effort. Zhenlin An, Qiongzheng Lin, Ping Li 0020, Lei Yang 0025 |
MobiSys | 4 |
| 2020 | RFCamera: Identifying RFIDs in Pixel DimensionsabstractRadio Frequency IDentification (RFID) is emerging as a vital technology of the Internet of Things. Billions of RFID tags have been deployed to locate daily objects such as equipment, pharmaceuticals, and vehicles, and so on. Unlike previous solutions that focus on localizing tagged objects in the world coordinate system in reference to reader antennas, this work exploits a system, called RFCamera, that can identify and locate RFID-tagged objects in images with pixel dimensions. Many applications would benefit from RFCamera. For instance, the RF-aware image annotation system is able to generate rich annotations for RFID-tagged entities in images at the pixel level for the deep learning; the RF-aware auto-focus allows surveillance camera to exactly focalize the burglar who carries the stolen tagged-property out of a crowd. Our core insight is that an image is a visual AoA profile in terms of lights, which is resulted from the pinhole camera model. Similarly, we generate an RF image, derived from the AoA profile of a tag using the same pinhole model as the camera. Consequently, the locations of visual entities corresponding to tagged objects are highlighted by comparing two types of images. To this end, we customized a camera system equipped with a pair of rotatable reader antennas. Our experimental evaluation demonstrates that RFCamera enables a mean error of 5.7° and 2.9° at azimuth and elevation angle estimation. It can locate a visual entity with a mean error of 51 pixels (i.e., ≈ 1.3 cm at 96 dpi) in a 640 × 480 image. Qiongzheng Lin, Lei Yang 0025, Zhenlin An, Yi Guo 0008, Ping Li 0020 |
SECON | 2 |
| 2020 | Acquiring Bloom Filters Across Commercial RFIDs in Physical LayerabstractEmbedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address the issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags - allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou, Lei Xie 0004 |
IEEE/ACM Trans. Netw. | 3 |
| 2019 | Embracing Tag Collisions: Acquiring Bloom Filters across RFIDs in Physical LayerabstractEmbedding Radio-Frequency IDentification (RFID) into everyday objects to construct ubiquitous networks has been a long-standing goal. However, a major problem that hinders the attainment of this goal is the current inefficient reading of RFID tags. To address issue, the research community introduces the technique of Bloom Filter (BF) to RFID systems. This work presents TagMap, a practical solution that acquires BFs across commercial off-the-shelf (COTS) RFID tags in the physical layer, enabling upper applications to boost their performance by orders of magnitude. The key idea is to treat all tags as if they were a single virtual sender, which hashes each tag into different intercepted inventories. Our approach does not require hardware nor firmware changes in commodity RFID tags -allows for rapid, zero-cost deployment in existing RFID tags. We design and implement TagMap reader with commodity device (e.g., USRP N210) platforms. Our comprehensive evaluation reveals that the overhead of TagMap is 66.22% lower than the state-of-the-art solution, with a bit error rate of 0.4%. Zhenlin An, Qiongzheng Lin, Lei Yang 0025, Wei Lou |
INFOCOM | 3 |
| 2019 | Towards Physical-Layer Vibration Sensing with RFIDsabstractConventional vibration sensing systems, equipped with specific sensors (e.g., accelerometer) and communication modules, are either expensive or cumbersome in deployment. In recent years, the community revisits this classic topic by taking advantage of off-the-shelf RFIDs. However, limited by lower reading rate and larger wavelength, current RFID based solutions can only sense low-frequency (e.g. below 100Hz) mechanical vibrations with larger amplitude (e.g. (>) 5mm). To address this issue, this work presents TagSound, an RFID-based vibration sensing system that explores a tag's harmonic backscattering to recover high-frequency and tiny mechanical vibrations accurately. The key innovations are in two aspects: harmonics based sensing and a new recovery scheme. We implement TagSound with USRP platforms. Our comprehensive evaluation shows TagSound can achieve a mean error of 0.37 Hz when detecting vibrations at frequencies below 100Hz, and a mean error of 4.2 Hz even when the vibration frequency is up to 2500Hz. Ping Li 0020, Zhenlin An, Lei Yang 0025, Panlong Yang |
INFOCOM | 3 |
| 2019 | Demo: Activating Wireless Voice for E-Toll Collection Systems with Zero Start-up CostabstractThis work enhances the machine-to-human communication between electronic toll collection (ETC) systems and drivers by providing an AM broadcast service to deployed ETC systems. This demo is the first to show that ultra-high radio frequency identification signals can be received by an AM radio receiver due to the presence of the nonlinearity effect in the AM receiver. Such a phenomenon allows the development of a previously infeasible cross-technology communication, called Tagcaster, which converts an ETC reader to an AM station for broadcasting short messages (e.g, charged-fees and traffic forecast) to drivers at tollbooths. The prototype of Tagcaster is designed, implemented and evaluated over four general and five vehicle-mounted AM receivers (e.g, Toyota, Audi, and Jetta). Experiments reveal that Tagcaster can provide good-quality (PESQ>2) and stable AM broadcasting service with a 30m coverage range. Zhenlin An, Lei Yang 0025, Qiongzheng Lin |
MobiCom | 2 |
| 2019 | Rebooting Ultrasonic Positioning Systems for Ultrasound-incapable Smart DevicesabstractAn ultrasonic Positioning System (UPS) has outperformed RF-based systems in terms of its accuracy for years. However, few of the developed solutions have been deployed in practice to satisfy the localization demand of today's smart devices, which lack ultrasonic sensors and were considered as being "deaf'' to ultrasound. A recent finding demonstrates that ultrasound may be audible to the smart devices under certain conditions due to their microphone's nonlinearity. Inspired by this insight, this work revisits the ultrasonic positioning technique and builds a practical UPS, called UPS+, for ultrasound-incapable smart devices. The core concept is to deploy two types of indoor beacon devices, which will advertise ultrasonic beacons at two different ultrasonic frequencies respectively. Their superimposed beacons are shifted to a low-frequency by virtue of the nonlinearity effect at the receiver's microphone. This underlying property functions as an implicit ultrasonic downconverter without throwing harm to the hearing system of humans. We demonstrate UPS+, a fully functional UPS prototype, with centimeter-level localization accuracy using custom-made beacon hardware and well-designed algorithms. Qiongzheng Lin, Zhenlin An, Lei Yang 0025 |
MobiCom | 3 |
| 2019 | Proactive Batch Authentication: Fishing Counterfeit RFID Tags in Muddy WatersabstractRadio frequency identification technology has been recently employed as an effective solution for anti-counterfeiting. By attaching a tag on each product, a reader can provide a fast and automatic authentication. However, most of existing approaches adopt a per-tag approach to validate each product, which will incur a long scanning time and communication traffic when there are many products to be concurrently authenticated. To address these issues, batch authentication, e.g., SEBA, is proposed in recent literature. Batch authentication is an identification-free and probabilistic approach and aims to authenticate the validity of a batch of tags. Unfortunately, the existing batch authentication still suffers a serious scalability problem where the system cost linearly depends on the total number of genuine tags, e.g.,${\mathcal {O}(N)}$. Its efficiency will significantly decrease and even be worse than the per-tag approach when there is a large number of genuine tags in the system. This limitation hinders the batch authentication to be widely used in practice because there are up to millions of total genuine tags in usual. In this paper, we propose FISH, which is also probabilistic batch authentication-based, to overcome the scalability problem by reducing the dependence to${\mathcal {O}(\log (N))}$. Moreover, FISH owns the following two salient advantages: 1) FISH can identify the genuine products when there is no counterfeit product in the batch although it is identification-free in essence and 2) FISH can defend against silence attack by utilizing Pearson Chi-square test. Last, we also conduct the theoretical analysis and extensive simulation with the real logistics trace Qiongzheng Lin, Lei Yang 0025, Yi Guo 0008 |
IEEE Internet Things J. | 2 |
| 2019 | iLogBook: Enabling Text-Searchable Event Query Using Sparse Vehicle-Mounted GPS DataabstractQuerying an incident (i.e., an occurrence of seemingly minor importance) from coarse-grained driving log (i.e., GPS trace) has been a daunting task. For example, “Which restaurant did I drive by at exactly 4 pm yesterday?” The question seems very simple but is nontrivial, because the question is semantics-driven while the actual log data are GPS coordinate-based. Especially, the practical GPS log is very sparse and inaccurate for high-speed mobile objects such as vehicles. This paper seeks to answer any fuzzy query over sparse vehicles GPS data. Our system, called iLogBook, achieves these two goals by leveraging tensor technique and latent semantic analysis to high-precision trajectory recovery and similarity matching. We have implemented and evaluated the iLogBook with the GPS data of over 13, 798 taxicabs collected in eight days in Shenzhen, China. Our results show about 97% accuracy in trajectory inference. Moreover, the system handles about 90% daily queries among 10 marked drivers. Siqian Yang, Cheng Wang 0001, Lei Yang 0025, Changjun Jiang 0002 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2019 | Robust Spinning Sensing with Dual-RFID-Tags in Noisy SettingsabstractConventional spinning inspection systems, equipped with separated sensors (e.g., accelerometer, laser, etc.) and communication modules, are either very expensive and/or suffering from occlusion and narrow field of view. The recently proposed RFID-based sensing solution draws much attention due to its intriguing features, such as being cost-effective, applicable to occluded objects, auto-identification, etc. However, this solution only works in quiet settings where both the reader and spinning object remain absolutely stationary, as their shaking would ruin the periodicity and sparsity of the spinning signal, making it impossible to be recovered. To overcome such limitation, this work introduces Tagtwins, a robust spinning sensing system that can work in noisy settings. It addresses the challenge by attaching dual RFID tags on the spinning surface and developing a new formulation of spinning signal that is shaking-resilient, even if the shaking involves unknown trajectories. Our main contribution lies in two newly developed techniques. First, we propose relative spinning signal using dual tags' readings and analytically demonstrate its feasibility in various settings. Second, we introduce dual compressive reading to inspect high-frequency spinning with relatively low reading rate of RFIDs. We have implemented Tagtwins with commercial RFID devices and evaluated it extensively. Experimental results show that Tagtwins can inspect the rotation frequency with high accuracy and robustness. Chunhui Duan, Lei Yang 0025, Qiongzheng Lin, Yunhao Liu 0001, Lei Xie 0004 |
IEEE Trans. Mob. Comput. | 2 |
| 2019 | Revisiting Reading Rate with Mobility: Rate-Adaptive Reading of COTS RFID SystemsabstractRadio-frequency identification (RFID) systems, as major enablers of automatic identification, are currently supplemented with various interesting sensing functions, e.g., motion tracking. All these sensing applications forcedly require much higher reading rate (i.e., sampling rate) such that any fast movement of tagged objects can be accurately captured in a timely manner through tag readings. However, COTS RFID systems suffer from an extremely low individual reading rate when multiple tags are present, due to their intense channel contention in the link layer. In this work, we present a holistic system, called Tagwatch, a rate-adaptive reading system for COTS RFID devices. This work revisits the reading rate from a distinctive perspective: mobility. We observe that the reading demands of mobile tags are considerably more urgent than those of stationary tags because the states of the latter nearly remain unchanged; meanwhile, only a few tags (e.g., <; 20%) are actually in motion despite the existence of a massive amount of tags in practice. Thus, Tagwatch adaptively improves the reading rates for mobile tags by cutting down the readings of stationary tags. Our main contribution is a two-phase reading design, wherein the mobile tags are discriminated in the Phase I and exclusively read in the Phase II. We built a prototype of Tagwatch with COTS RFID readers and tags. Results from our microbenchmark analysis demonstrate that the new design outperforms the reading rate by 3:2× when 5 percent of tags are moving. Qiongzheng Lin, Lei Yang 0025, Chunhui Duan, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2019 | Tash: Toward Selective Reading as Hash Primitives for Gen2 RFIDsabstractDeployment of billions of commercial off-the-shelf (COTS) radio frequency identification (RFID) tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predictable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a ten-year untouchable mirage. This paper designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function, and tash operator. All of these hash primitives are implemented through the selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication-a feature allowing zero-cost fast deployment on billions of Gen2 tags. We further apply our hash primitives in one typical HEP application (i.e., missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3000 Alien tags, demonstrate that the new design lowers 70% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%. Qiongzheng Lin, Lei Yang 0025, Chunhui Duan, Zhenlin An |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | RF-Dial: An RFID-based 2D Human-Computer Interaction via Tag ArrayabstractNowadays, the demand for novel approaches of 2D human-computer interaction has enabled the emergence of a number of intelligent devices, such as Microsoft Surface Dial. Surface Dial realizes 2D interactions with the computer via simple clicks and rotations. In this paper, we propose RF-Dial, a battery-free solution for 2D human-computer interaction based on RFID tag arrays. We attach an array of RFID tags on the surface of an object, and continuously track the translation and rotation of the tagged object with an orthogonally deployed RFID antenna pair. In this way, we are able to transform an ordinary object like a board eraser into an intelligent HCI device. According to the RF-signals from the tag array, we build a geometric model to depict the relationship between the phase variations of the tag array and the rigid transformation of the tagged object, including the translation and rotation. By referring to the fixed topology of the tag array, we are able to accurately extract the translation and rotation of the tagged object during the moving process. Moreover, considering the variation of phase contours of the RF-signals at different positions, we divide the overall scanning area into the linear region and non-linear region in regard to the relationship between the phase variation and the tag movement, and propose tracking solutions for the two regions, respectively. We implemented a prototype system and evaluated the performance of RF-Dial in the real environment. The experiments show that RF-Dial achieved an average accuracy of 0. 6cm in the translation tracking, and an average accuracy of 1.9°in the rotation tracking. Yanling Bu, Lei Xie 0004, Yinyin Gong, Lei Yang 0025, Jia Liu 0008, Sanglu Lu |
INFOCOM | 5 |
| 2018 | Robust Spinning Sensing with Dual-RFID-Tags in Noisy SettingsabstractConventional spinning inspection systems, equipped with separated sensors (e.g., accelerometer, laser, etc.) and communication modules, are either very expensive and/or suffering from occlusion and narrow field of view. The recently proposed RFID-based sensing solution draws much attention due to its intriguing features, such as being cost-effective, applicable to occluded objects and auto-identification, etc. However, this solution only works in quiet settings where the reader and spinning object remain absolutely stationary, as their shaking would ruin the periodicity and sparsity of the spinning signal, making it impossible to be recovered. This work introduces Tagtwins, a robust spinning sensing system that can work in noisy settings. It addresses the challenge by attaching dual RFID tags on the spinning surface and developing a new formulation of spinning signal that is shaking-resilient, even if the shaking involves unknown trajectories. Our main contribution lies in two newly developed techniques, relative spinning signal and dual compressive reading. We analytically demonstrate that our solution can work in various settings. We have implemented Tagtwins with COTS RFID devices and evaluated it extensively. Experimental results show that Tagtwins can inspect the rotation frequency with high accuracy and robustness. Chunhui Duan, Lei Yang 0025, Huanyu Jia, Qiongzheng Lin, Yunhao Liu 0001, Lei Xie 0004 |
INFOCOM | 2 |
| 2018 | Cross-Frequency Communication: Near-Field Identification of UHF RFIDs with WiFi!abstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (e.g., 2.4 GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. Our work, which is called TiFi, challenges this belief by allowing a 2.4 GHz WiFi receiver (e.g., a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840 - 920 MHz. TiFi does not require changing current smartphones or tags. Instead, it leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement TiFi with commodity WiFi chipsets (e.g., Broadcom BCM43xx, Murata KM6D280 40, and Qualcomm WCN3990). Our comprehensive evaluation shows that TiFi allows WiFi receivers to identify UHF RFID tags within the range of 2 m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
MobiCom | 3 |
| 2018 | Demo: Near-Field Identification of UHF RFIDs with WiFi!abstractRecent advances in Cross-Technology Communication (CTC) have improved efficient cooperation among heterogeneous wireless devices. To date, however, even the most effective CTC systems require these devices to operate in the same ISM band (eg. 2.4GHz) because of the conventional wisdom that wireless transceivers with different (fundamental) frequencies cannot communicate with one another. In this demo, we present a practical CTC application, called øursystem, allowing a 2.4GHz WiFi receiver (eg. a smartphone) to identify UHF RFID tags, which operates at the spectrum between 840~920MHz. øursystem leverages the underlying harmonic backscattering of tags to open a second channel and uses it to communicate with WiFi receivers. We design and implement øursystem with commodity WiFi chipsets. Our comprehensive evaluation shows that øursystem allows WiFi receivers to identify UHF RFID tags within the range of $2$ m and with a median goodput of 95%, which is comparable to today's mobile RFID readers. Zhenlin An, Qiongzheng Lin, Lei Yang 0025 |
MobiCom | 3 |
| 2018 | Device-free human localization and tracking with UHF passive RFID tags: A data-driven approach
Wenjie Ruan, Quan Z. Sheng, Lina Yao 0001, Xue Li 0001, Nick Falkner, Lei Yang 0025 |
J. Netw. Comput. Appl. | 6 |
| 2018 | Tagspin: High Accuracy Spatial Calibration of RFID Antennas via Spinning TagsabstractRecent years have witnessed the advance of RFID-based localization techniques that demonstrate high precision. Many efforts have been made locating RFID tags accurately with a mandatory assumption that the RFID reader's position is known in advance. Unfortunately, calibrating reader's location manually is always time-consuming and laborious in practice. In this paper, we present Tagspin, an approach using COTS tags to pinpoint the reader (antenna) quickly and easily with high accuracy. Tagspin enables each tag to emulate a circular antenna array by uniformly spinning on the edge of a rotating disk. We design an SAR-based method for estimating the angle spectrum of the target reader. Compared to previous AoA-based techniques, we employ an enhanced power profile modeling the relative signal power received from the reader along different spatial directions, which is more accurate and immune to ambient noise as well as measurement errors caused by hardware characteristics. Besides, we find that tag's phase measurements in practice are related to its orientation. To the best of our knowledge, we are the first to point out this fact and quantify the relationship between them. By calibrating the phase shifts caused by orientation, the positioning accuracy can be improved by 3:7×. We have implemented Tagspin with COTS RFID devices and evaluated it extensively. Experimental results show that Tagspin achieves mean accuracy of 7:3 cm with standard deviation of 1:8 cm in 3D space. Chunhui Duan, Lei Yang 0025, Qiongzheng Lin, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2018 | Making Sense of Doppler Effect for Multi-Modal Hand Motion DetectionabstractHand gesture is becoming an increasingly popular means of interacting with consumer electronic devices, such as mobile phones, tablets and laptops. In this paper, we present AudioGest, a device-free gesture recognition system that can accurately sense the hand in-air movement around user's devices. Compared to the state-of-the-art techniques, AudioGest is superior in using only one pair of built-in speaker and microphone, without any extra hardware or infrastructure support and with no training, to achieve multimodal hand detection. Specifically, our system is not only able to accurately recognize various hand gestures, but also reliably estimate the hand in-air duration, average moving speed and waving range. We achieve this by transforming the device into an active sonar system that transmits inaudible audio signal and decodes the echoes of hand's movement at its microphone. We address various challenges including cleaning the noisy reflected sound signal, interpreting the echo spectrogram into hand gestures, decoding the Doppler frequency shifts into the hand waving speed and range, as well as being robust to the environmental motion and signal drifting. We extensively evaluate our system on three electronic devices under four real-world scenarios using overall 3,900 hand gestures collected by five users for more than two weeks. Our results show that AudioGest detects six hand gestures with an accuracy up to 96 percent. By distinguishing the gesture attributions, it can provide more fine-grained control commands for various applications. Wenjie Ruan, Quan Z. Sheng, Peipei Xu, Lei Yang 0025, Tao Gu 0001, Longfei Shangguan |
IEEE Trans. Mob. Comput. | 4 |
| 2017 | Revisiting Reading Rate with Mobility: Rate-Adaptive Reading in COTS RFID SystemsabstractRadio-frequency identification (RFID) systems, as major enablers of automatic identification, are currently supplemented with various interesting sensing functions, e.g., motion tracking. All these sensing applications forcedly require much higher reading rate (i.e., sampling rate) such that any fast movement of tagged objects can be accurately captured in a timely manner through tag readings. However, COTS RFID systems suffer from an extremely low individual reading rate when multiple tags are present, due to their intense channel contention in the link layer. In this work, we present a holistic system, called Tagwatch, a rate-adaptive reading system for COTS RFID devices. This work revisits the reading rate from a distinctive perspective: mobility. We observe that the reading demands of mobile tags are considerably more urgent than those of stationary tags because the states of the latter nearly remain unchanged; meanwhile, only a few tags (e.g., < 20%) are actually in motion despite the existence of a massive amount of tags in practice. Thus, Tagwatch adaptively improves the reading rates for mobile tags by cutting down the readings of stationary tags. Our main contribution is a two-phase reading design, wherein the mobile tags are discriminated in the Phase I and exclusively read in the Phase II. We built a prototype of Tagwatch with COTS RFID readers and tags. Results from our microbenchmark analysis demonstrate that the new design outperforms the reading rate by 3.2x when 5% of tags are moving. Qiongzheng Lin, Lei Yang 0025, Huanyu Jia, Chunhui Duan, Yunhao Liu 0001 |
CoNEXT | 2 |
| 2017 | Fusing RFID and computer vision for fine-grained object trackingabstractIn recent years, both the RFID and computer vision technologies have been widely employed in indoor scenarios aimed at different goals while faced with respective limitations. For example, the RFID-based EAS system is useful in quickly identifying tagged objects but the accompanying false alarm problem is troublesome and hard to tackle with except that the accurate trajectory of the target tag can be easily acquired. On the other side, the CV system performs fairly well in tracking multiple moving objects precisely while finding it difficult to screen out the specific target among them. To overcome the above limitations, we present TagVision, a hybrid RFID and computer vision system for fine-grained localization and tracking of tagged objects. A fusion algorithm is proposed to organically combine the position information given by the CV subsystem, and phase data output by the RFID subsystem. In addition, we employ the probabilistic model to eliminate the measurement error caused by thermal noise and device diversity. We have implemented TagVision with COTS camera and RFID devices and evaluated it extensively in our lab environment. Experimental results show that TagVision can achieve 98% blob matching accuracy and 10.33mm location tracking precision. Chunhui Duan, Xing Rao, Lei Yang 0025, Yunhao Liu 0001 |
INFOCOM | 3 |
| 2017 | TagScreen: Synchronizing social televisions through hidden sound markersabstractMillions of people nowadays share their television (TV) experience with other people through social media like Twitter or Facebook with mobile devices. It is generally believed that TV has been repurposed for social networks, called as social television. A key functionality of social television is that it allows the viewers to interchange their comments through mobile devices, thus creating the impression of watching TV like alongside a group of friends. To do so, mobile devices have to be aware of the current media context (identifier and progress) of what the TV is playing, known as synchronizing context from TVs to mobile devices. Unfortunately, most legacy systems are not able to track the playing progresses or need to upgrade TV devices. To address the issue, we design a purely software-based solution, called as TagScreen, which inserts a series of hidden sound markers into the audio of the content. TagScreen supports longrange or multipath-resistant synchronization at second-level, being independent of device diversity over severely frequency-selective acoustic channels. We implement TagScreen by using COTS TVs and mobile devices. The system has been extensively tested on 150 movies and 150 TV series across five different environments. Results show that TagScreen has a mean recognition accuracy of 98% up to 35m, and a mean tracking accuracy of 97%. Qiongzheng Lin, Lei Yang 0025, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2017 | Analog On-Tag Hashing: Towards Selective Reading as Hash Primitives in Gen2 RFID SystemsabstractDeployment of billions of Commercial Off-The-Shelf (COTS) RFID tags has drawn much of the attention of the research community because of the performance gaps of current systems. In particular, hash-enabled protocol (HEP) is one of the most thoroughly studied topics in the past decade. HEPs are designed for a wide spectrum of notable applications (e.g., missing detection) without need to collect all tags. HEPs assume that each tag contains a hash function, such that a tag can select a random but predicable time slot to reply with a one-bit presence signal that shows its existence. However, the hash function has never been implemented in COTS tags in reality, which makes HEPs a 10-year untouchable mirage. This work designs and implements a group of analog on-tag hash primitives (called Tash) for COTS Gen2-compatible RFID systems, which moves prior HEPs forward from theory to practice. In particular, we design three types of hash primitives, namely, tash function, tash table function and tash operator. All of these hash primitives are implemented through selective reading, which is a fundamental and mandatory functionality specified in Gen2 protocol, without any hardware modification and fabrication. We further apply our hash primitives in two typical HEP applications (i.e., cardinality estimation and missing detection) to show the feasibility and effectiveness of Tash. Results from our prototype, which is composed of one ImpinJ reader and 3,000 Alien tags, demonstrate that the new design lowers 60% of the communication overhead in the air. The tash operator can additionally introduce an overhead drop of 29.7%. Lei Yang 0025, Qiongzheng Lin, Chunhui Duan, Zhenlin An |
MobiCom | 1 |
| 2017 | Tagbeat: Sensing Mechanical Vibration Period With COTS RFID SystemsabstractTraditional vibration inspection systems, equipped with separated sensing and communication modules, are either very expensive (e.g., hundreds of dollars) and/or suffer from occlusion and narrow field of view (e.g., laser). In this paper, we present an RFID-based solution, Tagbeat, to inspect mechanical vibration using COTS RFID tags and readers. Making sense of micro and high-frequency vibration using random and low-frequency readings of tag has been a daunting task, especially challenging for achieving sub-millisecond period accuracy. Our system achieves these three goals by discerning the change pattern of backscatter signal replied from the tag, which is attached on the vibrating surface and displaced by the vibration within a small range. This paper introduces three main innovations. First, it shows how one can utilize COTS RFID to sense mechanical vibration and accurately discover its period with a few periods of short and noisy samples. Second, a new digital microscope is designed to amplify the micro-vibration-induced weak signals. Third, Tagbeat introduces compressive reading to inspect high-frequency vibration with relatively low RFID read rate. We implement Tagbeat using a COTS RFID device and evaluate it with a commercial centrifugal machine. Empirical benchmarks with a prototype show that Tagbeat can inspect the vibration period with a mean accuracy of 0.36ms and a relative error rate of 0.03%. We also study three cases to demonstrate how to associate our inspection solution with the specific domain requirements. Lei Yang 0025, Qiongzheng Lin, Huanyu Jia, Xiang-Yang Li 0001, Yunhao Liu 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | Design and Implementation of an RFID-Based Customer Shopping Behavior Mining SystemabstractShopping behavior data is of great importance in understanding the effectiveness of marketing and merchandising campaigns. Online clothing stores are capable of capturing customer shopping behavior by analyzing the click streams and customer shopping carts. Retailers with physical clothing stores, however, still lack effective methods to comprehensively identify shopping behaviors. In this paper, we show that backscatter signals of passive RFID tags can be exploited to detect and record how customers browse stores, which garments they pay attention to, and which garments they usually pair up. The intuition is that the phase readings of tags attached to items will demonstrate distinct yet stable patterns in a time-series when customers look at, pick out, or turn over desired items. We design ShopMiner, a framework that harnesses these unique spatial-temporal correlations of time-series phase readings to detect comprehensive shopping behaviors. We have implemented a prototype of ShopMiner with a COTS RFID reader and four antennas, and tested its effectiveness in two typical indoor environments. Empirical studies from two-week shopping-like data show that ShopMiner is able to identify customer shopping behaviors with high accuracy and low overhead, and is robust to interference. Zimu Zhou, Longfei Shangguan, Xiaolong Zheng 0002, Lei Yang 0025, Yunhao Liu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | AudioGest: enabling fine-grained hand gesture detection by decoding echo signalabstractHand gesture is becoming an increasingly popular means of interacting with consumer electronic devices, such as mobile phones, tablets and laptops. In this paper, we present AudioGest, a device-free gesture recognition system that can accurately sense the hand in-air movement around user's devices. Compared to the state-of-the-art, AudioGest is superior in using only one pair of built-in speaker and microphone, without any extra hardware or infrastructure support and with no training, to achieve fine-grained hand detection. Our system is able to accurately recognize various hand gestures, estimate the hand in-air time, as well as average moving speed and waving range. We achieve this by transforming the device into an active sonar system that transmits inaudible audio signal and decodes the echoes of hand at its microphone. We address various challenges including cleaning the noisy reflected sound signal, interpreting the echo spectrogram into hand gestures, decoding the Doppler frequency shifts into the hand waving speed and range, as well as being robust to the environmental motion and signal drifting. We implement the proof-of-concept prototype in three different electronic devices and extensively evaluate the system in four real-world scenarios using 3,900 hand gestures that collected by five users for more than two weeks. Our results show that AudioGest can detect six hand gestures with an accuracy up to 96%, and by distinguishing the gesture attributions, it can provide up to 162 control commands for various applications. Wenjie Ruan, Quan Z. Sheng, Lei Yang 0025, Tao Gu 0001, Peipei Xu, Longfei Shangguan |
UbiComp | 3 |
| 2016 | Accurate Spatial Calibration of RFID Antennas via Spinning TagsabstractRecent years have witnessed the advance of RFID-based localization techniques that demonstrate high precision. Many efforts have been made locating RFID tags with a mandatory assumption that the RFID reader's position is known in advance. Unfortunately, calibrating reader's location manually is always time-consuming and laborious in practice. In this paper, we present Tagspin, an approach using COTS tags to pinpoint the reader (antenna) quickly and easily with high accuracy. Tagspin enables each tag to emulate a circular antenna array by uniformly spinning on the edge of a rotating disk. We design an SAR-based method for estimating the angle spectrum of the target reader. Compared to previous AoA-based techniques, we employ an enhanced power profile modeling the signal power received from the reader along different spatial directions, which is more accurate and immune to ambient noise as well as measurement errors caused by hardware characteristics. Besides, we find that tag's phase measurements in practice are related to its orientation. To the best of our knowledge, we are the first to point out this fact and quantify the relationship between them. By calibrating the phase shifts caused by orientation, the positioning accuracy can be improved by 3.7×. We have implemented Tagspin withCOTS RFID devices and evaluated it extensively. Experimentalresults show that Tagspin achieves mean accuracy of 7.3cm with standard deviation of 1.8cm in 3D space. Chunhui Duan, Lei Yang 0025, Yunhao Liu 0001 |
ICDCS | 2 |
| 2016 | Making sense of mechanical vibration with COTS RFID systems: demoabstractTraditional vibration inspection systems, equipped with separated sensing and communication modules, are either very expensive (e.g. hundreds of dollars) and/or suffer from occlusion and narrow field of view (e.g. laser). This demo brings forward a concept of 'communication is sensing', which is to make sense of the world purely based on communication carrier rather than specialized sensors. In this demo, we present an RFID-based solution, called Tagbeat, to inspect mechanical vibration using COTS RFID tags and readers. We implement our system using a COTS RFID device and evaluate it with a commercial centrifugal machine. Empirical benchmarks with a prototype show that our system can inspect the vibration period with a mean accuracy of 0.36ms and a relative error rate of 0.03%. Lei Yang 0025, Qiongzheng Lin |
MobiCom | 1 |
| 2016 | Making sense of mechanical vibration period with sub-millisecond accuracy using backscatter signalsabstractTraditional vibration inspection systems, equipped with separated sensing and communication modules, are either very expensive (e.g., hundreds of dollars) and/or suffer from occlusion and narrow field of view (e.g., laser). In this work, we present an RFID-based solution, Tagbeat, to inspect mechanical vibration using COTS RFID tags and readers. Making sense of micro and high-frequency vibration using random and low-frequency readings of tag has been a daunting task, especially challenging for achieving sub-millisecond period accuracy. Our system achieves these three goals by discerning the change pattern of backscatter signal replied from the tag, which is attached on the vibrating surface and displaced by the vibration within a small range. This work introduces three main innovations. First, it shows how one can utilize COTS RFID to sense mechanical vibration and accurately discover its period with a few periods of short and noisy samples. Second, a new digital microscope is designed to amplify the micro-vibration-induced weak signals. Third, Tagbeat introduces compressive reading to inspect high-frequency vibration with relatively low RFID read rate. We implement Tagbeat using a COTS RFID device and evaluate it with a commercial centrifugal machine. Empirical benchmarks with a prototype show that Tagbeat can inspect the vibration period with a mean accuracy of 0.36ms and a relative error rate of 0.03%. We also study three cases to demonstrate how to associate our inspection solution with the specific domain requirements. Lei Yang 0025, Qiongzheng Lin, Xiang-Yang Li 0001, Yunhao Liu 0001 |
MobiCom | 1 |
| 2016 | BackPos: High Accuracy Backscatter Positioning SystemabstractRadio frequency identification (RFID) technology has been widely adopted in a variety of applications from logistics to access control. Many applications gain benefits from knowing the exact position of an RFID-tagged object. Existing localization algorithms in wireless network, however, can hardly be directly employed due to tag's limited capabilities in terms of energy and memory. In this paper, we propose BackPos, a fine-grained backscatter positioning technique using the commercial off-the-shelf (COTS) RFID products with detected phases. Our studies show that the phase is a stable indicator highly related to tag's position and preserved over frequency or tag orientation, but challenged by its periodicity and tag's diversity. We attempt to infer the distance differences from phases detected by antennas under triangle constraint. Further, hyperbolic positioning using the distance differences is employed to shrink the tag's candidate positions until finding out the real one. In combination with interrogation zone, we finally relax the triangle constraint and allow arbitrary deployment of antennas by sacrificing the feasible region. We implement a prototype of BackPos with COTS RFID products and evaluate this design in various scenarios. The results show that BackPos achieves the mean accuracy of 12:8cm with variance of 3:8 cm. Tianci Liu 0002, Yunhao Liu 0001, Lei Yang 0025, Yi Guo 0008, Cheng Wang 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | Beyond one-dollar mouse: A battery-free device for 3D human-computer interaction via RFID tagsabstractFor today's computer users, the mouse plays such an important role that it dominates the interaction interface in personal computer for nearly half a century since it was invented. However, the mouse is gradually unfit for the demand of modern 3D display techniques, e.g. 3D-projection or -screen, for the reason that the relevant interactions are confined in a surface. Although some new methods such as computer vision based techniques attempt to bridge the human-computer barrier, they suffer from many limitations such as ambiguity in multitargets and dependence on light. This paper presents a battery-free device called Tagball for 3D human-computer interaction via RFID tags. Tagball devises a control ball, on which N passive tags are attached, for users to generate two basic kinds of interactive commands: translation and rotation. Instead of locating N tags independently, we model the ball as a whole in a more cooperative way under the circumstance that their geometric relationships are known in advance. In addition, we consider the phase values measured by M RF antennas for these N tags as observations of the ball state. Our key innovations are the studies on motion behaviors of a group of tags by using Extended Kalman Filter, and the implementation based on purely Commercial Off-The-Shelf (COTS) RFID products. The systematical evaluation shows that Tagball traces the ball translation to 1.5cm and identifies ball orientation to 1.8° in 3D space. Qiongzheng Lin, Lei Yang 0025, Tianci Liu 0002, Xiang-Yang Li 0001, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2015 | TagBooth: Deep shopping data acquisition powered by RFID tagsabstractTo stay competitive, plenty of data mining techniques have been introduced to help stores better understand consumers' behaviors. However, these studies are generally confined within the customer transaction data. Actually, another kind of `deep shopping data', e.g. which and why goods receiving much attention are not purchased, offers much more valuable information to boost the product design. Unfortunately, these data are totally ignored in legacy systems. This paper introduces an innovative system, called TagBooth, to detect commodities' motion and further discover customers' behaviors, using COTS RFID devices. We first exploit the motion of tagged commodities by leveraging physical-layer information, like phase and RSS, and then design a comprehensive solution to recognize customers' actions. The system has been tested extensively in the lab environment and used for half a year in real retail store. As a result, TagBooth generally performs well to acquire deep shopping data with high accuracy. Tianci Liu 0002, Lei Yang 0025, Xiang-Yang Li 0001, Huaiyi Huang, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2015 | Anti-counterfeiting via federated RFID tags' fingerprints and geometric relationshipsabstractRFID has been widely adopted as an effective method for anti-counterfeiting. Legacy systems based on security protocol are either too heavy to be affordable by passive tags or suffering from various protocol-layer attacks, e.g. reverse engineering, cloning, side-channel. In this work, we present a novel anti-counterfeiting system, TagPrint, using COTS RFID tags and readers. Achieving a low-cost and offline genuineness validation utilizing passive tags has been a daunting task. Our system achieves these three goals by leveraging a few of federated tags' fingerprints and geometric relationships. In TagPrint, we exploit a new kind of fingerprint, called phase fingerprint, extracted from the phase value of the backscattered signal, provided by the COTS RFID readers. To further solve the separation challenge, we devise a geometric solution to validate the genuineness. We have implemented a prototype of TagPrint using COTS RFID devices. The system has been tested extensively over 6,000 tags. The results show that our new fingerprint exhibits a good fitness of uniform distribution and the system achieves a surprising Equal Error Rate of 0.1% for anti-counterfeiting. Lei Yang 0025, Fan Dang 0001, Cheng Wang 0001, Xiang-Yang Li 0001, Yunhao Liu 0001 |
INFOCOM | 1 |
| 2015 | See Through Walls with COTS RFID System!abstractThrough-wall tracking has gained a lot of attentions in civilian applications recently. Many applications would benefit from such device-free tracking, e.g. elderly people surveillance, intruder detection, gaming, etc. In this work, we present a system, named Tadar, for tracking moving objects without instrumenting them us- ing COTS RFID readers and tags. It works even through walls and behind closed doors. It aims to enable a see-through-wall technology that is low-cost, compact, and accessible to civilian purpose. In traditional RFID systems, tags modulate their IDs on the backscatter signals, which is vulnerable to the interferences from the ambient reflections. Unlike past work, which considers such vulnerability as detrimental, our design exploits it to detect surrounding objects even through walls. Specifically, we attach a group of RFID tags on the outer wall and logically convert them into an antenna array, receiving the signals reflected off moving objects. This paper introduces two main innovations. First, it shows how to eliminate the flash (e.g. the stronger reflections off walls) and extract the reflections from the backscatter signals. Second, it shows how to track the moving object based on HMM (Hidden Markov Model) and its reflections. To the best of our knowledge, we are the first to implement a through-wall tracking using the COTS RFID systems. Empirical measurements with a prototype show that Tadar can detect objects behind 5" hollow wall and 8" concrete wall, and achieve median tracking errors of 7.8cm and 20cm in the X and Y dimensions. Lei Yang 0025, Qiongzheng Lin, Xiang-Yang Li 0001, Tianci Liu 0002, Yunhao Liu 0001 |
MobiCom | 1 |
| 2015 | ShopMiner: Mining Customer Shopping Behavior in Physical Clothing Stores with COTS RFID DevicesabstractShopping behavior data are of great importance to understand the effectiveness of marketing and merchandising efforts. Online clothing stores are capable capturing customer shopping behavior by analyzing the click stream and customer shopping carts. Retailers with physical clothing stores, however, still lack effective methods to identify comprehensive shopping behaviors. In this paper, we show that backscatter signals of passive RFID tags can be exploited to detect and record how customers browse stores, which items of clothes they pay attention to, and which items of clothes they usually match with. The intuition is that the phase readings of tags attached on desired items will demonstrate distinct yet stable patterns in the time-series when customers look at, pick up or turn over desired items. We design ShopMiner,, a framework that harnesses these unique spatial-temporal correlations of time-series phase readings to detect comprehensive shopping behaviors. We have implemented a prototype of ShopMiner, with a COTS RFID reader and four antennas, and tested its effectiveness in two typical indoor environments. Empirical studies from two-week shopping-like data show that ShopMiner, could achieve high accuracy and efficiency in customer shopping behavior identification. Longfei Shangguan, Zimu Zhou, Xiaolong Zheng 0002, Lei Yang 0025, Yunhao Liu 0001, Jinsong Han |
SenSys | 4 |
| 2015 | Unlocking Smart Phone through Handwaving BiometricsabstractScreen locking/unlocking is important for modern smart phones to avoid the unintentional operations and secure the personal stuff. Once the phone is locked, the user should take a specific action or provide some secret information to unlock the phone. The existing unlocking approaches can be categorized into four groups: motion, password, pattern, and fingerprint. Existing approaches do not support smart phones well due to the deficiency of security, high cost, and poor usability. We collect 200 users' handwaving actions with their smart phones and discover an appealing observation: the waving pattern of a person is kind of unique, stable and distinguishable. In this paper, we propose OpenSesame, which employs the users' waving patterns for locking/unlocking. The key feature of our system lies in using four fine-grained and statistic features of handwaving to verify users. Moreover, we utilize support vector machine (SVM) for accurate and fast classification. Our technique is robust compatible across different brands of smart phones, without the need of any specialized hardware. Results from comprehensive experiments show that the mean false positive rate of OpenSesame is around 15 percent, while the false negative rate is lower than 8 percent. Lei Yang 0025, Yi Guo 0008, Jinsong Han, Yunhao Liu 0001, Cheng Wang 0001, Changwei Hu |
IEEE Trans. Mob. Comput. | 1 |
| 2015 | Perceiving the Slightest Tag Motion beyond LocalizationabstractExisting methods in RFID systems often employ presence or absence fashion to detect the tags' motions, so they cannot meet motion detection requirement in many applications. Our recent observations suggest that the signal strength backscattered from the tag is hypersensitive to its position, inspiring us to perceive the tag motion through its radio signal strength changes. Motion perception is not trivial and challenged by weak stability of strength in that any other interference or noise may incur significant changes as well, resulting in high false positives. To tackle this issue, we propose to model the strength via the Mixture of Gaussian Model (MoG). The problem is thus converted to foreground segment in computer vision with the help of Strength Image, where the technique of MoG based background subtraction is employed. We then implement a prototype using commercial off-the-shelf products. The evaluation results show that the slightest tag motion (~10 cm) can be precisely perceived, and the accuracy is up to 92.34 percent while the false positive is suppressed under 0.5 percent. Lei Yang 0025, Yi Guo 0008, Tianci Liu 0002, Cheng Wang 0001, Yunhao Liu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2015 | Capacity Scaling of Wireless Social NetworksabstractIn this paper, we investigate capacity scaling laws of wireless social networks under the social-based session formation. We model a wireless social network as a three-layered structure, consisting of the physical layer, social layer, and session layer; and we introduce a cross-layer distance & density-aware model, called the population-based formation model, under which: 1) for each node vk, the number of its friends/followers, denoted by qk, follows a Zipf's distribution with degree clustering exponent g; 2) qkanchor points are independently chosen according to a probability distribution with density function proportional to (Ek,X)-β, where Ek;Xis the expected number of nodes (population) within the distance |vk-X| to vk, and β is the clustering exponent of friendship formation; 3) finally, qknodes respectively nearest to those qkanchor points are selected as the friends of vk. We present the general density function of social relationship distribution, with general distribution of physical layer, serving as the basis for studying general capacity of wireless social networks. As the first step of addressing this issue, for the homogeneous physical layer, we derive the social-broadcast capacity under both generalized physical and protocol interference models, taking into account general clustering exponents of both friendship degree and friendship formation in a 2-dimensional parameter space, i.e., (γ,β) ϵ[0,∞)2. Importantly, we notice that the adopted model with homogenous physical layer does not sufficiently reflect the advantages of the population-based formation model in terms of realistic validity and practicability. Accordingly, we introduce a random network model, called the center-clustering random model (CCRM) with node distribution exponent δ ϵ [0, ∞), highlighting the clustering and inhomogeneity property in real-life networks, and discuss how to further derive more general network capacity over 3-dimensional parameter space (δ,γ,β) ϵ [0, ∞)3based on our results over (γ,β) ϵ [0, ∞)2. Cheng Wang 0001, Lu Shao, Zhong Li 0006, Lei Yang 0025, Xiang-Yang Li 0001, Changjun Jiang 0002 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2015 | Shelving Interference and Joint Identification in Large-Scale RFID SystemsabstractPrior work on anti-collision for radio frequency identification (RFID) systems usually schedule adjacent readers to exclusively interrogate tags for avoiding reader collisions. Although such a pattern can effectively deal with collisions, the lack of readers' collaboration wastes numerous time on the scheduling process and dramatically degrades the throughput of identification. Even worse, the tags within the overlapped interrogation regions of adjacent readers (termed as contentious tags), even if the number of such tags is very small, introduce a significant delay to the identification process. In this paper, we propose a new strategy for collision resolution. First, we shelve the collisions and identify the tags that do not involve reader collisions. Second, we perform a joint identification, in which adjacent readers collaboratively identify the contentious tags. In particular, we find that neighboring readers can cause a new type of tag collision, cross-tag-collision, which may impede the joint identification. We propose a protocol stack, named Season, to undertake the tasks in two phases and solve the cross-tag-collision. We conduct extensive simulations and preliminary implementation to demonstrate the efficiency of our scheme. The results show that our scheme can achieve above 6× improvement on the identification throughput in a large-scale dense reader environment. Lei Yang 0025, Yong Qi 0001, Jinsong Han, Cheng Wang 0001, Yunhao Liu 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2014 | RollCaller: User-friendly indoor navigation system using human-item spatial relationabstractIndoor navigation has received much attention in academics and industry in recent years. Previous methods often attempt to locate users with various localization algorithms in combination with an indoor map, so they need expensive infrastructures deployed in advance. In this study, we propose to utilize existing indoor objects attached RFID tags and the reader to navigate the user to the destination, without need of any extra hardware. The key insight is that the personal movement takes an impact on the Doppler frequency shift values collected from the indoor objects when getting close to the tag. Such local human-item spatial relation is leveraged to infer the users position and further navigate user to destination step by step. We implement a prototype navigation system, called RollCaller, and conduct comprehensive experiments to examine its performance. Yi Guo 0008, Lei Yang 0025, Tianci Liu 0002, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2014 | Anchor-free backscatter positioning for RFID tags with high accuracyabstractRFID technology has been widely adopted in a variety of applications from logistics to access control. Many applications gain benefits from knowing the exact position of an RFID-tagged object. Existing localization algorithms in wireless network, however, can hardly be directly employed due to tag's limited capabilities in terms of energy and memory. For example, the RSS based methods are vulnerable to both distance and tag orientation, while AOA based methods put a strict constraint on the antennas' spacing that reader's directional antennas are too large to meet. In this paper, we propose BackPos, a fine-grained backscatter positioning technique using the COTS RFID products with detected phase. Our study shows that the phase is indeed a stable indicator highly related to tag's position and preserved over frequency or tag orientation, but challenged by its periodicity and tag's diversity. We attempt to infer the distance differences from phases detected by antennas under triangle constraint. Further, hyperbolic positioning using the distance differences is employed to shrink the tag's candidate positions until filtering out the real one. In combination with interrogation zone, we finally relax the triangle constraint and allow arbitrary deployment of antennas by sacrificing the feasible region. We implement a prototype of BackPos with COTS RFID products and evaluate this design in various scenarios. The results show that BackPos achieves the mean accuracy of 12.8cm with variance of 3.8cm. Tianci Liu 0002, Lei Yang 0025, Qiongzheng Lin, Yi Guo 0008, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2014 | Frogeye: Perception of the slightest tag motionabstractExisting methods in RFID systems often employ presence or absence fashion to detect the tags' motions, so they cannot meet motion detection requirement in many applications. Our recent observations suggest that the signal strength backscattered from the tag is hypersensitive to its position, inspiring us to perceive the tag motion through its radio signal strength changes. Motion perception is not trivial and challenged by weak stability of strength in that any other interference or noise may incur significant changes as well, resulting in high false positives. To tackle this issue, we propose to model the strength via the Mixture of Gaussian Model (MoG). The problem is thus converted to foreground segment in computer vision with the help of Strength Image, where the technique of MoG based background subtraction is employed. We then implement a prototype using commercial off-the-shelf products. The evaluation results show that the slightest tag motion (~ 10cm) can be precisely perceived, and the accuracy is up to 92.34% while the false positive is suppressed under 0.5%. Lei Yang 0025, Yong Qi 0001, Jianbing Fang, Tianci Liu 0002, Mo Li 0001 |
INFOCOM | 1 |
| 2014 | Demo: high-precision RFID tracking using COTS deviesabstractIn many applications, we have to identify an object and then locate the object to within high precision (centimeter- or millimeter-level). Tracking mobile RFID tags in real time has been a daunting task, especially challenging for achieving high precision. We achieve these three goals by leveraging the phase value of the backscattered signal, provided by the COTS RFID readers, to estimate the location of the object. To illustrate the basic idea of our system, we firstly focus on a simple scenario where the tag is moving along a fixed track known to the system. We propose Differential Augmented Hologram (DAH) which will facilitate the instant tracking of the mobile RFID tag to a high precision. We then devise a comprehensive solution to accurately recover the tag's moving trajectory and its locations, relaxing the assumption of knowing tag's track function in advance. Lei Yang 0025, Yekui Chen, Xiang-Yang Li 0001, Yi Guo 0008, Yunhao Liu 0001 |
MobiCom | 1 |
| 2014 | Tagoram: real-time tracking of mobile RFID tags to high precision using COTS devicesabstractIn many applications, we have to identify an object and then locate the object to within high precision (centimeter- or millimeter-level). Legacy systems that can provide such accuracy are either expensive or suffering from performance degradation resulting from various impacts, e.g., occlusion for computer vision based approaches. Lei Yang 0025, Yekui Chen, Xiang-Yang Li 0001, Chaowei Xiao, Mo Li 0001, Yunhao Liu 0001 |
MobiCom | 1 |
| 2014 | Modeling data dissemination in online social networks: a geographical perspective on bounding network traffic loadabstractIn this paper, we model the data dissemination in online social networks (OSNs) and study the scaling laws of traffic load. We propose a three-layered system model to formulate data dissemination sessions for social applications in OSNs. The layered model consists of the physical network layer, social relationship layer, and application session layer. By analyzing mutual relevances among these three layers, we investigate the geographical distribution feature of dissemination sessions in OSNs. Based on this, we derive the traffic load of OSNs under a realistic assumption that every source sustains a data generating rate of constant order. To the best of our knowledge, this is the first work to address the issue of traffic load scaling for OSNs by modeling the social data dissemination from a layered perspective. Cheng Wang 0001, Shaojie Tang 0001, Lei Yang 0025, Yi Guo 0008, Fan Li 0001, Changjun Jiang 0002 |
MobiHoc | 3 |
| 2013 | OpenSesame: Unlocking smart phone through handshaking biometricsabstractScreen locking/unlocking is important for modern smart phones to avoid the unintentional operations and secure the personal stuff. Once the phone is locked, the user should take a specific action or provide some secret information to unlock the phone. Existing approaches do not support smart phones well due to the deficiency of security, high cost, and poor usability. We collect 200 users' handshaking actions with their smart phones and discover an appealing observation: the shaking pattern of a person is kind of unique, stable and distinguishable. In this paper, we propose OpenSesame, which employs the users' shaking patterns for locking/unlocking. The key feature of our system lies in using four fine-grained and statistic features of handshaking to verify users. Moreover, we utilize support vector machine (SVM) for accurate classification. Results from comprehensive experiments show that our technique is robust compatible across different brands of smart phones, without the need of any specialized hardware. Yi Guo 0008, Lei Yang 0025, Jinsong Han, Yunhao Liu 0001 |
INFOCOM | 2 |
| 2012 | Morello: A quality-of-monitoring oriented sensing scheduling protocol in Sensor NetworksabstractWireless Sensor Networks (WSN) are often densely deployed in the region of interest in order to continuously monitor physical phenomenon. Due to highly deployment density and the nature of the physical phenomenon, nearby sensor readings are often highly correlated in both space domain and time domain. These spatial and temporal correlations bring significant potential advantages as well as challenges for developing efficient sensing scheduling protocols for WSN. In this paper, a theoretical framework is developed to model the Quality of Monitoring (QoM) by exploiting both spatial and temporal correlations. The objective of this work is to enable the development of efficient sensing scheduling protocols which exploit these advantageous intrinsic features of the WSN paradigm. Specially, we propose two sensing scheduling schemes in order to maximize the overall QoM subject to resource constraints (e.g., under fixed duty cycle). Extensive experiments validate our theoretical results. Shaojie Tang 0001, Lei Yang 0025 |
INFOCOM | 2 |
| 2011 | Privacy Leakage in Access Mode: Revisiting Private RFID Authentication ProtocolsabstractExisting RFID Privacy-Preserving Authentication (PPA) solutions mainly focus on the design of crypto based interactive protocols between readers and tags. Although the cryptographic mechanisms enable randomization and enhance protocol-level privacy, the access mode in RFID systems is less random and may leak private information. We introduce anew attack based on such privacy leakage in access mode, where we show that the mainstream RFID PPA protocols, including the linear, tree-based, and synchronization-based solutions, are not private. We also show that this new attack is easy to conduct, e.g., we can track tags that employ typical tree-based PPA protocols without the need of compromising tags. We discuss the applicability of the attack. Moreover, we provide useful recommendations to strengthen existing PPA protocols in defending against such attacks. The simulation results demonstrate the practicability and effectiveness of this attack. Qingsong Yao, Jinsong Han, Yong Qi 0001, Lei Yang 0025, Yunhao Liu 0001 |
ICPP | 4 |
| 2011 | Season: Shelving interference and joint identification in large-scale RFID systemsabstractPrior work on anti-collision for Radio Frequency IDentification (RFID) systems usually schedule adjacent readers to exclusively interrogate tags for avoiding reader collisions. Although such a pattern can effectively deal with collisions, the lack of readers' collaboration wastes numerous time on the scheduling process and dramatically degrades the throughput of identification. Even worse, the tags within the overlapped interrogation regions of adjacent readers (termed as contentious tags), even if the number of such tags is very small, introduce a significant delay to the identification process. In this paper, we propose a new strategy for collision resolution. First, we shelve the collisions and identify the tags that do not involve reader collisions. Second, we perform a joint identification, in which adjacent readers collaboratively identify the contentious tags. In particular, we find that neighboring readers can cause a new type of collisions, cross-tag-collision, which may impede the joint identification. We propose a protocol stack, named Season, to undertake the tasks in two phases and solve the cross-tag-collision. We conduct extensive simulations and preliminary implementation to demonstrate the efficiency of our scheme. The results show that our scheme can achieve above 6 times improvement on the identification throughput in a large-scale dense reader environment. Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Tao Gu 0001, Yunhao Liu 0001 |
INFOCOM | 1 |
| 2010 | Identification-free batch authentication for RFID tagsabstractCardinality estimation and tag authentication are two major issues in large-scale Radio Frequency Identification (RFID) systems. While there exist both per-tag and probabilistic approaches for the cardinality estimation, the RFID-oriented authentication protocols are mainly per-tag based: the reader authenticates one tag at each time. For a batch of tags, current RFID systems have to identify them and then authenticate each tag sequentially, incurring large volume of authentication data and huge communication cost. We study the RFID batch authentication issue and propose the first probabilistic approach, termed as Single Echo based Batch Authentication (SEBA), to meet the requirement of prompt and reliable batch authentications in large scale RFID applications, e.g., the anti-counterfeiting solution. Without the need of identifying tags, SEBA provides a provable probabilistic guarantee that the percentage of potential counterfeit products is under the user-defined threshold. The experimental result demonstrates the effectiveness of SEBA in fast batch authentications and significant improvement compared to existing approaches. Lei Yang 0025, Jinsong Han, Yong Qi 0001, Yunhao Liu 0001 |
ICNP | 1 |
| 2010 | Utilizing RF Interference to Enable Private Estimation in RFID SystemsabstractCounting or estimating the number of tags is crucial for RFID system. Researchers have proposed several fast cardinality estimation schemes to estimate the quantity of a batch of tags within a short time frame. Existing estimation schemes scarcely consider the privacy issue. Without effective protection, the adversary can utilize the responding signals to estimate the number of tags as accurate as the valid reader. To address this issue, we propose a novel privacy-preserving estimation scheme, termed as MEAS, which provides an active RF countermeasure against the estimation from invalid readers. MEAS comprises of two components, an Estimation Interference Device (EID) and two well-designed Interference Blanking Estimators (IBE). EID is deployed with the tags to actively generate interfering signals, which introduce sufficiently large estimation errors to invalid or malicious readers. Using a secret interference factor shared with EID, a valid reader can perform accurate estimation via two IBEs. Our theoretical analysis and simulation results show the effectiveness of MEAS. Meanwhile, MEAS can also maintain a high estimation accuracy using IBEs. Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Qingsong Yao, Ying Chen 0004, Xiao Zhong |
ICPADS | 1 |
| 2010 | Revisting Tag Collision Problem in RFID SystemsabstractIn RFID systems, the reader is unable to discriminate concurrently reported IDs of tags from the overlapped signals, and a collision happens. Many algorithms for anticollision are proposed to improve the throughput and reduce the latency for tag identification. Existing anti-collision algorithms mainly employ CRC based collision detection functions for determining whether the collision happens. Generating CRC codes, however, requires complicated computations for both RF tags and readers, and hence incurs non-trivial time consumption, becoming the bottleneck. In this study, we design a Quick Collision Detection (QCD) scheme based on the bitwise complement function plus collision preamble, which significantly reduces the number of gates for computation and facilitates to simplify the IC design of RFID tags. The QCD scheme does not require any modification on upperlevel air protocols, so it can be seamlessly adopted by current anti-collision algorithms. Through comprehensive analysis and simulations, we show that QCD improves the identification efficiency by 40%. Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Yunhao Liu 0001, Ying Chen 0004, Xiao Zhong |
ICPP | 1 |