EDBT 2026 Demo / reviewers in the wild / expert
Aiqun Hu
dblp:55/4757
· DBLP profile ↗
101ranked-venue papers
0as first author
72since 2021 · last 2026
0000-0002-0398-4899ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 56 · 41 since 2021Security and privacy · 19 · 15 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Channel-Robust RFF for Low-Latency 5G Device Identification in SIMO ScenariosabstractUltra-low latency, the hallmark of fifth-generation mobile communications (5G), imposes exacting timing demands on identification as well. Current cryptographic solutions introduce additional computational overhead, which results in heightened identification delays. Radio frequency fingerprint (RFF) identifies devices at the physical layer, blocking impersonation attacks while significantly reducing latency. Unfortunately, multipath channels compromise RFF accuracy, and existing channel-resilient methods demand feedback or processing across multiple time points, incurring extra signaling latency. To address this problem, the paper introduces a new RFF extraction technique that employs signals from multiple receiving antennas to address multipath issues without adding latency. Unlike single-domain methods, the Log-Linear Delta Ratio (LLDR) of co-temporal channel frequency responses (CFRs) from multiple antennas is employed to preserve discriminative RFF features, eliminating multi-time sampling and reducing acquisition time. To overcome the challenge of the reliance on minimal channel variation, the frequency band is segmented into sub-bands, and the LLDR is computed within each sub-band individually. Simulation results indicate that the proposed scheme attains a 96.13% identification accuracy for 30 user equipments (UEs) within a 20-path channel under a signal-to-noise ratio (SNR) of 20 dB. Furthermore, we evaluate the theoretical latency using the Roofline model, resulting in the air interface latency of 0.491 ms, which satisfies ultra-reliable and low-latency communications (URLLC) latency requirements. Yingjie Sun, Guyue Li, Hongfu Chou, Aiqun Hu |
WCNC | 4 |
| 2026 | Robust Radio Frequency Fingerprint Extraction and Identification for LoRa Low-Power Devices
Aiqun Hu, Tianshu Chen, Yanbing Chen |
WCNC | 2 |
| 2026 | Reciprocal signal generation method for making symmetric keys over internet
Dongbin He, Aiqun Hu, Xiaochuan He, Yaohui Guo, Genwen Chen |
Comput. Networks | 2 |
| 2026 | Corrigendum to "Reciprocal signal generation method for making symmetric keys over internet" [Computer Networks 276 (2026) 111989]
Dongbin He, Aiqun Hu, Xiaochuan He, Yaohui Guo, Genwen Chen |
Comput. Networks | 2 |
| 2026 | ES-PUF: A practical Physically Unclonable Function for wired networks using Ethernet physical-layer signals
Aiqun Hu, Linning Peng, Baofu Han, Tian Fang, Pan Feng |
Comput. Networks | 2 |
| 2026 | JOCLNet: A Physical-Layer Key Generation Scheme Based on Joint Optimization and Contrastive Learning NetworkabstractPhysical-layer key generation exploits the randomness and unpredictability of wireless channels to enhance the security of wireless communications. However, factors such as asynchronous measurements, channel noise, and hardware impairments undermine the ideal reciprocity of channel state information (CSI) observed by legitimate users, thereby limiting key generation performance. To address this issue, this paper proposes a jointly optimized contrastive learning network (JOCLNet), which consists of a joint learning model and a contrastive learning model. The joint learning model, built upon a convolutional neural network (CNN) and a feedforward neural network (FNN), separates non-reciprocal components such as noise and measurement errors from the raw CSI of legitimate users, while extracting reciprocal components for key generation, thus improving robustness in noisy environments. To overcome the inability of existing deep-learning-based SKG schemes to resist passive eavesdropping attacks, the contrastive learning model introduces a contrastive loss on top of the joint learning model. This enables a dual objective: enhancing reciprocity between the processed CSI of legitimate users while ensuring that the processed data of an eavesdropper remains highly uncorrelated with that of legitimate parties. Furthermore, a complete key generation scheme is designed based on the proposed JOCLNet. Experimental results demonstrate that the proposed scheme achieves strong resistance to eavesdropping and robust adaptability to noise. Yu Jiang 0020, Aiqun Hu |
IEEE Internet Things J. | 3 |
| 2026 | FineLorKey: An Efficient LoRa Physical-Layer Key Generation Scheme Utilizing Fine-Grained Channel Impulse ResponseabstractPhysical layer key generation has emerged as a promising solution to secure communications in LoRa networks. However, existing LoRa-based key generation systems suffer from low efficiency and limited security due to their reliance on coarse-grained channel measurements. To overcome the limitation, this paper proposes FineLorKey, the first systematic physical layer key generation framework for LoRa that leverages fine-grained Channel Impulse Response (CIR). FineLorKey introduces a novel CIR extraction method tailored to LoRa Chirp Spread Spectrum (CSS) modulation. This method can be seamlessly integrated into the demodulation process without incurring additional computational overhead. Theoretical analysis demonstrates that the extracted CIR maintains high reliability under the low signal-to-noise ratio (SNR) conditions typical of LoRa environments. Furthermore, to address the dynamic SNR variations inherent in LoRa scenarios, this paper designs an SNR aware quantization scheme based on quantitative bit error rate analysis. The scheme dynamically adjusts the quantization order to maximize entropy extraction. Extensive experiments were conducted in diverse scenarios, including indoor and outdoor environments, line-of-sight and non-line-of-sight conditions, as well as both static and mobile settings. The results show that compared with RSSI-based methods, FineLorKey achieves a more than 10× improvement in key generation rate, reduces the key disagreement rate to below 5%, decreases channel information eavesdropping rate by over 60%, and exhibits strong robustness under large-scale deployment scenarios. These findings underscore the effectiveness and security of FineLorKey and mark a substantial advancement in wireless key generation for long-range, low-SNR wireless environments. Aiqun Hu, Yanbing Chen, Bingshu Dong, Shichen Sun |
IEEE Internet Things J. | 2 |
| 2026 | Data-Agnostic LTE-V2X RFF Extraction Approach Based on Contextual Characterization and Invariant Feature ModelingabstractRadio Frequency Fingerprint (RFF) extraction is a key technology for physical layer authentication, relying on the unique hardware imperfections of transmitters. However, its application in vehicular networks remains challenging due to the dynamic and unpredictable channel conditions that often lead to overfitting. Current methods struggle to generalize beyond the specific sequences and statistical channel characteristics present in training data, which limits their effectiveness in real-world scenarios where unknown signal data and varying channel conditions are the norm. This research addresses this gap by developing a novel framework to enhance RFF extraction in LTE-V2X devices. Here, we propose a two-step approach to mitigate overfitting and improve generalization. First, we introduce a Contextual Contrastive Learning (CCL) network that employs three loss functions with varied fusion weights to learn robust representations. This network is trained using signals from the same frame symbols, different content frames from the same device, and the same content frames from different devices, effectively reducing the model’s reliance on fixed data patterns. Second, we implement an Invariant Feature Learning (IFL) network, wherein signals are collected from multiple transmitting devices at a single location while receivers are placed at several fixed positions. This setup allows the network to learn device-specific representations that are invariant to channel variations. Experimental results demonstrate that our method significantly outperforms existing approaches in both accuracy and robustness, especially in challenging environments characterized by multipath and shadow fading. Shiqi Zhang 0013, Aiqun Hu, Xinyu Qi, Tianshu Chen |
IEEE Internet Things J. | 2 |
| 2026 | Risk-Balanced Open-Set Recognition for 1000BASE-T Device Fingerprinting in IIoT
Yu Jiang 0020, Shuangyu Yang, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2026 | Interpretable High-Pass Filter Fingerprint Model for 1000BASE-T Ethernet Authentication in IIoTabstractIndustrial Internet of Things (IIoT) increasingly relies on Gigabit Ethernet (1000BASE-T) as the physical back-bone for interconnecting industrial devices, while the rapid growth of IIoT nodes has intensified concerns about physical-layer identity spoofing and unauthorized access. Recently, device fingerprinting has emerged as a promising approach to achieving secure authentication at the physical layer. However, existing 1000BASE-T fingerprint extraction methods rely on randomly scrambled signals, leading to degraded authentication reliability. In addition, the absence of radio-frequency (RF) frontend modules—commonly defined in wireless systems—within 1000BASE-T transmitters prevents the direct application of conventional hardware-imperfection models. To overcome these challenges, this paper first introduces test mode (TM) signals as highly consistent and controllable reference inputs, and on this basis, proposes an interpretable high-pass filter (HPF) fingerprint model. The model characterizes the high-pass response of the transmission link using a single-pole system, establishes a monotonic relationship between filter parameters and waveform morphology, and extracts stable fingerprint features accordingly. Furthermore, a closed-loop physical-layer authentication framework is developed, integrating signal acquisition, preprocessing, feature extraction, and device identification. Experimental results demonstrate that the proposed method achieves 100% identification accuracy under standard sampling conditions and preserves perfect recognition over the entire tested sampling-rate range. Moreover, the method exhibits substantially enhanced noise robustness compared with baseline methods, and retains 95.59% accuracy after a 30-day interval in temporal stability evaluations. Yu Jiang 0020, Shuangyu Yang, Siwen Li, Aiqun Hu |
IEEE Internet Things J. | 5 |
| 2026 | Channel-Robust Radio Frequency Fingerprint Extraction Based on Channel ReciprocityabstractRecently, Radio Frequency Fingerprint (RFF) technology has emerged as a promising technique for physical layer authentication. However, overcoming the interference from wireless multipath channels remains a key challenge for robust RFF extraction. Existing channel-robust studies often suppress channel effects at the expense of intrinsic RFF information, and the retained RFF features may lack sufficient discrimination. This paper proposes a channel-robust RFF extraction scheme based on channel reciprocity. Firstly, a Channel State Information (CSI) feedback mechanism is proposed to collect reciprocal uplink and downlink CSI. Then, CSI preprocessing methods and the channel reciprocity judging method based on Mean Absolute Distance (MAD), are exploited to further enhance CSI reciprocity. Finally, a novel RFF extraction algorithm eliminates reciprocal channel components by calculating the quotient of uplink and downlink CSI, thereby retaining the differentiated device-specific RFF features. A unified identification framework supports both in-library classification and unknown device detection. Extensive experiments using 41 ESP32 development kits under various Wi-Fi channel environments show that the extracted RFF features are channel-robust, highly distinctive, and stable over time. Specifically, in a static scenario with strong multipath effects, the in-library classification accuracy reaches 96.86%. And the same metric in a dynamic scenario with significant interference remains 93.48%. Furthermore, new-device recognition accuracy remains above 94% across all scenarios, with a False Negative Rate (FNR) below 1.3%. Bingshu Dong, Aiqun Hu, Jiabao Yu, Zhiyi Shi |
IEEE Trans. Commun. | 2 |
| 2026 | A Neural-Inspired Security Control Model Integrating Feedforward and Feedback Bionic MechanismsabstractAs network architectures become increasingly dynamic and complex, traditional static defense mechanisms—relying on predefined rules—are proving inadequate in coping with evolving and unknown security threats. Inspired by the regulatory logic of the human nervous system, particularly its feed-forward and feedback mechanisms, conditioned reflexes, and self-adaptive learning, this paper proposes a neural-inspired security control model that integrates predictive regulation with adaptive optimization. The model employs a multi-hypersphere modeling approach to characterize multiple normal operating states of the system, simulating the nervous system's ability to flexibly reset regulatory baselines under different conditions. This enables accurate anomaly detection and feed-forward signal generation. In the feedback loop, a reward mechanism based on potential functions guides the system in progressively refining its countermeasure strategies, enhancing adaptability to unknown attacks. Experiments were conducted on a simulated Spring Boot based Web service platform, covering two normal states and seven categories of abnormal states. All experimental data were collected from the actual system runtime. Results show that the model achieves 98.00% accuracy in anomaly detection and 98.29% correctness in feed-forward signal generation, with all abnormal scenarios successfully regulated within a limited number of steps. Furthermore, comparative analysis demonstrates that the proposed model significantly outperforms standard anomaly detection baselines, such as OC-SVM and Isolation Forest, in both detection accuracy and regulatory capability. These findings validate the model's capabilities in self-learning, generalization, and practical application in intelligent security control. Tao Li 0053, Keyang Qiang, Aiqun Hu, Feilin Li |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Toward a Practical Key Generation System for V2X CommunicationsabstractThe vehicle to everything (V2X) serves as a crucial foundation for future intelligent transportation systems. Security concerns within the V2X have garnered significant attention and key generation from wireless channels have emerged as a promising technique. However, applying key generation to V2X is quite challenging because the fast moving vehicles result in very small coherence time and impact channel measurements correlation. This paper designed a practical V2X key generation by enhancing channel state information (CSI) reciprocity and carried out extensive experimental evaluation. In particular, the designed key generation consists of channel probing, CSI preprocessing, CSI compensation and key establishment. In the channel probing, we deliberately reduced the time delay between uplink and downlink transmissions, to allow almost simultaneous measurements. We then carefully designed CSI preprocessing to remove hardware carrier leakage and eliminate noise effects. Furthermore, we devised CSI compensation by using interpolation or deep learning prediction to further improve the reciprocity. Finally, key establishment converted the measured CSI into binary sequences and reconcile on a common key via low-density parity-check (LDPC) code. We adopted universal software radio peripheral (USRP) X310 platforms for channel measurements and implemented the above algorithms. We carried out extensive experiments in real-road environments with various vehicle speeds. These carefully designed algorithms enabled our system working robustly even in high mobility scenarios, e.g., 40 km/h. Experimental results demonstrated common and random key can be generated with a key block error rate (BER) less than 0.1. Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
IEEE Trans. Mob. Comput. | 6 |
| 2026 | A Novel Reciprocal Signal Generating Method Based on Network Delay of Random Routing ProtocolsabstractThe growing popularity of Internet of Things (IoT) devices raises significant challenges for secure key distribution in wide-area networks. Traditional solutions often face high deployment costs or distance limitations. This paper proposes a novel method that leverages the inherent reciprocity of Internet transmission delay to achieve lightweight symmetric keys distribution. The core of the method lies in the generation of reciprocal delay signals, and then in the enhancement of their randomness through randomized routing protocols and additional artificial delays. Moreover, an eavesdropping model is proposed to analyze single attackers, and a probabilistic framework is established to evaluate security limits against collusion attacks. Furthermore, error correction codes are implemented to allow the raw key to be directly used for encryption, eliminating additional communication overhead. Experimental results demonstrate a correlation coefficient of 0.97 for delay signals in a local area network (LAN), confirming strong reciprocity. On the public internet, the proposed randomness enhancement improves the entropy by 2 bits. Similarly, the correlation coefficient between signals obtained by an eavesdropper and the legitimate party in this wide-area environment ranges from 0.02 to 0.26, indicating that the method is resilient to eavesdropping. This work demonstrates the feasibility of utilizing public network characteristics for secure key distribution among wide-area terminals. Dongbin He, Aiqun Hu, Xiaochuan He |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2026 | Erratum to "A Novel Reciprocal Signal Generating Method Based on Network Delay of Random Routing Protocols"
Dongbin He, Aiqun Hu, Xiaochuan He |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | A LoRa Radio Frequency Fingerprint Extraction Scheme Against Variable Channel CharacteristicsabstractRadio Frequency Fingerprint (RFF) recognition has emerged as a promising physical layer security technique, enabling the identification of wireless devices based on their unique RF characteristics. However, the performance of RFF recognition can be significantly hindered by interference stemming from variable channel conditions. To address this challenge, we propose a novel LoRa-based RFF extraction scheme that exploits the temporal variations in channel features. Initially, we compute the power spectrum by cross-correlating the received signal with a locally generated reference signal, effectively mitigating noise in the context of long-range LoRa communications. Subsequently, we derive both the linear and logarithmic differential spectra of the power spectrum based on received signals from different time instances, and then calculate the ratio of these two spectra to extract the RFF. Experimental results demonstrate that the proposed method exhibits strong resilience to channel variations, maintaining an average recognition accuracy above 96% across diverse environments and time intervals. Yanbing Chen, Aiqun Hu, Linning Peng, Tianshu Chen |
VTC2025-Fall | 2 |
| 2025 | RFFDDPM: A Robust Framework for Radio Frequency Fingerprint Extraction and Open-Set Authentication in LTE-V2X NetworksabstractIn the field of vehicular networks, ensuring se-cure communication through device authentication has become increasingly critical. Traditional Radio Frequency Fingerprint (RFF) extraction methods often struggle under dynamic and unpredictable channel conditions, leading to overfitting and poor generalization, especially in open-set scenarios where unknown devices and varying environments must be handled. Current techniques are insufficient in mitigating channel effects, limiting their practical applicability in LTE-V2X systems. This paper addresses the gap by developing a novel deep learning frame-work for robust RFF extraction and open-set authentication in LTE-V2X environments, leveraging advanced generative models. Here, we propose the RFFDDPM framework, which integrates Denoising Diffusion Probabilistic Models (DDPM) with a Chan-nel Removal Guidance Module (CRGM) to eliminate channel effects and enhance RFF extraction. The CRGM utilizes both time-domain and frequency-domain features to guide DDPM during denoising, ensuring that the RFF characteristics are pre-served while the channel effects are removed. Our experimental results, conducted on both indoor and outdoor datasets, show that RFFDDPM significantly outperforms existing methods in terms of accuracy and robustness, particularly in high-speed, non-line-of-sight (NLoS), and open-set scenarios. Shiqi Zhang 0013, Aiqun Hu, Xinyu Qi, Tianshu Chen, Zhen Zhang 0065 |
WCNC | 2 |
| 2025 | A neural coding method based on feature sensingabstractAbstract The novel network contains many sensors, which greatly heightens data transmission burdens. Some networks require the data perceived by sensors for a period to make decisions. Drawing inspiration from the human neural conduction mechanism, a waveform data encoding method called feature sensing neural coding (FSNC) is proposed to enhance network data transmission efficiency. It involves feature decomposition of information and subsequent non‐linear encoding of feature coefficients for data transmission. This approach exploits the unique neuronal responses to diverse stimuli and the inherent non‐linear characteristics of human neural coding. Finally, taking the speech signal and seismic wave signal as examples, the effectiveness of FSNC is verified by simulating the auditory nerve conduction process with frequency as a feature according to the mechanism of travelling wave motion of the basilar membrane in the cochlea. Moreover, experiments on seismic waveform signals have demonstrated the wide applicability of FSNC. Compared with traditional speech coding schemes, the FSNC bit rate is only 6.4 kbps, which greatly reduces the amount of data transmitted. Not only that, FSNC also has a certain fault tolerance, and parallel transmission can also greatly increase the transmission rate. This research provides new ideas for efficient data transmission over new networks. Dongbin He, Aiqun Hu, Kaiwen Sheng |
IET Commun. | 2 |
| 2025 | Effective neural coding method based on maximum entropyabstractAbstract There are a large number of perceptrons in the new bionic network. To improve the efficiency of data transmission in the bionic network, a maximum entropy neural coding method is proposed. By drawing on the characteristics of human nerve conduction, the authors designed a data transmission model and adopted an adaptive spike firing rate encoding strategy to maximize information entropy, thereby improving encoding efficiency. The simulation experiment results and the applications of the maximum entropy neural coding method to fault detection and seismic detection have validated the effectiveness of the maximum entropy neural coding method. Even if there is certain data distortion, the statistical characteristics of the decoded data and the fault detection performance will not be affected. This research not only proposes novel approaches for efficient data transmission in bionic network, but also identifies possible directions for enhancing data transmission efficiency through the integration of task‐oriented semantic communications in future applications. Dongbin He, Aiqun Hu, Kaiwen Sheng |
IET Commun. | 2 |
| 2025 | Securing Wireless Communications via Channel Reciprocity and Dynamic Constellation ObfuscationabstractThe one-time pad secure transmission based on wireless channel reciprocity (CR-OTP) has drawn great attention recently due to its capability of providing perfect secrecy of data, as well as the modulation information. However, existing CR-OTP schemes encounter both reliability and security challenges as their assumptions of channel reciprocity and randomness are not always well satisfied in practical application scenarios. To tackle these issues, we propose a dynamic constellation obfuscation (DCO) method that obfuscates the plaintext by rotating its constellation dynamically. This kind of analog encryption method is proven to be more robust than the existing digital exclusive OR (XOR) encryption method as the former achieves a lower symbol error rate (SER) by reducing the double quantization loss to one. The rotation pattern is jointly dependent on the channel state information (CSI) and the previous message, which guarantees the randomness of the rotation pattern subjected to environmental drifts. Only the legitimate receiver that correctly recovers the previous message correctly and observes a similar CSI is able to decode the newly transmitted message. We proved that the secrecy capacity of the proposed DCO method is higher than that of the state-of-the-art. Simulation results confirm that the proposed method delivers superior performance regarding secrecy capacity and SER, achieving a 4.5 dB signal-to-noise ratio (SNR) gain at a SER of 0.1; moreover, when the secrecy capacity is 0.1, the main channel SNR gain reaches 6.5 dB when the wiretap channel SNR is 20 dB. Yujie Hou, Hai-Xi Sun, Guyue Li, Shuping Dang, Aiqun Hu |
IEEE Internet Things J. | 5 |
| 2025 | Enhancing Wireless Communication Security With Variable Bloom Filter-Based Physical-Layer Secure TransmissionabstractThis paper studies one-time pad (OTP) secure communication by leveraging the unpredictable physical layer channel characteristics. Existing OTP schemes based on physical-layer key generation (PKG) require additional transmission overhead of information reconciliation and may face security threats of information leakage under slow-varying channels. To tackle these challenges, we investigate a fault-tolerant privacy amplification method through variable bloom filters to address the underlying security problems. Specifically, the quantized bit sequence of the channel state information goes through a bloom filter to improve the randomness within the sequence while the parameters of bloom filter vary to avoid the correlations between adjacent sequences. We then optimize the parameters of the error-correcting code used during communication based on the position of the eavesdropper and the length of the quantized bits, thereby further enhancing the system security. Through comprehensive simulations, it is shown that our proposed approach can achieve a near-perfect pass rate in NIST randomness tests, and with a bit replacement rate around 0.45, whilst capable of resisting attacks under slow-varying channels. These results indicate that the proposed scheme significantly outperforms previous OTP secure transmission schemes. Anqi Huo, Guyue Li, Lilin Yang, Zi Long Liu 0001, Aiqun Hu |
IEEE Internet Things J. | 5 |
| 2025 | Research on Lightweight Sensing Technology Based on Single-Antenna MulticarrierabstractChannel state information (CSI) serves as a critical indicator of wireless signal conditions and is widely regarded by researchers for its sensitivity in detecting changes within the channel. However, traditional sensing technologies often require substantial data and intricate learning algorithms, highlighting an urgent need for advancements in lightweight sensing technologies. These technologies should leverage simpler terminal devices, reduced data volumes, and more straightforward classification algorithms to achieve sensing capability that are comparable to those offered by more complex and established methods. This article concentrates on the lightweight application of wireless sensing and encompasses the following key contributions: 1) the development of a lightweight sensing model utilizing a single-antenna multicarrier system, which introduces a CSI ratio model that adapts multiantenna techniques for single-antenna settings and 2) the enhancement of feature stability through the introduction of a complex-plane fitting method using artificial vector, alongside a dual receiver-based method for cross-scene feature generation aimed at producing stable and high-quality auxiliary features. Experimental results show that the feature extraction capability of the single-antenna multicarrier CSI ratio model is close to that of traditional multiantenna scheme. On the gait dataset, when the enhanced CSI ratio is used as a feature, the accuracy is nearly 100%, surpassing the 93% accuracy of the original amplitude feature. On the gesture dataset, the combination of the enhanced CSI ratio and position and environment independent features achieves an accuracy of 96%, which is superior to using the original CSI amplitude feature alone. An analysis of resource consumption shows that the lightweight SVM model incurs very low computational overhead during decision-making, validating the potential of this scheme in terms of efficiency and practical application. Yu Jiang 0020, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2025 | A Recovery-Mechanism-Driven Wireless Group Key Generation Protocol for Multiuser ScenariosabstractPhysical-layer key generation (PKG) leveraging the reciprocity of wireless channel provides an effective approach for key agreement among resource-constrained Internet of Things devices. However, current researches on PKG predominantly focus on pairwise communication scenarios, and there remain challenges in achieving group key generation for multiuser scenarios. In this article, we propose a novel recovery mechanism-driven wireless group key generation protocol to facilitate key sharing in the star network typology. Specifically, the root node will assign each member node its unique group key component before initiating group key distribution. Subsequently, all group key components are distributed to member nodes using a forward error correction mechanism, which helps reduce system overhead. Finally, all member nodes utilize a recovery mechanism and their respective group key component to obtain the same complete group key, thereby achieving group key distribution. Compared to existing schemes, our protocol can avoid the significant information leakage caused by repeated distribution of the same group key, thereby enhancing security. We further design and implement a practical wireless group key generation system using ESP32. Additionally, a group channel state information (CSI) extraction tool for multiuser channel measurements is developed. Experimental results demonstrate that our protocol can generate the group key with high randomness while benefiting from good channel reciprocity, making it suitable for cryptographic applications in multiuser communication scenarios. Huaicong Zhang, Yawen Huang, Jiabao Yu, Boqian Liu, Aiqun Hu |
IEEE Internet Things J. | 5 |
| 2025 | Channel-Robust RF Fingerprint Identification for Multi-Antenna 5G User EquipmentsabstractRadio frequency fingerprint (RFF) is a promising solution for realizing secure and efficient device identification. However, the accuracy of currently existing solutions suffer from multipath effects in practical scenarios. In this paper, we provide a robust RFF identification method that leverages channel state information (CSI) feedback to counteract the effect of the channel on the extracted RFF features. A straightforward zero-forcing (ZF) equalization fails to fully decouple RF impairments from the channel, making conventional approaches ineffective. To overcome this challenge, we utilize the potential of multi-antenna and introduce a new device-specific feature called Relative-RFF (R-RFF), which represents the relation between different RF chains in a multi-antenna transmitter. We propose an enhanced ZF post-equalization algorithm to eliminate the multipath channels and preserve the users’ R-RFF to the greatest extent. We evaluate the robustness of R-RFF under various channel conditions and noise levels and the performance of R-RFF in terms of identification accuracy under different channel scenarios. The results show that the proposed R-RFF method can achieve an identification accuracy of 91.2% for 70 devices in tapped delay line channel with a signal-to-noise ratio (SNR) of 30 dB. Hongyi Luo, Guyue Li, Alessandro Brighente, Mauro Conti, Yuexiu Xing, Aiqun Hu, Xianbin Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | An SNR-Aware Feature Reconstruction Method in Radio Frequency Fingerprint IdentificationabstractThe radio frequency fingerprint (RFF) has gained significant traction in the identification of wireless Internet of Things (IoT) devices. However, RFFs extracted from wireless signals are inherently susceptible to noise, particularly for narrowband signals. Furthermore, the noisy domain adaptation (NDA) problem presents a substantial challenge for RFF identification due to the variable noise interference across different noisy domains. To address this, the squared cross power spectral density (SCPSD) as new device RFFs is derived theoretically as a function of signal-to-noise ratio (SNR). Combined with the proposed high-precision SNR estimation algorithm, SCPSDs under low SNR can be reconstructed to the same feature distribution as those under high SNR. Because of the interpretability, ten samples under high SNR from each device under test (DUT) and a shallow convolutional neural network (CNN) are trained for experimental evaluation on the NDA problem. Tested on 60 off-the-shelf ZigBee DUTs, the improvement of identification accuracy is around 26% for SNR between 5 dB and 10 dB, and the overall improvement is more than 20% compared to the baseline. It outperforms the three other compared methods across all testing SNR and is highly practical. Junxian Shi, Linning Peng, Lingnan Xie, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Optimal Subcarrier Allocation Scheme for Physical-Layer Key Generation in an OFDMA NetworkabstractThis paper studies enhanced physical-layer key generation (PKG) for multiuser orthogonal frequency division multiple access (OFDMA) networks. In practical OFDMA systems, our key observation is that there are frequency correlations between different subcarriers which potentially lead to compromised randomness of the generated keys as well as reduced sum secret key rate. Motivated by this, we show that subcarrier allocation plays a key role in enhancing the PKG performance in OFMDA networks. We prove that when a single user terminal selects a finite number of subcarriers for key generation, adopting uniformly spaced subcarriers is the optimal solution as it leads to higher secret key rates and better randomness. Moreover, we derive a closed-form expression for the sum secret key rate and introduce a low-complexity near-optimal algorithm that can achieve an appropriate subcarrier allocation policy in a timely manner. Simulation results show that our proposed near-optimal algorithm exhibits significant advantages in maximizing the sum secret key rate and improving key randomness compared with existing subcarrier allocation algorithms. Qingjiang Xiao, Guyue Li, Zi Long Liu 0001, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Physical-layer Secret Key Generation with Energy Efficiency MaximizationabstractPhysical-layer secret key generation (PKG) is an emerging technique for secret key sharing. However, researches on it rarely consider the issue of energy efficiency, which results in a limited performance gain at the expense of a large amount of consumed energy. In this paper, we define the secret key energy efficiency (KEE) as the ratio of the generated secret key bits to the total energy consumption in the resource constrained PKG system. An optimization problem with quality of service (QoS) requirement and power consumption constraints is formulated and a multi-layer iterative algorithm to maximize the KEE is proposed. To cope with the difficulty of the non-convex problem, we transform and iterate it until it is equivalent to the primal problem by applying the Dinkelbach algorithm. In each iteration, the penalty algorithm and difference-of-convex-functions (DC) programming algorithm are used to tackle the non-convex constraints and objectives, respectively. Simulation results demonstrate that the KEE which is maximized can be 84% higher than that of the secret key rate (SKR) maximization only at the cost of a 5% decrease in SKR. Sheng Feng, Guyue Li, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 5 |
| 2024 | BioWarp: An SDN Failure Recovery Scheme Based on Bio-Mimetic Optimization and Weighted-Cost Multi-Path RoutingabstractThe escalating complexity of networks due to advancements in cloud computing, IoT, and data centers necessitates a shift towards more adaptable and scalable network architectures. Software Defined Networking (SDN) has risen as a prominent solution, offering a separation of control and data planes to bolster flexibility and manageability. However, network failures remain an inherent risk, undermining the reliability of both traditional and SDN environments. This paper presents BioWarp, a novel SDN failure recovery scheme that integrates bio-mimetic optimization with a Weighted-Cost Multi-Path (WCMP) routing approach. BioWarp confronts the unique challenges of SDN, such as TCAM overflow and controller computation stress, by proposing a hybrid strategy that merges the strengths of proactive and reactive recovery methods. We introduce a flow label based aggregation method to alleviate the burden on flow tables and controller resources. The Coati Optimization Algorithm (COA), inspired by the behaviors of coatis, is adapted to optimize weight update in real-time, facilitating rapid and efficient recovery from network faults. Simulation experiments are conducted to substantiate the scheme’s efficacy, demonstrating improved recovery times and resource management without compromising network stability. Zhongyuan Qin, Shiyuan Feng, Huahao Zhao, Aiqun Hu |
HPCC | 5 |
| 2024 | A Robust Radio Frequency Fingerprint Extraction Method Based on Channel ReciprocityabstractRadio Frequency Fingerprint (RFF) identification is a promising technique for physical layer identification that can enhance wireless security. However, interference of wireless channel characteristics is a key challenge hindering its robustness. To solve this problem, we propose a channel-robust RFF extraction method. First, we design a challenge-response mechanism-based framework to satisfy the uplink and downlink channel reciprocity. Then, we propose a novel RFF extraction method named Quotient of the Estimated Channel State Information (QoECSI) that exploits channel reciprocity to eliminate channel effects. We implemented the QoECSI with the ESP32 development kits that support 2.4GHz Wi-Fi, Experimental results show that the extracted RFF features have high discrimination and long-term stability, and are robust to channel variations and noise. The accuracy rate is higher than 98% when the Signal-to-Noise Ratio (SNR) exceeds 25 dB. Specifically, in a Non-Line-of-Sight (NLOS) scenario with SNR = 35 dB, the average recognition accuracy of cross-validation is 98.56%. In a dynamic scenario where the terminal moves slowly indoors along a fixed route, the highest cross-time-validation accuracy is 98.57%. Bingshu Dong, Aiqun Hu, Jiabao Yu, Hongxia Chen, Zhiyi Shi |
WCNC | 2 |
| 2024 | An Authentication Mechanism Based on Zero Trust With Radio Frequency Fingerprint for Internet of Things NetworksabstractWith the development of IoT and cloud networks, the security of edge networks, borderless networks and obscure networks are essential, so there are many security problems that need to be tackled, including over-trust in trust areas and security only based on security boundaries in traditional security architecture. According to characters of zero trust security architectures and integrative trust model, the zero trust architectures better adapt to handle these security problems compared to the integrative trust model for the Internet of Things (IoT) networks. Meanwhile, the radio frequency fingerprint (RFF) identification keeps high accuracy and high stability with researchers’ investigation, which makes RFF authentication feasible. Therefore, we propose a mechanism that combines the RFF authentication technique and zero trust architecture to improve security in IOT networks, including edge networks, borderless networks and obscure networks. The method resolves the difficulty of over-reliance on a trustable center or trust chain, and the method is suitable for borderless networks and obscure networks. Besides, this method resists data leakage, counterfeit attack and rouge AP attack with RFF authentication, and it can reduce the risk caused by compromised devices with zero trust concepts. With the analysis in the paper, the proposed method keeps high-level security and performance that method effectively against spoofing identity, tampering and information disclosure. The authentication accuracy of the method has reached 99%, and the authentication owns robustness in time cost and collision-resistant. Wentao Jing, Linning Peng, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2024 | Wireless Channel Key Generation Based on Multisubcarrier Phase DifferenceabstractWireless channel key generation technology is an important mechanism to guarantee the security of wireless network, but influenced by the key length and the actual electromagnetic environment, wireless channel key generation technology is faced with the challenge of high-key generation rate (KGR) and low-key disagreement rate (KDR). The existing key generation methods also lack the full use of the channel state information (CSI). We propose a key generation method based on multisubcarrier phase difference to expand the randomness source dimension, eliminate the phase bias, offset part of the noise influence, and set the threshold screening data to reduce the influence of measurement error. We further propose a key generation method based on resampling of kernel density estimation (KDE), which yields highly reciprocal randomness sources by resampling the results of KDE of phase difference values. To fill the metric gap of whether a method keeps low KDR while increasing the KGR, the evaluation metric of effective improvement ratio (EIR) is proposed. The two methods we proposed have a higher EIR than the method of using multiple-input and multiple-output (MIMO) and increasing the quantization level, achieving the goal of increasing the KGR while maintaining the low KDR. The KGR can reach about 12146 bits/s, and the KDR is 1.83%. The keys obtained by both methods can effectively prevent passive eavesdropping and meet the randomness requirements. Xiaowei Yuan, Yu Jiang 0020, Guyue Li, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2024 | Privacy-Preserving Decentralized Functional Encryption for Inner ProductabstractTo support secure data mining and privacy-preserving computation, partial access and selective computation on encrypted data are desirable. Functional encryption (FE) is a new paradigm of public-key encryption and allows authorized users to compute specific functions on encrypted data without knowing the data. However, in some FE schemes, a trusted central authority (CA) is required to generate secret keys for users according to the description of functions. In this paper, to reduce trust on the CA and protect users' privacy, a privacy-preserving decentralised FE for inner product (PPDFEIP) scheme is proposed where multiple authorities co-exist and work independently without any interaction. Especially, to resist collusion attacks, all secret keys of the same user are tied to his/her global identifier (GID), but authorities cannot know any information of the GID even if they collaborate. We formalize the definition and security model of our PPFEIP scheme, and propose a concrete construction. Furthermore, the proposed scheme is implemented and evaluated. Finally, the security of our PPDFEIP scheme is reduced to well-known complexity assumptions. The novelty is to reduce trust on the CA, protect users' privacy and enable authorized users to compute inner product on encrypted data without compromising confidentiality. Jinguang Han, Liqun Chen 0002, Aiqun Hu, Liquan Chen, Jiguo Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | RIS-Jamming: Breaking Key Consistency in Channel Reciprocity-Based Key GenerationabstractChannel Reciprocity-based Key Generation (CRKG) exploits reciprocal channel randomness to establish shared secret keys between wireless terminals. This new security technique is expected to complement existing cryptographic techniques for secret key distribution of future wireless networks. In this paper, we present a new attack, reconfigurable intelligent surface (RIS) jamming, and show that an attacker can prevent legitimate users from agreeing on the same key by deploying a malicious RIS to break channel reciprocity. Specifically, we elaborate on three examples to implement the RIS-jamming attack: Using active nonreciprocal circuits, performing time-varying controls, and reducing the signal-to-noise ratio. The attack effect is then studied by formulating the secret key rate with a relationship to the deployment of RIS. To resist such RIS-jamming attacks, we propose a countermeasure that exploits wideband signals for multipath separation. The malicious RIS path is distinguished from all separated channel paths, and thus the countermeasure is referred to as contaminated path removal-based CRKG (CPR-CRKG). We present simulation results, showing that legitimate users under RIS jamming are still able to generate secret keys from the remaining paths. We also experimentally demonstrate the RIS-jamming attack by using commodity Wi-Fi devices in conjunction with a fabricated RIS prototype. In our experiments, we were able to increase the average bit disagreement ratio (BDR) of raw secret keys by 20%. Further, we successfully demonstrate the proposed CPR-CRKG countermeasure to tackle RIS jamming in wideband systems as long as the source of randomness and the RIS propagation paths are separable. Guyue Li, Paul Staat, Markus Heinrichs, Christian T. Zenger, Rainer Kronberger, Harald Elders-Boll, Christof Paar, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2024 | Lightweight Radio Frequency Fingerprint Identification Scheme for V2X Based on Temporal CorrelationabstractRadio frequency fingerprinting identification (RFFI) is a promising physical layer authentication technique based on the inherent hardware defects of transmitters, yet there are bottlenecks in its application to vehicular networks. In this paper, we focus on the concerns of data dependency, channel effects, signal representation, and model efficiency to propose a lightweight RFFI scheme for vehicle-to-everything (V2X) communication based on temporal correlation. Specifically, modified gramian angular filed (MAGF) and Markov probability transition matrix with temporal dependency (MTTD) are proposed for signal representation to mine the temporal information related to device identity in terms of angular variation trajectory and first-order Markov transition probabilities, respectively. Due to the superiority of the proposed signal representation, paired with the customized pre-processing design, a lightweight feature extractor can achieve satisfactory RFFI performance in a very short time. We performed a comprehensive complexity analysis of existing models in the field and validated the proposed scheme using thirteen V2X devices in real wireless environments. In addition, the generalizability of the proposed pre-processing and representation method is demonstrated by testing on different deep learning models. Xinyu Qi, Aiqun Hu, Tianshu Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Reconfigurable Intelligent Surface-Assisted Secret Key Generation in Spatially Correlated ChannelsabstractReconfigurable intelligent surface (RIS) is a disruptive technology to enhance the performance of physical-layer key generation (PKG) thanks to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the base station (BS) and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment and neglecting the existence of channel spatial correlation would possibly degrade the PKG performance. In this paper, we establish a general spatially correlated channel model and propose a new channel probing framework based on the transmit and the reflective beamforming. We derive a closed-form key generation rate (KGR) expression and formulate an optimization problem, which is solved by using the low-complexity Block Successive Upper-bound Minimization (BSUM) with Mirror-Prox method. Simulation results show that compared to the existing methods based on the i.i.d. fading model, our proposed method achieves about 5 dB transmit power gain when the spacing between two neighboring RIS elements is a quarter of the wavelength. Also, the KGR increases significantly with the number of RIS elements while that increases marginally with the number of BS and user antennas. Lei Hu 0005, Guyue Li, Xuewen Qian, Aiqun Hu, Derrick Wing Kwan Ng |
IEEE Trans. Wirel. Commun. | 4 |
| 2023 | RelativeRFF: Multi-Antenna Device Identification in Multipath Propagation ScenariosabstractRadio frequency fingerprinting (RFF) is a promising solution for realizing secure and efficient device authentication. The multipath channel overshadows and disrupts the RFF extraction, which causes difficulties in training new models in the presence of fading. Existing approaches attempt to deal with this challenge by traversing channels through simulated channel models. However, this solution requires a large amount of data for training and it is difficult to guarantee that the training covers all possible channels. To mitigate the multipath channel effect on RFF with less training data, we propose a new method in a multi-antenna system, named Relative-RFF (R-RFF), which utilizes channel state information (CSI) feedback to counteract the multipath channel. The RFF imperfection relation between the different antenna chains of the device is proved to be retained after the counteraction of the multipath channel. Numerical results demonstrate that the proposed R-RFF can achieve an identification accuracy of 95.9% for 30 UEs in Tapped Delay Line channel with a signal-to-noise ratio of 20 dB. Hongyi Luo, Guyue Li, Yuexiu Xing, Junqing Zhang, Aiqun Hu, Xianbin Wang 0001 |
ICC | 5 |
| 2023 | Joint Estimation of Transmitter IQ Imbalance and Nonlinearity with Multipath in OFDM SystemsabstractRadio frequency (RF) fingerprint has been an emerging research topic since the last decade. Numerous algorithms for recognition have been proposed. However, algorithms for accurate extraction of in-phase/quadrature phase imbalance (IQI) and power amplifier (PA) nonlinearity are hardly available especially when multipath is considered. This paper presents a joint estimation of transmitter IQI and PA nonlinearity with multipath in OFDM systems. Using sequential iterative estimation algorithm, transmitter IQI, PA nonlinearity and multipath are jointly and separately estimated efficiently. After obtaining these parameters, a compensation approach for IQI, PA nonlinearity and multipath is given via equalization operation at receiver. Simulation results show that the proposed algorithm has a significant estimation accuracy advantage compared to the other two algorithms that already exist. Aiqun Hu, Huifeng Tian |
VTC Fall | 2 |
| 2023 | Angular-domain Secret Key Generation for RIS-aided mmWave MIMO systemsabstractThis paper investigates a physical layer key generation (PLKG) scheme for reconfigurable intelligent surface (RIS)-aided millimeter-wave (mmWave) multiple-input multipleoutput (MIMO) systems. Unlike traditional PLKG which relies on channel state information (CSI), we exploit the virtual angles of departure (AoDs). To accurately estimate these angles, we propose a redundant transforming matrix-based compressive sampling matching pursuit (RTMCoSa) method. We then derive the secret key rate (SKR) of the RIS-aided mmWave system. Simulation results demonstrate that the RTMCoSa method outperforms existing orthogonal matching pursuit (OMP) methods in channel probing for angle information. What is more, the proposed key generation scheme surpasses traditional CSI-based methods in SKR when the SNR is low. And the SKR of our method maintains robust when the SNR decreases. Hongyuan Li, Liquan Chen, Tianyu Lu, Aiqun Hu |
VTC Fall | 4 |
| 2023 | RIS-Assisted Physical-Layer Key Generation with Discrete Phase Shift OptimizationabstractThe artificial electromagnetic characteristics of reconfigurable intelligent surfaces (RIS) offers new opportunities to increase the secret key rate (SKR) in physical-layer key generation (PKG). However, the existing literature has primarily focused on continuous phase shift designs for RIS to enhance the SKR, while in practice the phase shifts are discrete due to hardware implementations. Hence, the extent to which practical RIS with discrete phase shifts can enhance SKR remains uncertain. Moreover, we have observed that existing optimization methods are not directly applicable to RIS with discrete phase shifts and relying solely on the approximation projection algorithm may lead to certain SKR performance degradation. To address these problems, this paper proposes a RIS-assisted PKG model considering the impact of discrete RIS phase shifts. To maximize the SKR by properly designing the RIS phase shifts, we propose an algorithm utilizing linear conic reformulation (LCR) with alternating difference-of-convex (DC) programming and successive convex approximation (SCA). Simulation results unveil that the proposed LCR-DC algorithm has the capability to achieve the SKR close to the optimal solutions. Furthermore, increasing the number of RIS elements or the number of quantization bits for RIS phase shifts enhances SKR but with diminishing returns. It is worth noting that a small number of discrete phase shifts, e.g., 2-3 quantization bits, is generally sufficient to achieve satisfactory SKR performance. Guyue Li, Lei Hu 0005, Aiqun Hu, Derrick Wing Kwan Ng |
VTC Fall | 4 |
| 2023 | Toward Novel Time Representations for RFF Identification Using Imperfect Data SetsabstractAs an inherent attribute of hardware circuit, radio-frequency fingerprint (RFF) is hardly forged and unique. Recently, the connection with deep learning has made it one of the most powerful guarantees of physical-layer security. Most existing RFF-based methods are designed under ideal data sets, thus tend to be less versatile in real-world scenarios. To address this problem, we propose a novel RFF identification scheme toward imperfect data sets of small sample size and fragmentary signal. Two novel time representations are proposed to visualize the RFFs by digging the embedded temporal information, which are named 1-D Gramian angular fields (1DGAF) and 2-D Gramian angular fields (2DGAF), respectively. Specifically, extremely short segments of the received preamble are transformed into images using 1DGAF and 2DGAF. Then, the images are fed into a channel-selectable convolutional neural network (CNN) for further identification. Theoretical analysis indicates that the proposed methods can augment the separability of the original data, leading to a better identification performance. Experimental results show that the accuracy reach 94.81% with only three half-sine waves and 99.26% with a quarter of the preamble at the signal-to-noise ratio level of 30 dB. The robustness of the proposed methods using unseen symbols has also been verified. Xinyu Qi, Aiqun Hu |
IEEE Internet Things J. | 2 |
| 2023 | Robust RF Fingerprint Extraction Based on Cyclic Shift CharacteristicabstractAs a novel solution for identification of Internet of Things (IoT) devices, radio frequency fingerprint (RFF) has excellent features, such as uniqueness, stability, and nonreproducibility. We propose an RFF extraction method for a type of signals with the cyclic shift characteristic (CSC). The extracted RFF is robust in terms of data independence, noise resistance, and channel immunity. A unified RFF representation is derived by the cross-power spectral density (CPSD)-based extraction method, which utilizes all different symbols within one signal frame under the random sending symbol conditions. Theoretical analysis demonstrates that this representation can be superimposed to obtain effective device identification performance under the low signal-to-noise ratio (SNR) conditions. Additionally, a preamble spectrum correlation (PSC) algorithm is proposed to fast estimate and compensate the large carrier frequency offset (CFO) in the preprocessing process of CPSD-based feature extraction. Our method is verified by conducting extensive experiments with over 34000 frames from 60 ZigBee devices in various scenarios, including indoor/outdoor and line-of-sight/non-LOS (LOS/NLOS). The identification accuracy reaches 96.66% for 60 devices in the LOS scenario and 98.81% for 36 devices in the NLOS scenario both with the shortest frame compared to the existing methods in practice. Thanks to the robust RFF extraction, experimental results show that our method adopting a simple linear discriminant analysis (LDA) classifier outperforms the state-of-the-art RFF identification methods using deep learning-based neural networks. Junxian Shi, Linning Peng, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2023 | Design of a Channel Robust Radio Frequency Fingerprint Identification SchemeabstractRadio frequency fingerprint (RFF) identification is an emerging device authentication technique that exploits the hardware imperfections resulting from the manufacturing process. Due to the varying impact of the wireless channel during RFF training and test stages, it is challenging to design channel-independent RFF techniques. This article designs a channel robust RFF identification scheme by leveraging the different spectrum of adjacent signal symbols, named the Difference of the Logarithm of the Spectrum (DoLoS), which does not rely on a single RFF feature or requires additional manipulation of the devices under test. Specifically, DoLoS exploits the fact that two different symbols in a packet exhibit different RFF features but have a similar channel response during the channel coherence time. We implemented the DoLoS with the IEEE 802.11 orthogonal frequency division multiplexing (OFDM) system as a case study. We carried out extensive experiments using seven Wi-Fi devices of the same model in different wireless channel environments, including 12 data collection positions in two completely different environments. Compared with conventional RFF identification schemes that do not eliminate channel effects, our scheme is robust to channel variations and the highest identification accuracy is 99.02% in the single-environment evaluation and 97.05% in the cross-environment evaluation. Yuexiu Xing, Aiqun Hu, Junqing Zhang, Linning Peng, Xianbin Wang 0001 |
IEEE Internet Things J. | 2 |
| 2023 | Anonymous Edge Representation for Inductive Anomaly Detection in Dynamic Bipartite GraphsabstractThe activities in many real-world applications, such as e-commerce and online education, are usually modeled as a dynamic bipartite graph that evolves over time. It is a critical task to detect anomalies inductively in a dynamic bipartite graph. Previous approaches either focus on detecting pre-defined types of anomalies or cannot handle nodes that are unseen during the training stage. To address this challenge, we propose an effective method to learn anonymous edge representation (AER) that captures the characteristics of an edge without using identity information. We further propose a model named AER-AD to utilize AER to detect anomalies in dynamic bipartite graphs in an inductive setting. Extensive experiments on both real-life and synthetic datasets are conducted to illustrate that AER-AD outperforms state-of-the-art baselines. In terms of AUC and F1, AER-AD is able to achieve 8.38% and 14.98% higher results than the best inductive representation baselines, and 6.99% and 19.59% than the best anomaly detection baselines. Lanting Fang, Kaiyu Feng, Jie Gui, Shanshan Feng 0001, Aiqun Hu |
Proc. VLDB Endow. | 5 |
| 2023 | Reconfigurable Intelligent Surface-Aided Secret Key Generation in Multi-Cell SystemsabstractPhysical-layer key generation (PKG) exploits the reciprocity and randomness of wireless channels to generate a symmetric key between two legitimate communication ends. However, in multi-cell systems, PKG suffers from severe pilot contamination due to the reuse of pilots in different cells. In this paper, we invoke multiple reconfigurable intelligent surfaces (RISs) for adaptively shaping the environment and enhancing the PKG performance. To this end, we formulate an optimization problem to maximize the weighted sum key rate (WSKR) by jointly optimizing the precoding matrices at the base stations (BSs) and the phase shifts at the RISs. To address the non-convexity of the problem, we adopt an alternating optimization (AO)-based algorithm that divides the joint optimization problem into two subproblems. For the subproblem of precoding matrices, we apply the Lagrangian dual approach based on the Karush-Kuhn-Tucker (KKT) conditions. As for the subproblem of phase shifts, we adopt a projected gradient ascent (PGA) algorithm. Simulation results validate the effectiveness of the proposed scheme, demonstrating significant gains in WSKR. Moreover, compared with a single-RIS case, deploying multiple RISs offer spatial diversity so as to improve the PKG performance of multicell systems. Lei Hu 0005, Chen Sun 0004, Guyue Li, Aiqun Hu, Derrick Wing Kwan Ng |
IEEE Trans. Commun. | 4 |
| 2023 | Disentangled Representation Learning for RF Fingerprint Extraction Under Unknown Channel StatisticsabstractDeep learning (DL) applied to a device’s radio-frequency fingerprint (RFF) has attracted significant attention in physical-layer authentication due to its extraordinary classification performance. Conventional DL-RFF techniques are trained by adopting maximum likelihood estimation (MLE). Although their discriminability has recently been extended to unknown devices in open-set scenarios, they still tend to overfit the channel statistics embedded in the training dataset. This restricts their practical applications as it is challenging to collect sufficient training data capturing the characteristics of all possible wireless channel environments. To address this challenge, we propose a DL framework of disentangled representation (DR) learning that first learns to factor the signals into a device-relevant component and a device-irrelevant component via adversarial learning. Then, it shuffles these two parts within a dataset for implicit data augmentation, which imposes a strong regularization on RFF extractor learning to avoid the possible overfitting of device-irrelevant channel statistics, without collecting additional data from unknown channels. Experiments validate that the proposed approach, referred to as DR-based RFF, outperforms conventional methods in terms of generalizability to unknown devices under unknown complicated propagation environments, e.g., dispersive multipath fading channels, even though all the training data are collected in a simple environment with dominated direct line-of-sight (LoS) propagation paths. Renjie Xie, Wei Xu 0001, Jiabao Yu, Aiqun Hu, Derrick Wing Kwan Ng, A. Lee Swindlehurst |
IEEE Trans. Commun. | 4 |
| 2023 | Joint Precoding and Phase Shift Design in Reconfigurable Intelligent Surfaces-Assisted Secret Key GenerationabstractPhysical layer key generation (PLKG) is a promising technique to establish symmetric keys between resource-constrained legitimate users. However, PLKG suffers from a low key rate in harsh environments where channel randomness is limited. To address the problem, reconfigurable intelligent surfaces (RISs) are introduced to reshape the channels by controlling massive reflecting elements, which can provide more channel diversity. In this paper, we design a channel probing protocol to fully extract the randomness from the cascaded channel, i.e., the channels through reflecting elements. We derive the analytical expressions of the key rate and design a water-filling algorithm based on the Karush-Kuhn-Tucker (KKT) conditions to find the upper bound. To find the optimal precoding and phase shift matrices, we propose an algorithm based on the Grassmann manifold optimization methods. The system is evaluated in terms of the key rate, bit disagreement rate (BDR) and randomness. Simulation results show that our protocols significantly improve the key rate as compared to existing protocols. Compared to multiple-antennas systems without a RIS, our proposed method achieves an average 9.51 dB performance gain when the side length of an element is 1/4 wavelength and the Rician factor is 0 dB. Tianyu Lu, Liquan Chen, Junqing Zhang, Chen Chen 0071, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Unsupervised Rumor Detection Based on Propagation Tree VAEabstractThe wide spread of rumors inflicts damages on social media platforms. Detecting rumors has become an emerging problem concerning the public and government. A crucial problem for rumors detection on social media is the lack of reliably pre-annotated dataset to train classification models. To solve this problem, we propose an unsupervised model that detects rumors by measuring how well the tweets follow the normal patterns. However, the problem is challenging in how to automatically discover the normal patterns of tweets. To tackle the challenge, we first propose a novel tree variational autoencoder model that reconstructs the sentiment labels along the propagation tree of a factual tweet. Then we propose a cross-alignment method to align the multiple modalities, i.e., tree structure and propagation features, and output the final prediction results. We conduct extensive experiments on a real-world dataset collected from Weibo. The experiments show that the proposed method significantly outperforms the state-of-the-art unsupervised methods and adapts better to the concept drift than state-of-the-art supervised methods. Lanting Fang, Kaiyu Feng, Kaiqi Zhao 0001, Aiqun Hu, Tao Li 0053 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2023 | A Knowledge-Enriched Ensemble Method for Word Embedding and Multi-Sense EmbeddingabstractRepresenting words as embeddings has been proven to be successful in improving the performance in many natural language processing tasks. Different from the traditional methods that learn the embeddings from large text corpora, ensemble methods have been proposed to leverage the merits of pre-trained word embeddings as well as external semantic sources. In this paper, we propose a knowledge-enriched ensemble method to combine information from both knowledge graphs and pre-trained word embeddings. Specifically, we propose an attention network to retrofit the semantic information in the lexical knowledge graph into the pre-trained word embeddings. In addition, we further extend our method to contextual word embeddings and multi-sense embeddings. Extensive experiments demonstrate that the proposed word embeddings outperform the state-of-the-art models in word analogy, word similarity and several downstream tasks. The proposed word sense embeddings outperform the state-of-the-art models in word similarity and word sense induction tasks. Lanting Fang, Yong Luo 0002, Kaiyu Feng, Kaiqi Zhao 0001, Aiqun Hu |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2022 | Joint Transmit and Reflective Beamforming for RIS-assisted Secret Key GenerationabstractReconfigurable intelligent surface (RIS) is a promising technique to enhance the performance of physical-layer key generation (PKG) due to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the transmitter and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment. Also, neglecting the existence of channel spatial correlation would degrade the PKG performance. In this paper, we establish a general spatially correlated channel model in multi-antenna systems and propose a new PKG framework based on the transmit and the reflective beamforming at the base station (BS) and the RIS. Specifically, we derive a closed-form expression for characterizing the key generation rate (KGR) and obtain a globally optimal solution of the beamformers to maximize the KGR. Furthermore, we analyze the KGR performance difference between the one adopting the assumption of the i.i.d. model and that of the spatially correlated model. It is found that the beamforming designed for the correlated model outperforms that for the i.i.d. model while the KGR gain increases with the channel correlation. Simulation results show that compared to existing methods based on the i.i.d. fading model, our proposed method achieves about 5 dB performance gain when the BS antenna correlation$\rho$is 0.3 and the RIS element spacing is half of the wavelength. Lei Hu 0005, Guyue Li, Xuewen Qian, Derrick Wing Kwan Ng, Aiqun Hu |
GLOBECOM | 5 |
| 2022 | Signal-independent RFF Identification for LTE Mobile Devices via Ensemble Deep LearningabstractRadio frequency fingerprint (RFF)-based wireless device authentication is an emerging technique to prevent potential spoofing attacks in wireless communications. The random access preamble of the physical random access channel (PRACH) in Long Term Evolution (LTE) systems is the first message sent from a user equipment (UE). However, PRACH preambles change under different evolved Node B (eNB), which will affect the RFF extraction. In this paper, a signal-independent RFF extraction method is first proposed to extract varying LTE PRACH preambles under different LTE eNBs. Residual transient segment (RTS) features from the varying PRACH preambles are extracted for RFF identification. A convolutional neural network (CNN) based ensemble deep learning scheme is proposed to integrate benefits from different RFF features. An experimental system under real operator LTE eNB is designed to capture and identify real UE signals. Experimental results show that the classification accuracy of five UEs can reach more than 95% under the same eNB and 85% under different eNBs. Furthermore, longtime evaluations show that the UE RTS feature is robust over time. Yanjin Qiu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
GLOBECOM | 6 |
| 2022 | Fast and Secure Key Generation with Channel Obfuscation in Slowly Varying EnvironmentsabstractPhysical-layer secret key generation has emerged as a promising solution for establishing cryptographic keys by leveraging reciprocal and time-varying wireless channels. However, existing approaches suffer from low key generation rates and vulnerabilities under various attacks in slowly varying environments. We propose a new physical-layer secret key generation approach with channel obfuscation, which improves the dynamic property of channel parameters based on random filtering and random antenna scheduling. Our approach makes one party obfuscate the channel to allow the legitimate party to obtain similar dynamic channel parameters, yet prevents a third party from inferring the obfuscation information. Our approach allows more random bits to be extracted from the obfuscated channel parameters by a joint design of the K-L transform and adaptive quantization. Results from a testbed implementation show that our approach, compared to the existing ones that we evaluate, performs the best in generating high entropy bits at a fast rate and is able to resist various attacks in slowly varying environments. Specifically, our approach can achieve a significantly faster secret bit generation rate at roughly 67 bit/pkt, and the key sequences can pass the randomness tests of the NIST test suite. Guyue Li, Haiyu Yang, Junqing Zhang, Hongbo Liu 0002, Aiqun Hu |
INFOCOM | 5 |
| 2022 | Radio Frequency Fingerprints Extraction for LTE-V2X: A Channel Estimation Based MethodologyabstractThe vehicle-to-everything (V2X) technology has recently drawn attention from both academic and industrial areas. However, the openness of the wireless communication system makes it more vulnerable to identity impersonation and information tampering. How to employ the powerful radio frequency fingerprint (RFF) identification technology in V2X systems turns out to be a vital and challenging task. In this paper, we propose a novel RFF extraction method for Long Term Evolution-V2X (LTE-V2X) systems. In order to conquer the difficulty of extracting transmitter RFF in the presence of wireless channel and receiver noise, we first estimate the wireless channel which excludes the RFF. Then, we remove the impact of the wireless channel based on the channel estimate and obtain initial RFF features. Finally, we conduct RFF denoising to enhance the quality of the initial RFF. Simulation and experiment results both demonstrate that our proposed RFF extraction scheme achieves a high identification accuracy. Furthermore, the performance is also robust to the vehicle speed. Tianshu Chen, Hong Shen 0002, Aiqun Hu, Weihang He, Hongxing Hu |
VTC Fall | 3 |
| 2022 | Physical Layer Encryption Scheme Based on Dynamic Constellation RotationabstractPhysical layer encryption (PLE) has emerged as a promising technique to secure wireless communications. Different from conventional cryptography implemented at higher layers, PLE exploits the randomness of wireless channels to adjust symbol patterns at the physical layer, by which both data and modulation information can be protected. However, existing PLE schemes face challenges of security and robustness in practical usage. In a slowly varying environment, the constellation variation is negligible, which results in the vulnerability of PLE to the differential attack. Moreover, the decryption error rate of PLE is high when the channel reciprocity is not ideal. To tackle these problems, we exploit data randomness to enhance the dynamics of constellation variations between adjacent frames. Then we utilize analog-based encryption instead of digital-based encryption to dynamically rotate constellation, which reduces quantization loss and improves robustness to channel phase errors. Simulation results verify that the proposed scheme can effectively resist the differential attack and provide approximately a 4.5 dB gain when the bit error ratio (BER) is 0.001. Yujie Hou, Guyue Li, Shuping Dang, Lei Hu 0005, Aiqun Hu |
VTC Fall | 5 |
| 2022 | Embrace Imperfect Datasets: New Time Representation for RFF IdentificationabstractAs the inherent attribute of equipment circuit hardware, Radio Frequency Fingerprints (RFFs) is hardly-forged and has become one of the most powerful guarantees of physical layer security. Most existing RFF-based methods ignore the temporal relation and are designed under an ideal dataset with a large number of samples and complete signal records, thus they tend to be less versatile in real-world scenarios. To address this problem, we propose a novel time representation method for wireless signal pictorialization called modified gramian angular fields (MGAF), which depicts the characteristics of the signal along the time axis through the transformation of coordinate system and a representation of trigonometric difference. After that, a channel-selectable convolution neural network (CNN) is used to extract high-dimensional feature vectors as the RFFs for further identification. The entire experiments are conducted with purposely poorly designed datasets. The results shows the accuracy can reach at 94.82% with only three half-sine waves and 99.26% with a quarter of the preamble at the SNR level of 30 dB. Xinyu Qi, Aiqun Hu |
VTC Fall | 2 |
| 2022 | Authorized and Rogue LTE Terminal Identification Using Wavelet Coefficient Graph with Auto-encoderabstractThe wide popularity of 4G/5G mobile terminals increase the requirements of wireless security. Radio frequency fingerprint (RFF) technology can strengthen 4G/5G air interface accessing security at the physical layer. In this paper, a wavelet transform (WT) coefficient graphs RFF extraction with auto-encoder (AE) based rogue terminal detection scheme is proposed. At first, WT coefficients at 48 scales are extracted from the transient-power-off part of LTE physical random access channel (PRACH) preamble. Then, an AE network structure aimed for 2D WT coefficient graph is designed for rogue terminal detection. We successfully distinguish 7 mobile phones and 1 USRP under the proposed mechanism, where the authorized terminals from the same manufacturer can be identified with an accuracy of 90.08%. In addition, extensive experiments are carried out at LOS and NOLS scenarios, respectively, the proposed LTE identification scheme has demonstrated robustness in dynamic environments. Zhenni Wu, Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
VTC Fall | 6 |
| 2022 | Towards a privacy protection-capable noise fingerprinting for numerically aggregated data
Yun Hu 0002, Aiqun Hu, Chunguo Li |
Comput. Secur. | 2 |
| 2022 | Deep-Learning-Based Physical-Layer Secret Key Generation for FDD SystemsabstractPhysical-layer key generation (PKG) establishes cryptographic keys from highly correlated measurements of wireless channels, which relies on reciprocal channel characteristics between uplink and downlink, is a promising wireless security technique for Internet of Things (IoT). However, it is challenging to extract common features in frequency-division duplexing (FDD) systems as uplink and downlink transmissions operate at different frequency bands whose channel frequency responses are not reciprocal anymore. Existing PKG methods for FDD systems have many limitations, i.e., high overhead and security problems. This article proposes a novel PKG scheme that uses the feature mapping function between different frequency bands obtained by deep learning to make two users generate highly similar channel features in FDD systems. In particular, this is the first time to apply deep learning for PKG in FDD systems. We first prove the existence of the band feature mapping function for a given environment and a feedforward network with a single hidden layer can approximate the mapping function. Then, a key generation neural network (KGNet) is proposed for reciprocal channel feature construction, and a key generation scheme based on the KGNet is also proposed. Numerical results verify the excellent performance of the KGNet-based key generation scheme in terms of randomness, key generation ratio, and key error rate. Besides, the overhead analysis shows that the method proposed in this article can be used for resource-constrained IoT devices in FDD systems. Xinwei Zhang 0002, Guyue Li, Junqing Zhang, Aiqun Hu, Zongyue Hou, Bin Xiao 0001 |
IEEE Internet Things J. | 4 |
| 2022 | On Maximizing the Sum Secret Key Rate for Reconfigurable Intelligent Surface-Assisted Multiuser SystemsabstractChannel reciprocity-based key generation (CRKG) has recently emerged as a new technique to address the problem of key distribution in wireless networks. However, as this approach relies upon the characteristics of fading channels, the corresponding secret key rate may be low when the communication link is blocked. To enhance the applicability of CRKG in harsh propagation scenarios, this paper introduces a novel multiuser key generation scheme, which is referred to as RIS-assisted multiuser key generation (RMK) that leverages the reconfigurable intelligent surface (RIS) technology for appropriately shaping the environment and enhancing the sum secret key rate between an access point and multiple users. In the RMK scheme, an RIS-induced channel, rather than the direct channel, serves as the key source. We derive a general closed-form expression of the secret key rate and optimize the configuration of the RIS to maximize the sum secret key rate over independent and correlated fading channels in the presence of multiple users. In the presence of independent fading, we introduce a low-complexity algorithm based on the Karush-Kuhn-Tucker (KKT) condition. In the presence of correlated fading, the optimization problem is non-convex and challenging to solve. To tackle it, we propose a new optimization algorithm based on the semi-definite relaxation (SDR) and successive convex approximation (SCA) methods. Simulation results demonstrate that the proposed RMK scheme outperforms existing RIS-assisted algorithms and achieves a near-optimal sum secret key rate over independent and correlated fading channels. Guyue Li, Chen Sun 0004, Wei Xu 0001, Marco Di Renzo, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Griffin: Real-Time Network Intrusion Detection System via Ensemble of Autoencoder in SDNabstractMany efforts have been devoted to the development of efficient Network Intrusion Detection System (NIDS) using machine learning approaches in Software-defined Network (SDN). Unfortunately, existing solutions failed to detect real-time and zero-day attacks due to their limited throughput and prior knowledge-based detection. To this end, we propose Griffin, a NIDS that uses unsupervised machine learning expertise to detect both known and zero-day intrusion attacks in real-time with high accuracy. Specifically, Griffin uses an efficient feature extraction framework to capture the sequential features of the traffic packets. Then, it utilizes cluster analysis to reduce the feature scale to achieve low throughput. Moreover, an ensemble autoencoder is built automatically to further extract features with low complexity and high precision to train the model. We evaluate the accuracy, robustness, and complexity of the system using open datasets. The result shows that Griffin’s complexity is about 40% lower, and its accuracy is at most 19% higher than existing NIDS.Additionally, even in the situation with evasion, the Griffin has at most 9% decrease of AUC, which is a good performance compared with other solutions. Furthermore, this paper also utilizes the differential privacy framework during training autoencoders to protect datasets’ privacy which is inherent in machine learning approaches. Liyan Yang, Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data ReleasingabstractGenerative Adversarial Networks (GAN)-synthesized table publishing lets people privately learn insights without access to the private table. However, existing studies on Membership Inference (MI) Attacks show promising results on disclosing membership of training datasets of GAN-synthesized tables. Different from those works focusing on discovering membership of a given data point, in this paper, we propose a novel Membership Collision Attack against GANs (TableGAN-MCA), which allows an adversary given only synthetic entries randomly sampled from a black-box generator to recover partial GAN training data. Namely, a GAN-synthesized table immune to state-of-the-art MI attacks is vulnerable to the TableGAN-MCA. The success of TableGAN-MCA is boosted by an observation that GAN-synthesized tables potentially collide with the training data of the generator. Aoting Hu, Renjie Xie, Zhigang Lu 0001, Aiqun Hu, Minhui Xue 0001 |
CCS | 4 |
| 2021 | LTE Device Identification Based on RF Fingerprint with Multi-Channel Convolutional Neural NetworkabstractRadio frequency fingerprint (RFF) identification technique has drawn great attention to wireless terminal authentication. Long-Term Evolution (LTE) has been widely deployed all over the world. RFF-based LTE terminal identifications can prevent the potential impersonation or denial of service (DoS) attacks in the physical layer. This paper proposes a novel multi-channel convolutional neural network (MCCNN) for LTE terminal identification. Differential constellation trace figure (DCTF) is extracted from the random access preamble of the physical random access channel (PRACH). To the best knowledge of the authors, this is the first work dedicated to RFF-based LTE terminal identification. The proposed scheme is evaluated in the hardware experimental system consisting of the LTE eNodeB implemented on the software-defined radio (SDR) platform and six LTE mobile phones. Experimental results show that the classification accuracy can reach 98.96% at the SNR level of 30 dB with the line-of-sight (LOS) scenarios. Furthermore, long-time evaluations show that the proposed DCTF-MCCNN scheme is robust over time. Linning Peng, Junqing Zhang, Ming Liu 0010, Aiqun Hu |
GLOBECOM | 6 |
| 2021 | You Can Hear But You Cannot Record: Privacy Protection by Jamming Audio RecordingabstractUnauthorized voice recording via smartphones can leak the talking content stealthily. This would be a serious security threat to those individuals, enterprises and the government who need to keep the conversation confidential. Furthermore, due to the size miniaturization of smartphones, it is hard to find the covert recording from malicious attendees. Existing solutions usually jam the recording with audible noise or electromagnetic emitting. However, the audible noise will seriously interfere with conversation and the effect of electromagnetic emitting will be limited by the distance. In this paper, we propose UltraArray, a pioneering silent ultrasonic anti-recording jammer, which can covertly block recording for a long distance. The principle of covert blocking is inspired by acoustic parametric array theory, which suggests that the audible frequency wave can be spread through the air silently while it is modulated to an inaudible ultrasonic frequency. The modulation used in this paper is double sideband (DSB) modulation. The microphone on the phone will record the audible frequency and filtering out the ultrasonic frequency. The jammer we developed uses an acoustics array to form a beam to spread the signal further. The evaluation shows that the device has a good jamming effect on more than 5 meters for most Android smartphones. It will also work well with more than 2.5 meters effective distance on iPhone XR, which has the active noise control (ANC) function. Those results achieve ten times the interference ability of existing solutions. Xiaosong Ma, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
ICC | 6 |
| 2021 | On the RIS Manipulating Attack and Its Countermeasures in Physical-layer Key GenerationabstractReconfigurable Intelligent Surface (RIS) is a new paradigm that enables the reconfiguration of the wireless environment. Based on this feature, RIS can be employed to facilitate Physical-layer Key Generation (PKG). However, this technique could also be exploited by the attacker to destroy the key generation process via manipulating the channel features at the legitimate user side. Specifically, this paper proposes a new RIS-assisted Manipulating attack (RISM) that reduces the wireless channel reciprocity by rapidly changing the RIS reflection coefficient in the uplink and downlink channel probing step in orthogonal frequency division multiplexing (OFDM) systems. The vulnerability of traditional key generation technology based on channel frequency response (CFR) under this attack is analyzed. Then, we propose a slewing rate detection method based on path separation. The attacked path is removed from the time domain and a flexible quantization method is employed to maximize the Key Generation Rate (KGR). The simulation results show that under RISM attack, when the ratio of the attack path variance to the total path variance is 0.17, the Bit Disagreement Rate (BDR) of the CFR-based method is greater than 0.25, and the KGR is close to zero. In addition, the proposed detection method can successfully detect the attacked path for SNR above 0 dB in the case of 16 rounds of probing and the KGR is 35 bits/channel use at 23.04MHz bandwidth. Lei Hu 0005, Guyue Li, Hongyi Luo, Aiqun Hu |
VTC Fall | 4 |
| 2021 | Data desensitization mechanism of Android application based on differential privacyabstractIn recent years, the mining and analysis of user data by Android applications have posed the risk of privacy breaches. However excessive permission control can affect the usability of applications. A mechanism that balances security and usability is urgently needed. In this paper, a data desensitization mechanism for Android applications based on differential privacy techniques is proposed. The mechanism can address the privacy protection of data flows generated by the interaction between users and Android applications. In order to solve the problem of constraints on the basic functions of the application caused by privacy security technique, this paper introduces a differential privacy mechanism based on Gaussian process. The mechanism performs hyperparametric optimization methods that combine sparse approximations and classification results. Also, by specifying the global sensitivity of the differential privacy budget specific randomization algorithm, the mechanism selects parameters with a specific probability to obtain the most effective parameter combination. Experimental results show that the differential privacy technique based on Gaussian process further enhances the availability of Android application data while obtaining the same privacy protection effect compared with ordinary differential privacy mechanisms. Xinzao Jiang, Yubo Song, Rui Song 0010, Aiqun Hu |
VTC Fall | 4 |
| 2021 | CSI Measurement and Reciprocity Evaluation Method Based on Embedded PlatformabstractThe idea of physical layer security is to use the characteristics and damage of the propagation medium to ensure secure communication in the physical layer. Channel state information is a fine-grained value from the physical layer, which describes the amplitude and phase of each sub-carrier in the frequency domain. It estimates the channel information by representing the channel properties of the communication link. Due to the uniqueness and short-term reciprocity of the channel, both the sender and receiver can obtain almost the same and random CSI in a short time, and can generate the same and random key to realize secure communication between the two parties. At present, most of the traditional methods of obtaining CSI are costly, bulky, and limited in regions. In order to verify the validity, feasibility and stability of extracting CSI with Nexmon firmware and using it to generate keys, this paper verifies its performance. Chenlu Li, Yu Jiang 0020, Aiqun Hu |
VTC Fall | 3 |
| 2021 | Secret Key Generation for FDD Systems Based on Complex-Valued Neural NetworkabstractSecret key generation based on wireless channel reciprocity has received widespread attention. However, in frequency division duplexing (FDD) systems, since the carrier frequencies of the uplink and downlink are different and the channel coefficients are no longer reciprocal, key generation for FDD systems is challenging. In this paper, a Complex-Valued neural Network (CVNet) is proposed to predict the downlink channel and generate reciprocal channel characteristics. Then, based on the trained CVNet, we propose a key generation protocol for FDD systems. Numerical results show that the CVNet achieves better performance in terms of prediction accuracy, bit disagreement rate, and bit generation ratio than a traditional Real-Valued Network (RVNet) under high signal-to-noise ratios. Furthermore, the training parameters required by the CVNet account for only half of that required by the RVNet. Xinwei Zhang 0002, Guyue Li, Zongyue Hou, Aiqun Hu |
VTC Fall | 4 |
| 2021 | Encrypting Wireless Communications on the Fly Using One-Time Pad and Key GenerationabstractThe one-time pad (OTP) secure transmission relies on the random keys to achieve perfect secrecy, while the unpredictable wireless channel is shown to be a good random source. There is very few work of the joint design of OTP and key generation from wireless channels. This article provides a comprehensive and quantitative investigation on secure transmission achieved by OTP and wireless channel randomness. We propose two OTP secure transmission schemes, i.e., identical key-based physical-layer secure transmission (IK-PST) and un-IK-PST (UK-PST). We quantitatively analyze the performance of both schemes and prove that UK-PST outperforms IK-PST. We extend the pairwise schemes to a group of users in networks with star and chain topologies. We implement prototypes of both schemes and evaluate the proposed schemes through both simulations and experiments. The results verify that UK-PST has a higher effective secret transmission rate than that of IK-PST for scenarios with both pairwise and group users. Guyue Li, Zheying Zhang, Junqing Zhang, Aiqun Hu |
IEEE Internet Things J. | 4 |
| 2021 | A Robust Radio-Frequency Fingerprint Extraction Scheme for Practical Device RecognitionabstractRadio-frequency fingerprinting (RFF) exploiting hardware characteristics has been employed for device recognition to enhance the overall security. However, the performance unreliability in long-term experiments, channel fading interference, and unauthorized devices verification are three open problems that restrict the development of RFF recognition. To address these issues, a robust RFF extraction scheme based on three corresponding algorithms is studied. For the first problem, a long-term stacking of repetitive symbols (LSRSs) algorithm is proposed to reduce the acquired signal variance, which contributes to the identification accuracy and long-term stability. For the second issue, we propose an artificial noise adding (ANA) algorithm to enhance the recognition robustness through regularization and channel adaptation. For the third issue, a verification algorithm based on the generative Gaussian probabilistic linear discriminant analysis (GPLDA) model is developed to handle unauthorized devices. Our robust RFF extraction scheme is verified in the experiments with 54 CC2530 ZigBee devices. It enables reliable node identification with the accuracy of 99.50% in the short rang line-of-sight (SLOS) scenarios for signals collected over 18 months, and 95.52% in the extensive multipath fading experiments. The equal error rate (EER) of the verification experiments with six authorized devices versus six unseen unauthorized devices is as low as 0.63%. Xinyu Zhou 0005, Aiqun Hu, Guyue Li, Linning Peng, Yuexiu Xing, Jiabao Yu |
IEEE Internet Things J. | 2 |
| 2021 | A LoRa-Based Lightweight Secure Access Enhancement SystemabstractThe access control mechanism in LoRa has been proven to have high security risks. In order to improve the secure access ability of LoRa terminals, this paper presents a physical layer-based authentication system for security enhancement. Different from the security access technology of cryptography, a lightweight gateway architecture called LW-LoRaWAN is proposed to realize a data frame-based authentication with radio frequency fingerprint (RFF). A novel RFF feature of Cross Power Spectral Density (CPSD) is used to achieve a fast authentication with one single frame. Theoretical analysis and experimental results show that the proposed system not only reinforces the authentication security of LoRa network but also protects the LoRa terminals against the Sybil attacks. The LW-LoRaWAN provides new security approach from physical layer for LoRa network. Yu Jiang 0020, Aiqun Hu |
Secur. Commun. Networks | 3 |
| 2021 | Sum Secret Key Rate Maximization for TDD Multi-User Massive MIMO Wireless NetworksabstractPhysical-layer key generation (PKG) based on channel reciprocity has recently emerged as a new technique to establish secret keys between devices. Most works focus on pairwise communication scenarios with single or small-scale antennas. However, the fifth generation (5G) wireless communications employ massive multiple-input multiple-output (MIMO) to support multiple users simultaneously, bringing serious overhead of reciprocal channel acquisition. This paper presents a multi-user secret key generation in massive MIMO wireless networks. We provide a beam domain channel model, in which different elements represent the channel gains from different transmit directions to different receive directions. Based on this channel model, we analyze the secret key rate and derive a closed-form expression under independent channel conditions. To maximize the sum secret key rate, we provide the optimal conditions for the Kronecker product of the precoding and receiving matrices and propose an algorithm to generate these matrices with pilot reuse. The proposed optimization design can significantly reduce the pilot overhead of the reciprocal channel state information acquisition. Furthermore, we analyze the security under the channel correlation between user terminals (UTs), and propose a low overhead multi-user secret key generation with non-overlapping beams between UTs. Simulation results demonstrate the near-optimal performance of the proposed precoding and receiving matrices design and the advantages of the non-overlapping beam allocation. Guyue Li, Chen Sun 0004, Eduard A. Jorswieck, Junqing Zhang, Aiqun Hu, You Chen 0004 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Robust Key Generation With Hardware Mismatch for Secure MIMO CommunicationsabstractIn practical implementations, physical-layer key generation (PKG) encounters the bottlenecks of imperfect channel reciprocity, nearby attack, and high temporal auto-correlation. Existing One-Band Multiple-Antenna Loop-bAck key generation (OB-MALA) schemes try to address these challenges through establishing bi-directional channels via echoing rotated received signals. However, we find that OB-MALA schemes can be vulnerable to a multiply-divide (MD) attack, as they echo the received signals through the same band with the pilot signals. To overcome this deficiency, we propose a new method, named Two-Band Multiple-Antenna Loop-bAck key generation (TB-MALA), which exploits two separate bands for pilot transmission and echo reception. The TB-MALA is proved to be robust to the imperfect channel reciprocity caused by radio frequency (RF) front-ends and can resist both the nearby attack and the MD attack. It also reduces the auto-correlation of effective channels with the help of a rotation matrix. The secret key rate of TB-MALA is analyzed and the closed-form of a lower bound is derived for the worst case. Numerical results demonstrate that the proposed TB-MALA protects against these attacks and achieves performance comparable to the ideal case with the perfect reciprocity of RF front-ends. It can thus be used to form a robust, fast, and secure key generation in a multiple-input and multiple-output (MIMO) system. Guyue Li, Yinghao Xu 0002, Wei Xu 0001, Eduard A. Jorswieck, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | A Generalizable Model-and-Data Driven Approach for Open-Set RFF AuthenticationabstractRadio-frequency fingerprints (RFFs) are promising solutions for realizing low-cost physical layer authentication. Machine learning-based methods have been proposed for RFF extraction and discrimination. However, most existing methods are designed for the closed-set scenario where the set of devices is remains unchanged. These methods can not be generalized to the RFF discrimination of unknown devices. To enable the discrimination of RFF from both known and unknown devices, we propose a new end-to-end deep learning framework for extracting RFFs from raw received signals. The proposed framework comprises a novel preprocessing module, called neural synchronization (NS), which incorporates the data-driven learning with signal processing priors as an inductive bias from communication-model based processing. Compared to traditional carrier synchronization techniques, which are static, this module estimates offsets by two learnable deep neural networks jointly trained by the RFF extractor. Additionally, a hypersphere representation is proposed to further improve the discrimination of RFF. Theoretical analysis shows that such a data-and-model framework can better optimize the mutual information between device identity and the RFF, which naturally leads to better performance. Experimental results verify that the proposed RFF significantly outperforms purely data-driven DNN-design and existing handcrafted RFF methods in terms of both discrimination and network generalizability. Renjie Xie, Wei Xu 0001, Yanzhi Chen, Jiabao Yu, Aiqun Hu, Derrick Wing Kwan Ng, A. Lee Swindlehurst |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Griffin: An Ensemble of AutoEncoders for Anomaly Traffic Detection in SDNabstractThe Network Intrusion Detection Systems (NIDS) with machine learning in SDN become increasingly popular solutions. NIDS uses abnormal traffic detection to identify unknown network attacks. Most of today's abnormal traffic detection systems are supposed to continuously update the recognition model in time based on the features from newly collected packets to accurately identify unknown network attack behaviors. However, those existing solutions always require a large number of packets to train the recognition model offline. That means it is impossible to accurately detect the emergence of new cyber-attacks immediately. This paper proposes Griffin, a per-packet anomaly detection system that can dynamically update the training model based on neural networks. The Griffin is executed in SDN environment, utilizing a novel ensemble of autoencoders to collectively filter out abnormal traffic from normal traffic. Meanwhile, the autoencoders are updated based on the root mean square error to adjust the training model. The adjustment is done in an unsupervised manner, which needs no expert to label the network traffic or update the model from time to time. Our evaluations, with the open Datasets provided by Yisroel Mirsky, show that Griffin's time delay is around 0. 1s and its accuracy is 98%. Moreover, we also compare Griffin with other four similar NIDSs and find that Griffin performs the best in terms of Matthews Correlation Coefficient and complexity. Liyan Yang, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 5 |
| 2020 | Improved collusion-resistant unidirectional proxy re-encryption scheme from latticeabstractProxy re‐encryption (PRE) is a promising cryptographic structure for pervasive data sharing in cloud‐based social networks, which enables a semi‐trusted proxy to convert a ciphertext for Alice into a ciphertext for Bob without seeing the corresponding plaintext. Since the proxy is semi‐trust, a PRE scheme which can resist the collusion attack will be of great practical value. Jiang et al . in 2015 and Kim and Jeong in 2016 have proposed collusion‐resistant PRE (CR‐PRE) schemes from the lattice by a similar technique, respectively. However, through the analysis of their schemes, the authors find that both of them have defects in the construction of the re‐encryption key, which will lead to the re‐encryption ciphertext cannot be decrypted or decrypted error with high probability. In this study, the authors first point out the defects in the work of Jiang et al . 's work and Kim and Jeong's work and propose an improved collusion‐resistant unidirectional PRE scheme from lattice, based on learning with errors problems. In addition to solving the defects, CR‐PRE still has many useful properties similar to the previous schemes, such as unidirectional, collusion resistant, chosen‐plaintext attack secure and so on. Aiqun Hu |
IET Inf. Secur. | 2 |
| 2020 | Design of a Robust Radio-Frequency Fingerprint Identification Scheme for Multimode LFM RadarabstractRadar is an indispensable part of the Internet of Things (IoT). Specific emitter identification is essential to identify the legitimate radars and, more importantly, to reject the malicious radars. Conventional methods rely on pulse parameters that are not capable to identify the specific emitter as two radars may have the same configuration or a malicious radar can perform spoofing attacks. Radio-frequency fingerprint (RFF) is the unique and intrinsic hardware characteristic of devices resulted from hardware imperfection, which can be used as the device identity. This article proposes a robust and reliable radar identification scheme based on the RFF, taking linear frequency modulation (LFM) radar as a case study. This scheme first classifies the operation mode of the pulses, then eliminates the noise effect, and finally identifies the radar emitters based on the transient and modulation-based RFF features. The experimental results verify the effectiveness of our radar identification scheme among three real LFM radars (same model) operating at four modes, each mode with 2000 pulses from each radar. The identification rates of the four modes are all higher than 90% when the signal-to-noise ratio (SNR) is about 5 dB. In addition, mode 3 achieves almost 100% identification accuracy even when the SNR is as low as -10 dB. Yuexiu Xing, Aiqun Hu, Junqing Zhang, Jiabao Yu, Guyue Li, Ting Wang 0029 |
IEEE Internet Things J. | 2 |
| 2020 | Detection and Mitigation of DoS Attacks in Software Defined NetworksabstractThe introduction of software-defined networking (SDN) has emerged as a new network paradigm for network innovations. By decoupling the control plane from the data plane in traditional networks, SDN provides high programmability to control and manage networks. However, the communication between the two planes can be a bottleneck of the whole network. SDN-aimed DoS attacks can cause long packet delay and high packet loss rate by using massive table-miss packets to jam links between the two planes. To detect and mitigate SDN-aimed DoS attacks, this paper presents FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks. FloodDefender stands between the controller platform and other controller apps, and conforms to the OpenFlow policy without additional devices. The detection module in FloodDefender utilizes new frequency features to precisely identify SDN-aimed DoS attacks. The mitigation module uses three new techniques to efficiently mitigate attack traffic: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to filter out attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. Our evaluation on a prototype implementation of FloodDefender shows that the defense framework can precisely identify and efficiently mitigate the SDN-aimed DoS attacks with very little overhead. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Aiqun Hu, Yubo Song, Kui Ren 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2019 | A Design of Deep Learning Based Optical Fiber Ethernet Device Fingerprint Identification SystemabstractThis paper proposes a novel deep learning based hardware fingerprint identification method for optical fiber Ethernet devices. An adjacent constellation trance figure (ACTF) feature extraction method is firstly introduced for baseband modulation system with only amplitude waveform. A 2-dimensional convolutional neural network (2D-CNN) is designed to classify different optical fiber Ethernet devices via ACTF features. An intensity modulation / direct detection (IM/DD) experimental system with 24 optical fiber Ethernet devices is designed for evaluations. We optimize the ACTF parameter setups and compare the classification accuracy with another deep learning based long short-term memory (LSTM) network and classical statistical feature methods. Experimental results show that our proposed ACTF-CNN can achieve a classification accuracy as high as 99.49% and 96.29% under SNR levels of 30 dB and 10 dB, respectively, which significantly outperforms LSTM network and statistical feature based methods. Linning Peng, Aiqun Hu |
ICC | 2 |
| 2019 | An Adaptive Information Reconciliation Protocol for Physical-Layer Based Secret Key GenerationabstractPhysical-layer based secret key generation (SKG) becomes a research focus as it solves key distribution problem which is difficult in traditional cryptographic mechanism. To remove the disagreements caused by imperfect reciprocity of communicating parties, information reconciliation is a critical process in SKG to obtain symmetric keys. Various reconciliation schemes are proposed, e.g. BBBSS, Cascade, BCH code and Turbo code. Reconciliation efficiency is a common evaluation index which takes reconciliation success rate and information leakage rate into account. However, time delay caused by information interaction and computation overhead may affect reconciliation performance under specific scenarios. Therefore, a comprehensive evaluation metric is required to compare existing schemes. Besides, channel condition changes all the time in real mobile communication systems, and most existing reconciliation schemes only work well in certain channel conditions. Hence, a reconciliation scheme which can adapt to time-varying channel condition is required. In this paper, we introduce a novel comprehensive reconciliation efficiency index (CREI) to evaluate existing reconciliation schemes and propose an adaptive information reconciliation scheme selection (AIRSS) protocol to maximize CREI. The simulation results show the superiority of AIRSS and present recommendations of reconciliation scheme selection in different scenarios. Zheying Zhang, Guyue Li, Aiqun Hu |
VTC Spring | 3 |
| 2019 | A Robust Radio Frequency Fingerprint Identification Scheme for LFM Pulse RadarsabstractRadar transmitter identification technology based on pulse descriptor word (PDW) is broadly used in military and civilian applications. However, as the complexity of the electromagnetic environment has increased, radar identification has been challenging. Radio frequency fingerprint (RFF) is an intrinsic hardware characteristic and has been widely employed for device identification. In this paper, we propose a robust RFF identification scheme for linear frequency modulation (LFM) pulse radars. The scheme includes a proposed piecewise curve fitting based denoising (PCFD) algorithm and a hybrid RFF identification algorithm. The PCFD algorithm can reduce the noise of LFM pulses without undermining RFF features. The hybrid RFF identification algorithm extracts both transient-based and modulation-based RFF features. Experimental results demonstrate that the proposed radar identification scheme can achieve a 100% identification accuracy when the SNR is about 0 dB. Yuexiu Xing, Aiqun Hu, Jiabao Yu, Guyue Li, Linning Peng, Fen Zhou 0001 |
WiMob | 2 |
| 2019 | Radio Frequency Fingerprint Identification Based on Denoising AutoencodersabstractRadio Frequency Fingerprinting (RFF) is one of the promising passive authentication approaches for improving the security of the Internet of Things (IoT). However, with the proliferation of low-power IoT devices, it becomes imperative to improve the identification accuracy at low SNR scenarios. To address this problem, this paper proposes a general Denoising AutoEncoder (DAE)-based model for deep learning RFF techniques. Besides, a partially stacking method is designed to appropriately combine the semi-steady and steady-state RFFs of ZigBee devices. The proposed Partially Stacking-based Convolutional DAE (PSC-DAE) aims at reconstructing a high-SNR signal as well as device identification. Experimental results demonstrate that compared to Convolutional Neural Network (CNN), PSCDAE can improve the identification accuracy by 14% to 23.5% at low SNRs (from -10 dB to 5 dB) under Additive White Gaussian Noise (AWGN) corrupted channels. Even at SNR = 10 dB, the identification accuracy is as high as 97.5%. Jiabao Yu, Aiqun Hu, Fen Zhou 0001, Yuexiu Xing, Guyue Li, Linning Peng |
WiMob | 2 |
| 2019 | Knowledge-Enhanced Ensemble Learning for Word EmbeddingsabstractRepresenting words as embeddings in a continuous vector space has been proven to be successful in improving the performance in many natural language processing (NLP) tasks. Beyond the traditional methods that learn the embeddings from large text corpora, ensemble methods have been proposed to leverage the merits from pre-trained word embeddings as well as external semantic sources. In this paper, we propose a knowledge-enhanced ensemble method to combine both knowledge graphs and pre-trained word embedding models. Specifically, we interpret relations in knowledge graphs as linear translation from one word to another. We also propose a novel weighting scheme to further distinguish edges in the knowledge graph with same type of relation. Extensive experiments demonstrate that our proposed method is up to 20% times better than state-of-the-art in word analogy task and up to 16% times better than state-of-the-art in word similarity task. Lanting Fang, Yong Luo 0002, Kaiyu Feng, Kaiqi Zhao 0001, Aiqun Hu |
WWW | 5 |
| 2019 | Design of a Hybrid RF Fingerprint Extraction and Device Classification SchemeabstractRadio frequency (RF) fingerprint is the inherent hardware characteristics and has been employed to classify and identify wireless devices in many Internet of Things applications. This paper extracts novel RF fingerprint features, designs a hybrid and adaptive classification scheme adjusting to the environment conditions, and carries out extensive experiments to evaluate the performance. In particular, four modulation features, namely differential constellation trace figure, carrier frequency offset, modulation offset and I/Q offset extracted from constellation trace figure, are employed. The feature weights under different channel conditions are calculated at the training stage. These features are combined smartly with the weights selected according to the estimated signal to noise ratio at the classification stage. We construct a testbed using universal software radio peripheral platform as the receiver and 54 ZigBee nodes as the candidate devices to be classified, which are the most ZigBee devices ever tested. Extensive experiments are carried out to evaluate the classification performance under different channel conditions, namely line-of-sight (LOS) and nonline-of-sight scenarios. We then validate the robustness by carrying out the classification process 18 months after the training, which is the longest time gap. We also use a different receiver platform for classification for the first time. The classification error rate is as low as 0.048 in LOS scenario, and 0.1105 even when a different receiver is used for classification 18 months after the training. Our hybrid classification scheme has thus been demonstrated effective in classifying a large amount of ZigBee devices. Linning Peng, Aiqun Hu, Junqing Zhang, Yu Jiang 0020, Jiabao Yu |
IEEE Internet Things J. | 2 |
| 2019 | A Robust RF Fingerprinting Approach Using Multisampling Convolutional Neural NetworkabstractWith the increasing popularity of the Internet of Things (IoT), device identification, and authentication has become a critical security issue. Recently, radio frequency (RF) fingerprint-based identification schemes have attracted wide attention as they extract the inherent characteristics of hardware circuits which is very hard to forge. However, existing RF fingerprint-based approaches face the problems of unstable region of interest (ROI), high-cost feature design, and incomplete automation. To address these problems, this paper proposes a multisampling convolutional neural network (MSCNN) to extract RF fingerprint from the selected ROI for classifying ZigBee devices. A signal-to-noise ratio (SNR) adaptive ROI selection algorithm is also developed to alleviate the effect of semi-steady behavior of ZigBee devices owing to sleep mode switching. The proposed MSCNN uses multiple downsampling transformations for multiscale feature extraction and classification automatically. To validate and evaluate the performance of our proposed method, we design a testbed consisting of one low-cost universal software radio peripheral (USRP) as the receiver and 54 CC2530 devices as targets for identification. Extensive experiments are conducted to demonstrate the feasibility and reliability of MSCNN both in the line-of-sight (LOS) scenarios and non-LOS (NLOS) scenarios. The classification accuracy is as high as 97% under the LOS scenarios around SNR = 30 dB. Our scheme is robust over a wide range of SNRs under the LOS scenarios as well as under the NLOS scenarios. Jiabao Yu, Aiqun Hu, Guyue Li, Linning Peng |
IEEE Internet Things J. | 2 |
| 2019 | An Investigation of Using Loop-Back Mechanism for Channel Reciprocity Enhancement in Secret Key GenerationabstractPhysical layer security key generation exploits unpredictable features from wireless channels to achieve high security, which requires high reciprocity in order to set up symmetric keys between two users. This paper investigates enhancing the channel reciprocity using a loop-back scheme with multiple frequency bands in time-division duplex (TDD) communication systems, in order to mitigate the effect of hardware fingerprint interference and synchronization offset. The scheme is evaluated to be robust to passive eavesdropping and active Man-in-the-Middle attack through both theoretical analyses and practical measurements. A secret key generation protocol is subsequently designed. The performance of the proposed secret key generation method is then evaluated through both numerical simulation and experiments. Results demonstrate that the proposed scheme can effectively mitigate non-reciprocity and outperforms the classical TDD scheme in both key disagreement rate and key generation rate. Linning Peng, Guyue Li, Junqing Zhang, Roger F. Woods, Ming Liu 0010, Aiqun Hu |
IEEE Trans. Mob. Comput. | 6 |
| 2018 | I Know What You Type: Leaking User Privacy via Novel Frequency-Based Side-Channel AttacksabstractSmartphone sensors have been applied to record the movement of users for healthy use. However, the motion sensor readings recorded by malicious applications can be utilized as a side-channel to leak user privacy by keystroke inference. Most existing approaches use time-domain statistical characteristics for keystroke inference. Their systems are poor to show the subtle changes in short time period, since the time- domain statistical features can only reflect the characteristics in a long-time interval. In this paper, we propose a novel framework to perform keystroke inference on smartphones. This framework introduces an improved MFCC algorithm to extract frequency- domain features for more comprehensive use of raw data. Since the frequency-domain energy distribution of motion signals is concentrated, and the specificity of signals is strong, MFCC can improve the inference accuracies under complex scenarios. Based on this framework, we present a prototype called FreqKey, which is an inference system to leak user privacy such as PINs and passwords. FreqKey collects motion sensor readings during keystroke events and constructs classification models with machine learning algorithms. Experimental results show that FreqKey improves the performance in a variety of complex scenarios. Especially, even in web platform whose sampling rate is lower than 80Hz, FreqKey can achieve relatively high accuracy of 74.6%. To mitigate the frequency-based side-channel attack and protect user privacy, we propose a defense solution which contains sensor- activity monitoring, malicious program identification and interference signal injection. Rui Song 0010, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 5 |
| 2018 | High-Agreement Uncorrelated Secret Key Generation Based on Principal Component Analysis PreprocessingabstractRandom and high-agreement secret key generation from noisy wideband channels is challenging due to the autocorrelation inside the channel samples and compromised cross correlation between channel measurements of two keying parties. This paper studies the signal preprocessing algorithms to establish high-agreement uncorrelated secret key in the presence of channel independent eavesdroppers. We first propose a general mathematical model for various preprocessing schemes, including principal component analysis (PCA), discrete cosine transform (DCT) and wavelet transform (WT). Among preprocessing schemes, PCA is proved to achieve the optimal secret key rate. Next, PCA with common eigenvector has been found to outperform PCA with private eigenvector in terms of an overall consideration of key agreement, information leakage, and computational expense. Then, we propose a system level design of key generation, including quantization, information reconciliation, and privacy amplification. Numerical results verify that the key generation enhanced by PCA with common eigenvector can achieve secret key with high key generation rate, low key error rate, and good randomness. Guyue Li, Aiqun Hu, Junqing Zhang, Linning Peng, Chen Sun 0004, Daming Cao |
IEEE Trans. Commun. | 2 |
| 2017 | Security Analysis of a Novel Artificial Randomness Approach for Fast Key GenerationabstractWireless key generation in slow fading channels is challenging because of the limited channel variation and randomness. This paper proposes a novel artificial randomness (AR) assisted approach for fast key generation in slow fading environments. It integrates user-designed randomness into the channel probing to form a fast-changing combined channel to realize information-theory security. The analytical expressions of secret key capacity are derived. We find that it is possible to improve secret key capacity by introducing AR when legitimate users have a better channel condition than that of eavesdropper. We also find that the improved secret key capacity is proportional to the channel probing number and is bounded by the noise variance and channel condition. Simulation and experimental results show that AR approach can generate secret key effectively in slow fading environments by carefully designing probing numbers. Compared to existing work in literature, the proposed approach does not rely on multiple antennas or extra helpers, and it can be applied in both single antenna and multi-antenna systems. Guyue Li, Aiqun Hu, Junqing Zhang, Bin Xiao 0001 |
GLOBECOM | 2 |
| 2017 | Novel attacks in OSPF networks to poison routing tableabstractLink State Advertisement (LSA) reflects the current status of all incident links of a router in an Autonomous System (AS). A fake LSA with false link status information will pollute the view of the network topology on routers. In this paper, we present two novel attacks that inject malicious Link State Advertisements (LSAs) to modify the routing tables: adjacency spoofing and single path injection. Adjacency spoofing attack makes attacker access to routing networks by disguising as a legitimate router. Single path injection attack evades the “fight-back” mechanism and affects routing advertisements of routers. Unlike existing LSA injection attacks, which need to be launched by malicious routers, a common host can launch these attacks and control the transmission path of data traffic in an AS. Simulation and real-world experiment results show that these two attacks can efficiently modify the routing tables of routers, and further lead to DNS spoofing, phishing Website, eavesdropping, and manin-the-middle attacks. Furthermore, we also implement a security vulnerability detection system to detect the existing vulnerabilities of routing protocol deployed in real-world routers. Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
ICC | 3 |
| 2017 | FloodDefender: Protecting data and control plane resources under SDN-aimed DoS attacksabstractThe separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Aiqun Hu, Kui Ren 0001 |
INFOCOM | 4 |
| 2017 | Throughput and BER of wireless powered DF relaying in Nakagami-m fading
Yan Gao 0007, Yunfei Chen 0001, Aiqun Hu |
Sci. China Inf. Sci. | 3 |
| 2017 | A subband excitation substitute based scheme for narrowband speech watermarkingabstractWe propose a new narrowband speech watermarking scheme by replacing part of the speech with a scaled and spectrally shaped hidden signal. Theoretically, it is proved that if a small amount of host speech is modified, then not only an ideal channel model for hidden communication can be established, but also high imperceptibility and good intelligibility can be achieved. Furthermore, a practical system implementation is proposed. At the embedder, the power normalization criterion is first imposed on a passband watermark signal by forcing its power level to be the same as the original passband excitation of the cover speech, and a synthesis filter is then used to spectrally shape the scaled watermark signal. At the extractor, a bandpass filter is first used to get rid of the out-of-band signal, and an analysis filter is then employed to compensate for the distortion introduced by the synthesis filter. Experimental results show that the data rate is as high as 400 bits/s with better bandwidth efficiency, and good imperceptibility is achieved. Moreover, this method is robust against various attacks existing in real applications. Aiqun Hu |
Frontiers Inf. Technol. Electron. Eng. | 2 |
| 2015 | A Novel Transform for Secret Key Generation in Time-Varying TDD Channel under Hardware Fingerprint DeviationabstractChannel reciprocity can be used for providing sufficient key generation in time division duplex (TDD) system. However, in practice, its application is limited by the hardware fingerprint deviation (HFD) problem. In this paper, we propose a novel real-time transform that can cope with this problem in time- varying TDD channel without any calibration period or feedback loops. More specifically, a log-domain differential (LDD) transform is developed and the resulting performance is analyzed in terms of mean square error (MSE) between receptions at Alice and Bob and effective signal to error ratio (ESER). The analysis shows that the proposed transform can eliminate the impact of HFD, yet its performance is very sensitive to channel noise and moving speed. For this purpose, an enhanced version is proposed including an efficient noise reduction technique and the impact of mobility on parameter design is also analyzed. Numerical results show that the proposed LDD advanced transform provides performance comparable to the ideal case without HFD, and thus, can be used to form a simple, practical and flexible solution for secret key generation in time-varying TDD channel. Guyue Li, Aiqun Hu, Yaning Zou, Linning Peng, Mikko Valkama |
VTC Fall | 2 |
| 2015 | Special issue on recent advances in network and information security - security and communication networks journalabstractSpecial issue on recent advances in network and information security - security and communication networks journal Xueqi Cheng 0001, Jinhong Yuan, Ali Tajer, Aiqun Hu, Wanlei Zhou 0001 |
Secur. Commun. Networks | 4 |
| 2015 | Efficient trust chain model based on turing machineabstractTrust chain, which focuses on the security in trusted computing platform, is the key technology to ensure system security. Aiming to establish the trust chain for mobile terminals, this paper proposes a trusted turing machine to formally describe the trust transitive process and construct an efficient trust chain model during the system boot time and the run time. The model consists of the following two characteristics. First, the boot code and operating system image are stored in Root of Trusted Storage. This structure provides more safety, reliability, and efficiency than that proposed by Trusted Computing Group. Second, a resource-oriented protecting scheme is designed during the system run time. A process can access specific resources on the condition that it has been granted trust property by the related verifying program. In addition, we also develop a prototype of trusted mobile terminal systems. Results show that the system boot time is shortened by 5.2s. In the meantime, the dynamic trusted mechanism executed during system run time can efficiently protect platform from malicious attack while it has little impact to system performance. The proposed model has the trust transitive property of the trust chain and can be applied to build a high efficiency trusted mobile terminal. Copyright © 2013 John Wiley & Sons, Ltd. Tao Li 0053, Aiqun Hu |
Secur. Commun. Networks | 2 |
| 2013 | Monte Carlo Based Test Pattern Generation for Hardware Trojan DetectionabstractHardware Trojan (HT) has emerged as a serious security threat to many critical systems. HT detection techniques are badly needed to ensure trust in hardware systems. In related works, only a fixed large number of random patterns are applied, with no regard to the pattern's effect to HT detection result. The variations in target signal caused by different sets of input vectors are not addressed. There is also no guarantee that the vector set used is long enough to be representative or whether it is already over testing. To solve these problems, we propose a Monte Carlo based test pattern generation method for HT detection. The proposed approach offers a solution by sampling the detection until the standard deviation of the measured signal over all the samples is within certain accuracy. This gives us the confidence in the signal measurement without having to do exhaustive test. Moreover, it is conducive to simplify test vector sets. Experiment results on ISCAS89 benchmarks showed that the proposed approach usually needs much less time than that required by exhaustive test to achieve reliable results and desired accuracy. Mingfu Xue, Aiqun Hu, Guyue Li |
DASC | 2 |
| 2013 | Trust relationships in secure mobile systemsabstractSecurity on mobile system has attracted so much attention. The traditional method of finding and killing viruses is not suitable for mobile handset due to its limited resources. This paper presented the notion of trust as an important component in a security infrastructure for mobile system and introduced the role of security service provider in the system. A trust model that can be used in tackling the aspect of protecting mobile handset from hostile software is proposed. We defined many trust relationships in our model, and presented a derivation algorithm that can be used to infer new trust relationships from existing ones. A framework of how such a model can be applied in a practical mobile system is provided. Aiqun Hu |
WCNC | 2 |
| 2011 | Two-piecewise companding transform for PAPR reduction of OFDM signalsabstractTo reduce the peak-to-average power ratio (PAPR) of orthogonal frequency division multiplexing (OFDM) signals, a two-piecewise companding (TPWC) transform is proposed so as to compress large signal amplitudes and expand small ones with two different linear functions. The TPWC transform can provide significant PAPR reduction with low computational complexity, which is similar to other existing linear transforms. Besides, a good trade-off between PAPR reduction and bit-error-rate (BER) performances can be achieved by carefully choosing the three parameters in the proposed scheme. A good power spectral density (PSD) performance can also be achieved, since there are no inflexion points in the resulting profile. The idea of the two-piecewise transform can be extended to other nonlinear functions. Pinlu Yang, Aiqun Hu |
IWCMC | 2 |
| 2008 | Maximum Utility-Based Resource Allocation Algorithm in the IEEE 802.16 OFDMA SystemabstractAlthough the medium access control (MAC) protocol and the physical layer have been well-defined in the IEEE 802.16 specifications, resource allocation and management schemes, which are crucial components to guarantee quality of service (QoS) performances, still remain as open issues. In this paper, we focus on the problem of the utility-based resource allocation in the IEEE 802.16 OFDMA systems. The utility is used in our study to balance the efficiency and fairness of resource allocation. We formulate the optimization problem as one that maximizes the system utility of all active users subject to certain conditions, which are determined by adaptive resource allocation schemes. To maximize the system utility, a near optimal multiuser resource allocation algorithm with low complexity is proposed. Numerical results show that the proposed algorithm can achieve a system performance very close to the optimal solution obtained by the exhaustive method with a low computational complexity and offer a more preferable tradeoff via the predesigned fairness factor between the spectral efficiency and the fairness than existing approaches. Juncai Shi, Aiqun Hu |
ICC | 2 |
| 2007 | Reducing the Message Overhead of AODV by Using Link Availability Prediction
Aiqun Hu |
MSN | 2 |
| 2006 | Advanced remote password authentication and key agreement using smart card
Aiqun Hu |
CAINE | 2 |
| 1998 | Solving a kind of nonlinear programming problems via analog neural networks
Aiqun Hu, Zhenya He |
Neurocomputing | 2 |