EDBT 2026 Demo / reviewers in the wild / expert
Chenglong Fu 0002
dblp:58/2521-2
· DBLP profile ↗
18ranked-venue papers
4as first author
14since 2021 · last 2025
0000-0001-6555-9858ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 9 since 2021Computer networks · 5 · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Discovering and Exploiting IoT Device Hidden Attributes: A New Vulnerability in Smart Homes
Xuening Xu, Chenglong Fu 0002, Xiaojiang Du, Bo Luo |
CCS | 2 |
| 2025 | Few-Shot Learning-Based Cyber Incident Detection with Augmented Context IntelligenceabstractIn recent years, the adoption of cloud services has been expanding at an unprecedented rate. As more and more organizations migrate or deploy their businesses to the cloud, a multitude of related cybersecurity incidents such as data breaches are on the rise. Many inherent attributes of cloud environments, for example, data sharing, remote access, dynamicity and scalability, pose significant challenges for the protection of cloud security. Even worse, cyber threats are becoming increasingly sophisticated and covert. Attack methods, such as Advanced Persistent Threats (APTs), are continually developed to bypass traditional security measures. Among the emerging technologies for robust threat detection, system provenance analysis is being considered as a promising mechanism, thus attracting widespread attention in the field of incident response. This paper proposes a new few-shot learning-based attack detection with improved data context intelligence. We collect operating system behavior data of cloud systems during realistic attacks and leverage an innovative semiotics extraction method to describe system events. Inspired by the advances in semantic analysis, which is a fruitful area focused on understanding natural languages in computational linguistics, we further convert the anomaly detection problem into a similarity comparison problem. Comprehensive experiments show that the proposed approach is able to generalize over unseen attacks and make accurate predictions, even if the incident detection models are trained with very limited samples. Fei Zuo, Junghwan Rhee, Yung Ryn Choe, Chenglong Fu 0002, Xianshan Qu |
COMPSAC | 4 |
| 2024 | Poster: TAPChecker: Model Checking in Trigger-Action Rules Generation Using Large Language ModelsabstractThe integration of large language models (LLMs) in smart home systems holds significant promise for automating the generation of Trigger-Action Programming (TAP) rules, potentially streamlining smart home user experiences and enhancing convenience. However, LLMs lack of holistic view of smart home IoT deployments and may introduce TAP rules that result in hazards. This paper explores the application of LLM for generating TAP rules and applying formal verification to validate and ensure the safety of TAP rules generated by LLMs. By systematically analyzing and verifying these rules, we aim to identify and mitigate potential security vulnerabilities. Furthermore, we propose a feedback mechanism to refine the LLM's output, enhancing its reliability and safety in generating automation rules. Through this approach, we seek to bridge the gap between the efficiency of LLMs and the stringent security requirements of smart IoT systems, fostering a safer automation environment. Huan Bui, Harper Lienerth, Chenglong Fu 0002, Meera Sridhar |
CCS | 3 |
| 2024 | Audio-Assisted Smart Home Security Monitoring with Few SamplesabstractSmart home IoT devices have always been the target of various cyber attacks. By leveraging the smart home monitoring infrastructure, event-based anomaly detection is effective to detect anomalies that cause unfavorable working state of IoT devices. However, IoT events are proven to be vulnerable to event-targeted attacks which could be achieved by exploiting the vulnerabilities embedded in IoT devices, protocols and/or platforms. Thus, existing event-based anomaly detection is not robust in the case of unreliable input. To address this issue, our insight is that the embedded microphone components in many off-the-shelf home devices (e.g., smart doorbells, speakers, cameras, tablets, laptops, etc.) could be utilized to gather acoustic information to help increase the reliability and capability of smart home security monitoring systems. To verify this idea, we propose an audio-assisted framework IoTAudMon for detecting event-targeted attacks. Considering the heterogeneity and sparsity nature of smart homes IoT devices and events, we employ transfer learning to design a practical pipeline for extracting semantic information from audio, eliminating the requirement of human labeling and mitigating the cold start issue in existing solutions. Experiments on public datasets and real devices demonstrate the effectiveness of IoTAudMon. Haotian Chi, Chenglong Fu 0002, Haijun Geng, Xiaojiang Du |
GLOBECOM | 4 |
| 2024 | TrustEvent: Cross-Platform IoT Trigger Event Verification Using Edge ComputingabstractAs smart home IoT systems gain popularity, they inevitably become targets for security risks and concerns. Among various cyber-attacks targeting these systems, the fake event attack poses significant issues due to its ability to manipulate secure devices through automation rules. In response to this threat, we propose TrustEvent - a system designed to offer end-to-end event signature verification. By integrating TrustEvent with existing home automation platforms, event authenticity is verified against signatures generated from edge devices before these events trigger automation rule execution. Notably, we have developed a signature proxy module, enhancing our system's compatibility across various platform scenarios. We have implemented a TrustEvent prototype in conjunction with existing commercial smart home IoT platforms, evaluating its overhead in the process. Our experimentation demonstrates that our system only marginally increases the automation execution latency, by an average of 3.74 seconds, representing a acceptable compromise for enhanced security. Trent Reichenbach, Chenglong Fu 0002, Xiaojiang Du, Jia Di, Yuede Ji |
ICC | 2 |
| 2024 | Seeing Is Believing: Extracting Semantic Information from Video for Verifying IoT EventsabstractAlong with the increasing popularity of smart home IoT devices, more users are turning to smart home automation platforms to control and automate their IoT devices. However, IoT automation is vulnerable to spoofed event attacks. Given that IoT devices are intricately linked with the physical environment and operate autonomously, event-based attacks can pose serious safety and security challenges. Our observations show that many IoT events are accompanied by visual modifications in objects such as shape alterations (for example, contact sensor events correspond with door movement) or changes in color/brightness (for example, a functioning microwave oven with the internal light switched on). These alterations can be detected by the commonly deployed smart cameras, providing a visually rich but challenging to manipulate channel for verifying IoT events. We introduce IoTSentry, the first system of its kind to extract high-level semantic information from streaming video data and pixels for IoT event verification. We have designed a Siamese deep neural network to identify variations in the appearance of IoT devices and interior objects. These are used as the yardstick for verifying IoT events received at IoT automation platforms. Upon assessing IoTSentry with 21 IoT devices (8 types), the results demonstrate that IoTSentry can be trained within 120 seconds, yielding an accuracy rate of over 96.7% in recognizing device states. We have deployed the 21 IoT devices and IoTSentry on two real-world smart home test sites. Over the course of our one-week evaluation, IoTSentry consistently achieved an average detection rate of 99.24% in identifying attack instances. Moreover, it triggered no more than 2 false alarms per day on each test site. Chenglong Fu 0002, Xiaojiang Du, Qiang Zeng 0001, Fei Zuo, Jia Di |
WISEC | 1 |
| 2023 | VoiceGuard: An Effective and Practical Approach for Detecting and Blocking Unauthorized Voice Commands to Smart SpeakersabstractSmart speakers bring convenience to people's daily lives. However, various attacks can be launched against smart speakers to execute malicious commands, which may cause serious safety or security issues. The existing solutions against sophisticated attacks such as voice replay attacks and voice synthesis attacks require intrusive modifications of the smart speaker hardware and/or software, which are impractical for general users. In this work, we present a novel security scheme- VoiceGuard that can effectively detect and block unauthorized voice commands to smart speakers. VoiceGuard does not require any modification to smart speakers' hardware or software. We implement a prototype of VoiceGuard on two popular smart speakers: Amazon Echo Dot and Google Home Mini, and evaluate the scheme in three real-world testbeds, which include both single-user and multi-user scenarios. The experimental results show that VoiceGuard achieves an accuracy of 97% in blocking malicious voice commands issued by illegitimate sources while having a negligible impact on the user experience. Xuening Xu, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi |
DSN | 2 |
| 2023 | Discovering Complex Correlations Among Multiple IoT Devices in Smart EnvironmentsabstractThe ubiquity of the Internet of Things (IoT) in a vast range of consumer applications is unparalleled. Unfortunately, despite the benefits of IoT, its widespread integration comes with significant security challenges. Considering IoT devices' capability to interact with the physical environment, there is an urgent need for effective anomaly detection. The state-of-the-art anomaly detection method, HAWatcher, models the normal behaviors of smart homes with inter-device correlations and demonstrates great results. Nonetheless, it is limited to capturing only simple one-to-one correlations between two events or states, which undermines its capability to detect anomalies in more complicated environments. To address this issue, we present a novel correlation discovering method to mine complex two-to-one correlations in such complicated IoT-enabled environments. We conduct experiments over two weeks on four smart home testbeds and obtain 70 two-to-one correlations. The correlations are applied to 9 anomaly scenarios, which show significant improvements in detecting anomalies over one-to-one correlations. Andrew D'Angelo, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi |
GLOBECOM | 2 |
| 2023 | MP-Mediator: Detecting and Handling the New Stealthy Delay Attacks on IoT Events and CommandsabstractIn recent years, intelligent and automated device control features have led to a significant increase in the adoption of smart home IoT systems. Each IoT device sends its events to (and receives commands from) the corresponding IoT server/platform, which executes automation rules set by the user. Recent studies have shown that IoT messages, including events and commands, are subject to stealthy delays ranging from several seconds to minutes, or even hours, without raising any alerts. Exploiting this vulnerability, adversaries can intentionally delay crucial events (e.g., fire alarms) or commands (e.g., locking a door), as well as alter the order of IoT messages that dictate automation rule execution. This manipulation can deceive IoT servers, leading to incorrect command issuance and jeopardizing smart home safety. In this paper, we present MP-Mediator, which is the first defense system that can detect and handle the new, stealthy, and widely applicable delay attacks on IoT messages. For IoT devices lacking accessible APIs, we propose innovative methods leveraging virtual devices and virtual rules as a bridge for indirect integration with MP-Mediator. Furthermore, a VPN-based component is proposed to handle command delay attacks on critical links. We implement and evaluate MP-Mediator in a real-world smart home testbed with twenty-two popular IoT devices and two major IoT automation platforms (IFTTT and Samsung SmartThings). The experimental results show that MP-Mediator can quickly and accurately detect the delay attacks on both IoT events and commands with a precision of more than 96% and a recall of 100%, as well as effectively handle the delay attacks. Xuening Xu, Chenglong Fu 0002, Xiaojiang Du |
RAID | 2 |
| 2022 | IoT Phantom-Delay Attacks: Demystifying and Exploiting IoT Timeout BehaviorsabstractThis paper unveils a set of new attacks against Internet of Things (IoT) automation systems. We first propose two novel IoT attack primitives: Event Message Delay and Command Message Delay (event messages are generated by IoT devices to report device states, and command messages are used to control IoT devices). Our insight is that timeout detection in the TCP layer is decoupled from data protection in the Transport Layer Security (TLS) layer. As a result, even when a session is protected by TLS, its IoT event and/or command messages can still be significantly delayed without triggering alerts. It is worth highlighting that, by compromising/controlling one WiFi device in a smart environment, the attacker can delay the IoT messages of other non-compromised IoT devices; we thus call the attacks IoT Phantom-Delay Attacks. Our study shows the attack primitives can be used to build rich attacks and some of them can induce persistent effects. The presented attacks are very different from jamming. 1) Unlike jamming, our attacks do not discard any packets and thus do not trigger re-transmission. 2) Our attacks do not cause disconnection or timeout alerts. 3) Unlike reactive jamming, which usually relies on special hardware, our attacks can be launched from an ordinary WiFi device. Our evaluation involves 50 popular IoT devices and demonstrates that they are all vulnerable to the phantom-delay attacks. Finally, we discuss the countermeasures. We have contacted multiple IoT platforms regarding the vulnerable IoT timeout behaviors, and Google, Ring and SimpliSafe have acknowledged the problem. Chenglong Fu 0002, Qiang Zeng 0001, Haotian Chi, Xiaojiang Du, Siva Likitha Valluru |
DSN | 1 |
| 2022 | Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference AttacksabstractWith the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues. Haotian Chi, Chenglong Fu 0002, Qiang Zeng 0001, Xiaojiang Du |
SP | 2 |
| 2021 | Decision-Tree Based Root Cause Localization for Anomalies in Smart IoT SystemsabstractWith the rapid growth of Internet of Things (IoTs), Internet-connected devices and home appliances gain popularity on the consumer electronic market. New home IoT products with built-in network connections and intelligent functionalities are quickly rolled out to the market. As predicted by Gartner, there will be more than 500 IoT devices deployed in a typical household by 2022. The easy device integration and advanced automation logic also brings new challenges with regard to security and privacy. IoT devices have been reported as unreliable because of the constraints in costs and resources. Anomalies of IoT devices include malfunctions of the physical part or the cyber part of an IoT device, as well as abnormal behaviors due to malicious attacks. Abnormal IoT devices could cause severe consequences, because they reside in the home environment and have critical functions that can change the physical world, such as door (smart lock) opening, smart oven burning (which could cause fire), or smart water valve opening (which could cause flooding). In this paper, we study the important issue of localizing the root cause of anomalies in a smart environment (e.g., smart homes and smart offices). We propose to use decision trees for efficient and effective anomaly root cause localization. We construct decision trees from automation rules that control the operations of smart IoT devices in a smart environment. Our performance evaluation on data collected from real smart homes demonstrate the effectiveness of our proposed approach. Chenglong Fu 0002, Xiaojiang Du |
ICC | 2 |
| 2021 | SniffMislead: Non-Intrusive Privacy Protection against Wireless Packet Sniffers in Smart HomesabstractWith the booming deployment of smart homes, concerns about user privacy keep growing. Recent research has shown that encrypted wireless traffic of IoT devices can be exploited by packet-sniffing attacks to reveal users’ privacy-sensitive information (e.g., the time when residents leave their home and go to work), which may be used to launch further attacks (e.g., a break-in). To address the growing concerns, we propose SniffMislead, a non-intrusive (i.e., without modifying IoT devices, hubs, or platforms) privacy-protecting approach, based on packet injection, against wireless packet sniffers. Instead of randomly injecting packets, which is ineffective against a smarter attacker, SniffMislead proposes the notion of phantom users, “people” who do not exist in the physical world. From an attacker’s perspective, however, they are perceived as real users. SniffMislead places multiple phantom users in a smart home, which can effectively prevent an attacker from inferring useful information. We design a top-down approach to synthesize phantom users’ behaviors, construct the sequence of decoy device events and commands, and then inject corresponding packets into the home. We show how SniffMislead ensures logical integrity and contextual consistency of injected packets, as well as how it makes a phantom user indistinguishable from a real user. Our evaluation results from a smart home testbed demonstrate that SniffMislead significantly reduces an attacker’s privacy-inferring capabilities, bringing the accuracy from 94.8% down to 3.5%. Qiang Zeng 0001, Xiaojiang Du, Siva Likitha Valluru, Chenglong Fu 0002, Xiao Fu 0005, Bin Luo 0003 |
RAID | 5 |
| 2021 | HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart Homes
Chenglong Fu 0002, Qiang Zeng 0001, Xiaojiang Du |
USENIX Security Symposium | 1 |
| 2020 | Multi-layer security scheme for implantable medical devices
Heena Rathore, Chenglong Fu 0002, Amr Mohamed 0001, Abdulla K. Al-Ali, Xiaojiang Du, Mohsen Guizani, Zhengtao Yu 0001 |
Neural Comput. Appl. | 2 |
| 2019 | A Multiversion Programming Inspired Approach to Detecting Audio Adversarial ExamplesabstractAdversarial examples (AEs) are crafted by adding human-imperceptible perturbations to inputs such that a machine-learning based classifier incorrectly labels them. They have become a severe threat to the trustworthiness of machine learning. While AEs in the image domain have been well studied, audio AEs are less investigated. Recently, multiple techniques are proposed to generate audio AEs, which makes countermeasures against them urgent. Our experiments show that, given an audio AE, the transcription results by Automatic Speech Recognition (ASR) systems differ significantly (that is, poor transferability), as different ASR systems use different architectures, parameters, and training datasets. Based on this fact and inspired by Multiversion Programming, we propose a novel audio AE detection approach MVP-Ears, which utilizes the diverse off-the-shelf ASRs to determine whether an audio is an AE. We build the largest audio AE dataset to our knowledge, and the evaluation shows that the detection accuracy reaches 99.88%. While transferable audio AEs are difficult to generate at this moment, they may become a reality in future. We further adapt the idea above to proactively train the detection system for coping with transferable audio AEs. Thus, the proactive detection system is one giant step ahead of attackers working on transferable AEs. Qiang Zeng 0001, Jianhai Su, Chenglong Fu 0002, Golam Kayas, Lannan Luo, Xiaojiang Du, Chiu C. Tan 0001, Jie Wu 0001 |
DSN | 3 |
| 2019 | Effective UAV and Ground Sensor AuthenticationabstractNowadays, The Internet of Things (IoT) has been widely used in various fields due to its smart sensing and communication capabilities. IoT devices serve as bridges for the cyber system to interact with the physical environment by providing various useful sensing capabilities such as battlefield surveillance, home monitoring, traffic control, etc. These capabilities also make IoT an important role in tactical missions in the military, including Reconnaissance, Intelligence, Surveillance, and Target Acquisition (RISTA). Nevertheless, IoT devices are known to have critical issues on security due to constraints on cost and resources. Most existing researches are based on smart sensors that have comparatively more computing and communication resources, while security solutions for dumb sensors are still lacking. Some IoT sensors that are deployed in a hostile environment are dumb due to limitations on cost and power supply, making them more vulnerable to attacks. In this work, we try to tackle this problem by proposing effective authentication solutions between a UAV and dumb IoT devices (also referred to as dumb sensors) within an example application of a UAV-sensor collaborative RISTA mission. We present two different schemes for two-way mutual authentication between the UAV and dumb sensors which utilize non-cryptographic physical layer cover channel and neighboring devices' signal sensing correlations respectively. We demonstrate the feasibility and effectiveness of our schemes with extensive real-world experiments on our prototype deployment. Xuening Xu, Chenglong Fu 0002, Xiaojiang Du, E. Paul Ratazzi |
GLOBECOM | 2 |
| 2019 | POKs Based Secure and Energy-Efficient Access Control for Implantable Medical Devices
Chenglong Fu 0002, Xiaojiang Du, Longfei Wu, Qiang Zeng 0001, Amr Mohamed 0001, Mohsen Guizani |
SecureComm (1) | 1 |