Tao Ni 0003

dblp:50/4043-3 · DBLP profile ↗
← Back
23ranked-venue papers
11as first author
23since 2021 · last 2026
0000-0003-0671-3020ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 5 first-author · 13 since 2021Security and privacy · 7 · 6 first-author · 7 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion Sensors
Tao Ni 0003, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee, Cong Wang 0001
SP1
2026 Characterizing Contactless Side-Channel Eavesdropping on Wireless Chargers
abstract
Today, there are an increasing number of smartphones equipped with wireless charging capabilities that use electromagnetic induction to transfer power from a wireless charger to devices that are being charged. In this paper, we unveil a novelcontactlessandcontext-awareside-channel attack in wire less charging, which harnesses two physical phenomena,i.e., the coil whine and the magnetic field perturbations, emanating from the wireless charging process and further infers user interactions on the charging smartphone. To validate the feasibility of this new side channel, we design and implement a three-stage attack framework, dubbed WISERS+, that first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to builduser interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of our proposed attacks with different commercial-off-the-shelf (COTS) smartphones and wireless chargers. Our evaluation results suggest that WISERS+canachieve over 90.4% accuracy in inferring sensitive information, such as the unlocking passcode on the screen and the launch of mobile apps. In addition, our study also demonstrates that WISERS+ is resilient to several practical impact factors, and presents its potential to be extended to attack the fast charging mode. Finally, we propose effective countermeasures and mitigate threats from the WISERS+ attack.
Tao Ni 0003, Chaoshun Zuo, Jianfeng Li 0006, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.1
2026 No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum Cleaner
abstract
Robot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.7
2026 SwiftChannel: Algorithm-Hardware Co-Design for Deep Learning-Based 5G Channel Estimation
abstract
Channel estimation is crucial in 5G communication networks for optimizing transmission parameters and ensuring reliable, high-speed communication. However, the use of multiple-input and multiple-output (MIMO) and millimeter-wave (mmWave) in 5G networks presents challenges in achieving accurate estimation under strict latency requirements on resource-limited hardware platforms. To address these challenges, we proposeSwiftChannel, an algorithm-hardware co-design framework that integrates a hardware-friendly deep learning-based channel estimator with a dedicated accelerator. Our approach employs a convolutional neural network enhanced with a parameter-free attention mechanism, which effectively reconstructs full-resolution spatial-frequency domain channel matrices from low-resolution least squares (LS) estimates. We further develop a multi-stage model compression pipeline combining knowledge distillation, convolution re-parameterization, and quantization-aware training, resulting in substantial model size reduction with negligible accuracy loss. The hardware accelerator, implementing the compressed model and the LS estimator on FPGA platforms using High-level Synthesis (HLS), features a fine-grained pipeline architecture and optimized dataflow strategies. Tested on a Zynq UltraScale+ RFSoC, the accelerator achieves sub-millisecond latency, providing up to 24x speed-up and over 33x improvement in energy efficiency compared to GPU-based solutions. Extensive evaluations demonstrate that the proposed design generalizes not only across various noise levels and user mobilities, but also to a variety of unseen channel profiles, outperforming state-of-the-art baselines. By unifying algorithmic innovation with hardware-aware design, our work presents a future-proof channel estimation solution for 5G MIMO systems. The source codes for the dataset synthesis, deep learning algorithm, and HLS-based FPGA design are accessible via GitHub.
Shengzhe Lyu, Yuhan She, Di Duan, Tao Ni 0003, Yu Hin Chan, Chengwen Luo 0001, Ray C. C. Cheung, Weitao Xu
IEEE Trans. Mob. Comput.4
2025 Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition
abstract
Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues such as conspicuousness, limited effectiveness, and insufficient robustness. To address these challenges, we propose a novel approach for adversarial face generation, UVHat, which utilizes ultraviolet (UV) emitters mounted on a hat to enable invisible and potent attacks in black-box settings. Specifically, UVHat simulates UV light sources via video interpolation and models the positions of these light sources on a curved surface, specifically the human head in our study. To optimize attack performance, UVHat integrates a reinforcement learning-based optimization strategy, which explores a vast parameter search space, encompassing factors such as shooting distance, power, and wavelength. Extensive experimental evaluations validate that UVHat substantially improves the attack success rate in black-box settings, enabling adversarial attacks from multiple angles with enhanced robustness.
Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Wenbo Jiang 0001, Tao Ni 0003, Wenshu Fan, Qingchuan Zhao, Guowen Xu
ICML6
2025 SpaceSched: A Constellation-Wide Scheduling System for Resolving Ground Track Congestion in Remote Sensing
abstract
The recent proliferation of spacecraft in Earth's orbits has ushered in the rise of large-scale satellite constellations. However, this unprecedented growth of constellations has introduced a previously unforeseen challenge: ground track congestion. Specifically, the increasing density of orbital slots forces satellites to share similar orbit planes, causing their nadir-point projections on Earth's surface (i.e., ground tracks) to overlap or remain in close proximity within short time intervals. Such orbit-endowed ground track congestion can degrade constellation performance in remote sensing operations, specified by limited constellation coverage, redundant satellite count, and delayed data delivery.
Zehua Sun, Tao Ni 0003, Pengfei Hu 0001, Tao Gu 0001, Weitao Xu
MobiCom2
2025 Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side Channel
Tao Ni 0003, Yuefeng Du 0001, Qingchuan Zhao, Cong Wang 0001
NDSS1
2025 The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
abstract
Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.
Shuai Yuan 0009, Xingshuo Han, Hongwei Li 0001, Guowen Xu, Wenbo Jiang 0001, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
NeurIPS6
2025 RingByte: Enhancing Text-Entry Practicality via A Singular Wearable Rotating Smart Ring
Rucheng Wu, Tao Ni 0003, Zehua Sun, Jiande Sun 0001, Weitao Xu
UIST2
2025 When Good Becomes Evil: Exploring Crosstalk Attack Surfaces on Multi-Port USB Chargers
abstract
Multi-port chargers, designed to simultaneously charge multiple mobile devices such as smartphones, have gained significant popularity, with millions of units sold in recent years. However, this multi-device charging feature introduces security and privacy risks. If not properly designed and implemented, these chargers can enable communication between connected devices because they are inherently interconnected, which leads to crosstalk voltage leakages. Despite their widespread use, these risks have not been thoroughly investigated. We have identified novel attack surfaces in the circuit design of multi-port chargers that allow an adversary who shares the multi-port charger with the target victim in close proximity to exploit one port to (i) recognize fine-grained user activities of other devices being charged, (ii) eavesdrop on secret audio transmission from USB-C audio pins, and (iii) inject malicious audio commands into built-in voice assistants of charging devices (e.g., Siri, Google Assistant). In this paper, we design and implement XPORTHEFT, a novel system to analyze and demonstrate the uncovered security and privacy threats in multi-port chargers. Specifically, it leverages changes in voltage signals in one neighbor port to monitor voltage changes in the charging port induced by user activities in various user interfaces, such as recognizing running apps and detecting keystrokes. Moreover, XPORTHEFT can also achieve audio transmission eavesdropping and launch inaudible audio injection attacks from the neighbor port to the charging mobile device via the USB-C interface. We extensively evaluate the effectiveness of XPORTHEFT using five commercial multi-port chargers and five mobile devices. The evaluation results show its high effectiveness in recognizing the launch of 20 mobile apps (88.7%) and revealing unlocking passcodes (98.8%), as well as eavesdropping on the audios of numeric digits (97.1%) and alphabetic characters (98.0%). Furthermore, XPORTHEFT achieves 100% success rates in inaudible audio injection attacks on three commercial voice assistants. In addition, our study also shows that XPORTHEFT is resilient to various impact factors and presents the potential to attack multiple victims.
Tao Ni 0003, Zehua Sun, Yihe Zhou, Jiayimei Wang, Weitao Xu, Qingchuan Zhao, Cong Wang 0001
IEEE Trans. Mob. Comput.1
2024 RF-Egg: An RF Solution for Fine-Grained Multi-Target and Multi-Task Egg Incubation Sensing
abstract
Eggs and chickens serve as crucial animal-source proteins in our diets, making large-scale breeding egg incubation an essential undertaking. However, current solutions, i.e., vision-based and sensor-based methods, are primarily designed for egg fertility detection tasks under single-egg settings, which have not yet satisfied the goal of multi-target and multi-task sensing. In this paper, we propose RF-Egg, the first RF-based fine-grained multi-target and multi-task egg incubation sensing system with respect to sensing fertility, incubation status, and early mortality of chicken embryos. RF-Egg leverages the weak coupling effects of RFID tags when interacting with eggs, which induces different impedance changes of RFID tags with the incubation levels of eggs, thereby resulting in a variation of low-level phase readings of the backscatter signals. Regarding the challenge of multi-target profiling interference, we propose a multipath combating algorithm to extract the target-induced signal component based on the built signal model, and address non-uniformity issues across multiple tags. Moreover, we devise three unique feature maps tailored to each task, and then design an Multi-Task Triplet (MTT) network for multitasking. Our evaluation results based on 189 eggs show that RF-Egg achieves an accuracy of 94.4%, 96.1%, and 90.1% for the aforementioned three tasks when supporting 16 targets. Additionally, our extensive field study in a local egg hatchery suggests that RF-Egg presents the potential to be widely deployed in the modern poultry industry.
Zehua Sun, Tao Ni 0003, Di Duan, Kai Liu 0008, Weitao Xu
MobiCom2
2024 REHSense: Towards Battery-Free Wireless Sensing via Radio Frequency Energy Harvesting
abstract
Diverse Wi-Fi-based wireless applications have been proposed, ranging from daily activity recognition to vital sign monitoring. Despite their remarkable sensing accuracy, the high energy consumption and the requirement for customized hardware modification hinder the wide deployment of the existing sensing solutions. In this paper, we propose REHSense, an energy-efficient wireless sensing solution based on Radio-Frequency (RF) energy harvesting. Instead of relying on a power-hungry Wi-Fi receiver, REHSense leverages an RF energy harvester as the sensor and utilizes the voltage signals harvested from the ambient Wi-Fi signals to enable simultaneous context sensing and energy harvesting. We design and implement REHSense using a commercial-off-the-shelf (COTS) RF energy harvester. Extensive evaluation of three fine-grained wireless sensing tasks (i.e., respiration monitoring, human activity recognition, and hand gesture recognition) shows that REHSense can achieve comparable sensing accuracy with conventional Wi-Fi-based solutions while adapting to different sensing environments, reducing the power consumption of sensing by 98.7% and harvesting up to 4.5 mW of power from RF energy.
Tao Ni 0003, Zehua Sun, Mingda Han, Yaxiong Xie, Guohao Lan, Zhenjiang Li 0001, Tao Gu 0001, Weitao Xu
MobiHoc1
2024 F2Key: Dynamically Converting Your Face into a Private Key Based on COTS Headphones for Reliable Voice Interaction
abstract
In this paper, we proposed F2Key, the first earable physical security system based on commercial off-the-shelf headphones. F2Key enables impactful applications, such as enhancing voiceprint-based authentication systems, reliable voice assistants, audio deepfake defense, and the legal validity of artifacts. The key idea of F2Key is to establish a stable acoustic sensing field across the user's face and embed the user's facial structures and articulatory habits into a user-specific generative model that serves as a private key. The private key can decrypt the Channel Impulse Response (CIR) profiles provided by the acoustic sensing field into an inferred spectrogram that can match the real one calculated from the corresponding speech, provided that the user's CIR-spectrogram mapping relationship is consistent with the one embedded in the generative model. Extensive experiments demonstrate that F2Key resists 99.9%, 96.4%, and 95.3% of speech replay attacks, mimicry attacks, and hybrid attacks, respectively. We discussed and evaluated F2Key from different perspectives, such as the health consideration and identical twins study, to show the practicality and reliability.
Di Duan, Zehua Sun, Tao Ni 0003, Shuaicheng Li 0001, Xiaohua Jia, Weitao Xu, Tianxing Li 0001
MobiSys3
2024 Sensor Security in Virtual Reality: Exploration and Mitigation
abstract
Virtual Reality (VR) technology, extensively utilized in gaming, social networking, and online collaboration, has raised significant security concerns due to the array of sensors integrated into VR headsets. This paper discusses several of our ongoing research that explore sensor vulnerabilities within VR headsets and proposes appropriate mitigation strategies. Specifically, we focus on three types of embedded sensors in VR headsets: unrestricted motion sensors, optical sensors, and eye-tracking sensors. Our investigation outlines the potential attacks exploiting these sensor vulnerabilities, which could result in privacy leakage and malicious signal injections. Furthermore, we detail the design and implementation of effective countermeasures to defend against these threats.
Tao Ni 0003
MobiSys1
2024 mmSign: mmWave-based Few-Shot Online Handwritten Signature Verification
abstract
Handwritten signature verification has become one of the most important document authentication methods that are widely used in the financial, legal, and administrative sectors. Compared with offline methods based on static signature images, online handwritten signature verification methods are more reliable because of the temporary dynamic information (e.g., signing velocity, writing force, stroke order) that alleviates the risk of being forged. However, most existing online handwritten signature verification solutions are reliant on specific signing devices (e.g., customized pens or writing pads) and require extensive data collection during the registration phase, resulting in poor adaptability and applicability for new users. In this article, we propose mmSign, a millimeter wave (mmWave)–based online handwritten signature verification system, which enables accurate sensing of the user’s hand movements when signing through the superior sensing capability of mmWave. mmSign extracts the time-velocity feature maps from the captured mmWave signals by the carefully designed signal processing algorithms and then exploits a transformer-based verification model for signature verification. In addition, a novel meta-learning strategy with proposed task generation and data augmentation methods is introduced in mmSign to teach the verification model to learn effectively with limited samples, allowing our model to quickly adapt to new users. Extensive experiments show that mmSign is a robust, efficient, and secure handwritten signature verification system, achieving 84.07%, 87.31%, 91.12%, and 96.54% verification accuracy when 1, 3, 5, and 10 labeled signatures are available, respectively, while being resistant to common forgery attacks.
Mingda Han, Huanqi Yang, Tao Ni 0003, Di Duan, Mengzhe Ruan, Jia Zhang 0028, Weitao Xu
ACM Trans. Sens. Networks3
2024 FLoRa+: Energy-efficient, Reliable, Beamforming-assisted, and Secure Over-the-air Firmware Update in LoRa Networks
abstract
The widespread deployment of unattended LoRa networks poses a growing need to perform Firmware Updates Over-The-Air (FUOTA). However, the FUOTA specifications dedicated by LoRa Alliance fall short of several deficiencies with respect to energy efficiency, transmission reliability, multicast fairness, and security. This article proposes FLoRa+ , energy-efficient, reliable, beamforming-assisted, and secure FUOTA for LoRa networks, which is featured with several techniques, including delta scripting, channel coding, beamforming, and securing mechanisms. Specifically, we first propose a joint differencing and compression algorithm to generate the delta script for processing gain, which unlocks the potential of incremental FUOTA in LoRa networks. Then, we design a concatenated channel coding scheme with outer rateless code and inner error detection to enable reliable transmission for coding gain. Afterward, we develop a beamforming strategy to avoid biased multicast and compromised throughput for power gain. Finally, we present a securing mechanism incorporating progressive hash chain and packet arrival time pattern verification to countermeasure firmware integrity and availability attacks for security gain. Experimental results on a 20-node testbed demonstrate that FLoRa+ improves transmission reliability and energy efficiency by up to 1.51× and 2.65× compared with LoRaWAN. Additionally, FLoRa+ can defend against 100% and 85.4% of spoofing and Denial-of-Service (DoS) attacks.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
ACM Trans. Sens. Networks2
2023 Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side Channel
abstract
Recently, in-display fingerprint sensors have been widely adopted in newly-released smartphones. However, we find this new technique can leak information about the user's fingerprints during a screen-unlocking process via the electromagnetic (EM) side channel that can be exploited for fingerprint recovery. We propose FPLogger to demonstrate the feasibility of this novel side-channel attack. Specifically, it leverages the emitted EM emanations when the user presses the in-display fingerprint sensor to extract fingerprint information, then maps the captured EM signals to fingerprint images and develops 3D fingerprint pieces to spoof and unlock the smartphones. We have extensively evaluated the effectiveness of FPlogger on five commodity smartphones equipped with both optical and ultrasonic in-display fingerprint sensors, and the results show it achieves promising similarities in recovering fingerprint images. In addition, results from 50 end-to-end spoofing attacks also present FPLogger achieves 24% (top-1) and 54% (top-3) success rates in spoofing five different smartphones.
Tao Ni 0003, Xiaokuan Zhang, Qingchuan Zhao
CCS1
2023 FLoRa: Energy-Efficient, Reliable, and Beamforming-Assisted Over-The-Air Firmware Update in LoRa Networks
abstract
LoRa has emerged as one of the promising long-range and low-power wireless communication technologies for Internet of Things (IoT). With the massive deployment of LoRa networks, the ability to perform Firmware Update Over-The-Air (FUOTA) is becoming a necessity for unattended LoRa devices. LoRa Alliance has recently dedicated the specification for FUOTA, but the existing solution has several drawbacks, such as low energy efficiency, poor transmission reliability, and biased multicast grouping. In this paper, we propose a novel energy-efficient, reliable, and beamforming-assisted FUOTA system for LoRa networks named FLoRa, which is featured with several techniques, including delta scripting, channel coding, and beamforming. In particular, we first propose a novel joint differencing and compression algorithm to generate the delta script for processing gain, which unlocks the potential of incremental FUOTA in LoRa networks. Afterward, we design a concatenated channel coding scheme to enable reliable transmission against dynamic link quality. The proposed scheme uses a rateless code as outer code and an error detection code as inner code to achieve coding gain. Finally, we design a beamforming strategy to avoid biased multicast and compromised throughput for power gain. Experimental results on a 20-node testbed demonstrate that FLoRa improves network transmission reliability by up to 1.51 × and energy efficiency by up to 2.65 × compared with the existing solution in LoRaWAN.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
IPSN2
2023 Demo Abstract: A Novel Firmware Update Over-The-Air System for LoRa Networks
abstract
LoRa has emerged as a novel Internet of Things (IoT) communication paradigm, featuring with long-range and low-power transmission capabilities. With the widespread deployment of LoRa networks, the demand to perform Firmware Update Over-The-Air (FUOTA) tasks has become increasingly critical for unattended LoRa devices. However, in practice, three fundamental problems that hinder the performance of FUOTA tasks are revealed, including low energy efficiency, poor transmission reliability, and biased multicast grouping. In this demo, we present a novel FUOTA system, the first work that offers an effective and sustainable solution to achieve energy-efficient and reliable over-the-air firmware updates in LoRa networks. In particular, this system incorporates threefold key modules: delta scripting, channel coding, and beamforming. The delta scripting algorithm unlocks the capability of incremental update, the channel coding scheme ensures the reliability and robustness of large-scale firmware image distribution, and the beamforming strategy as an optional module can further serve the unicast user. Thus, this demo presents a working example of functionality customization to show the efficacy and feasibility of our FUOTA system in LoRa networks.
Zehua Sun, Tao Ni 0003, Huanqi Yang, Kai Liu 0008, Yu Zhang 0093, Tao Gu 0001, Weitao Xu
IPSN2
2023 XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice Injection
abstract
Multi-port chargers, capable of simultaneously charging multiple mobile devices such as smartphones, have gained immense popularity and sold millions of units in recent years. However, this charging-targeted feature can also pose security and privacy risks by allowing one of the simultaneously charging devices to communicate with another one if not properly designed and implemented as these devices are actually interconnected. Unfortunately, such risks have not been thoroughly investigated and we have identified a novel attack surface in the circuit design of multi-port chargers, which allows an adversary to exploit one port to (i) eavesdrop on the activities of other devices being charged and (ii) inaudibly inject malicious audio commands if the charging device supports voice assistants and USB-C interface.
Tao Ni 0003, Weitao Xu, Lei Xue 0001, Qingchuan Zhao
MobiCom1
2023 Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot Learning
abstract
Recently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning.
Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
MobiCom1
2023 Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side Channels
abstract
Today, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors.
Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
SP1
2023 Eavesdropping Mobile App Activity via Radio-Frequency Energy Harvesting
Tao Ni 0003, Guohao Lan, Jia Wang 0008, Qingchuan Zhao, Weitao Xu
USENIX Security Symposium1