EDBT 2026 Demo / reviewers in the wild / expert
Pei Huang 0005
dblp:59/1856-5
· DBLP profile ↗
13ranked-venue papers
5as first author
5since 2021 · last 2023
0000-0001-8012-7105ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 4 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Signal Emulation Attack and Defense for Smart Home IoTabstractInternet of Things (IoT) is transforming every corner of our daily life and plays important roles in the smart home. Depending on different requirements on wireless transmission, dedicated wireless protocols have been adopted on various types of IoT devices. Recent advances in Cross-Technology Communication (CTC) enable direct communication across those wireless protocols, which will greatly improve the spectrum utilization efficiency. However, it incurs serious security concerns on heterogeneous IoT devices. In this paper, we identify a new physical-layer attack, cross-technology signal emulation attack, where a WiFi device eavesdrops a ZigBee packet on the fly, and further manipulates the ZigBee device by emulating a ZigBee signal. To defend against this attack, we propose two defense strategies with the help of a commonly found WiFi router. Particularly, the passive defense strategy focuses on misleading the ZigBee signal eavesdropping, while the proactive approach develops a real-time detection mechanism on distinguishing between a common ZigBee signal and an emulated signal. We implement the complete attacking process and defense strategies with TI CC26x2R LaunchPad, USRP-N210 platform, and a self-designed prototype. Extensive experiments have demonstrated the existence of the attack, and the feasibility, effectiveness, and accuracy of the proposed defense strategies. Xiaonan Zhang 0001, Sihan Yu, Hansong Zhou, Pei Huang 0005, Linke Guo, Ming Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Physical-Level Parallel Inclusive Communication for Heterogeneous IoT DevicesabstractThe proliferation of Internet of Things (IoT) has transformed the way people interact with the world. Various kinds of wireless protocols have been developed to support diverse types of IoT communications. Unfortunately, the lack of spectrum resources puts a hard limit on managing the large-scale heterogeneous IoT system. Although previous works alleviate this strain by coordinating transmission power, time slots, and sub-channels, they may not be feasible in future IoT applications with dense deployments. In this paper, we explore a physical-level parallel inclusive communication paradigm for the coexistence of Wi-Fi and ZigBee, which leverages novel bits embedding approaches on the OQPSK protocol to enable both Wi-Fi and ZigBee IoT devices to decode the same inclusive signals at the same time but with each one’s different data. By carefully crafting the inclusive signals using legacy Wi-Fi protocol, the overlapping spectrum can be simultaneously re-used by both protocols, expecting a maximum data rate (250kbps) for ZigBee devices and up to 3.75Mbps for a Wi-Fi pair over only a 2MHz bandwidth. The achieved spectrum efficiency outperforms a majority of CTC schemes and parallel communication designs. Compared with existing works on parallel communication, our proposed system is the first one that achieves an entire software-level design, which can be readily implemented on Commercial Off-The-Shelf (COTS) devices without any hardware modification. Based on extensive real-world experiments on both USRP and COTS device platforms, we demonstrate the feasibility, generality, and efficiency of the proposed new paradigm. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo |
INFOCOM | 3 |
| 2022 | Wearable-User Authentication via Cross-Technology Interference in Heterogeneous EnvironmentsabstractThe increasing deployment of wireless sensors enables a broad spectrum of health-related wearable applications. Due to the sensitivity of collected personal health information, these wearables should be authenticated together with their users as “wearable-user pairs” to ensure that they are attached to legitimate users. However, various devices are equipped with dedicated sensing abilities and wireless protocols corresponding to data characteristics in practice. Traditional authentication methodologies may not work in this heterogeneous environment because of protocol incompatibility. For example, how to verify a new ZigBee-enabled monitor when the existing trusted device is Wi-Fi-enabled? Therefore, to achieve authentication across protocols, in this article, we leverage the unique cross-technology interference (CTI), triggered by heterogeneous wireless transmissions, along with human physiological activity measurements (e.g., respiration patterns) to design an authentication scheme between wearables and users. Specifically, the authentication from an unknown ZigBee wearable to a trusted Wi-Fi device is achieved by monitoring the channel state information (CSI) changes according to human respiration. Our approach not only successfully recognizes a legitimate wearable-user pair but also blocks illegal access from adversaries. Extensive experiments have been conducted to demonstrate both the security and feasibility of the proposed scheme. The designed mechanism can achieve over 92% authentication accuracy with human subjects. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo, Ming Li 0006 |
IEEE Internet Things J. | 1 |
| 2022 | IS-WARS: Intelligent and Stealthy Adversarial Attack to Wi-Fi-Based Human Activity Recognition SystemsabstractThe non-intrusive human activity recognition has been envisioned as a key enabler for many emerging applications requiring interactions between humans and computing systems. To accurately recognize different human behaviors, ubiquitous wireless signals are widely adopted, e.g., Wi-Fi signals, whose Channel State Information (CSI) can precisely reflect human movements. Unfortunately, nearly all Wi-Fi-based recognition systems assume a clean wireless environment, i.e., no interference will compromise the developed algorithms, which, apparently, is not feasible in practice. Even worse, for systems using Wi-Fi 2.4GHz signals, the widely existing interference from coexisting protocols, such as ZigBee, Bluetooth, and LTE-Unlicensed, can easily compromise the recognition process, posing a hard limit on further enhancing the accuracy. Therefore, this work uncovers a new signal adversarial attack against Wi-Fi-based human activity recognition systems, by intentionally injecting interference using coexisting protocol signals. The contaminated Wi-Fi signal will distort CSI estimation and finally output a false recognition result. Different from traditional jamming attacks, this new adversarial attack is intelligent and stealthy in terms of avoiding being detected from traffic analysis. Along with both theoretical analysis and extensive real-world experiments, we have shown this newly-identified attack can easily compromise many existing Wi-Fi-based human recognition systems while still bypassing existing schemes for malicious signal detection. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Incentivizing Crowdsensing-Based Noise Monitoring with Differentially-Private LocationsabstractMobile crowd sensing is a technique where a crowd sensing server outsources sensing tasks to the crowd for mobile data collection. In mobile crowd sensing, some tasks require location information to achieve their objectives, such as road monitoring, indoor floor plan reconstruction, and smart transportation. This required information incurs severe concerns on location privacy leakage and threatens workers' properties as well as public safety. In some cases, even sensing data itself can be used as auxiliary information resulting in location privacy breaches. Many existing works apply differential privacy mechanisms for location privacy preservation to tackle this problem, but they cannot efficiently fulfill privacy goals because each worker only considers his own privacy. As a consequence, the accumulated privacy budget will lower down the composed privacy level of all the workers' locations. In addition, deploying differential privacy is costly for workers and it will degrade the quality of data required in crowd sensing tasks. How to balance the cost and provide accurate aggregated data while fulfilling privacy objectives becomes a challenging issue. In this paper, we propose a group-differentially-private game-theoretical solution, which addresses these limitations in a privacy-preserving and efficient way. Our scheme enables the indistinguishability of workers' locations and sensing data without the help of a trusted entity while meeting the accuracy demands of crowd sensing tasks. The effectiveness and efficiency of our scheme are thoroughly evaluated based on real-world datasets. Pei Huang 0005, Xiaonan Zhang 0001, Linke Guo, Ming Li 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | AuthCTC: Defending Against Waveform Emulation Attack in Heterogeneous IoT EnvironmentsabstractWidely deployed IoT devices have raised serious concerns for the spectrum shortage and the cost of multi-protocol gateway deployment. Recent emerging Cross-Technology Communication (CTC) technique can alleviate this issue by enabling direct communication among heterogeneous wireless devices, such as WiFi, Bluetooth, and ZigBee on 2.4 GHz. However, this new paradigm also brings security risks, where an attacker can use CTC to launch wireless attacks against IoT devices. Due to limited computational capability and different wireless protocols being used, many IoT devices are unable to use computationally-intensive cryptographic approaches for security enhancement. Therefore, without proper detection methods, IoT devices cannot distinguish signal sources before executing command signals. In this paper, we first demonstrate a new defined physical layer attack in the CTC scenario, named as waveform emulation attack, where a WiFi device can overhear and emulate the ZigBee waveform to attack ZigBee IoT devices. Then, to defend against this new attack, we propose a physical layer defensive mechanism, named as AuthCTC, to verify the legitimacy of CTC signals. Specifically, at the sender side, an authorization code is embedded into the packet preamble by leveraging the dynamically changed cyclic prefix. A WiFi-based detector is used to verify the authorization code at the receiver side. Extensive simulations and experiments using off-the-shelf devices are conducted to demonstrate both the feasibility of the attack and the effectiveness of our defensive mechanism. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Long Cheng 0005, Kuang-Ching Wang |
AsiaCCS | 3 |
| 2019 | Hide and Seek: Waveform Emulation Attack and Defense in Cross-Technology CommunicationabstractThe exponentially increasing number of heterogeneous Internet of Things (IoT) devices result in severe spectrum shortage and interference in the already crowded ISM band. Cross-Technology Communication (CTC) is dedicated to achieving direct communication among wireless devices with different radios and modulation schemes, which serves as an effective approach to address the above challenges. Nevertheless, CTC also provides opportunities for adversaries to manipulate IoT devices. In this paper, we identify a new attack. Built on CTC, WiFi devices are able to hide the pre-intercepted ZigBee message into their transmitted waveforms, achieving the objective of directly controlling ZigBee devices. To defend against the attack, we analyze possible strategies and consider constellation higher-order statistic analysis as the countermeasure. Extensive simulations and experiments with commodity devices (CC26x2R1) and USRP-based prototypes show the existence of the newly identified attack, and further, validate the effectiveness of the proposed defensive approach. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Yuguang Fang |
ICDCS | 2 |
| 2019 | Incentivizing Relay Participation for Securing IoT CommunicationabstractInternet of Things (IoT) has emerged as a new computing paradigm that promises to offer a fully connected “smart” world. However, due to the open nature of wireless medium, the information sensed, collected, and transmitted by IoT devices can be easily intercepted by adversaries, which becomes a serious concern in most IoT applications requiring sensitive data. In practice, cooperative communication approaches can effectively improve the security level for wireless communication under the presence of eavesdroppers with unbounded computational ability. In this paper, we apply the amplify-and-forward (AF) cooperative communication to increase the secrecy capacity of IoT systems by incentivizing relay IoT devices. Specifically, a Stackelberg game is designed to motivate the participation of the relay IoT devices for security enhancement. Extensive experimental results have demonstrated the feasibility and security of the proposed mechanism under both unknown and known channel state information (CSI) models. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Mo Sha 0001 |
INFOCOM | 2 |
| 2019 | Practical Privacy-Preserving ECG-Based Authentication for IoT-Based HealthcareabstractIn current healthcare systems, patients use various types of medical Internet of Things devices for monitoring their health conditions. The collected information (personal health records) will be sent back to hospitals for diagnosis and quick responses. However, severe security and privacy leakages with regard to data privacy and identity authentication are incurred because the monitored health data contains sensitive information. Therefore, the data should be well protected from unauthorized entities. Unfortunately, traditional cryptographic approaches or password-based mechanisms cannot fulfill the privacy and security demands in health monitoring due to their low efficiency and knowledge-based property. Biometric authentication overcomes these deficiencies and successfully verifies the inherent characteristics of humans. Among all biometrics, the electrocardiogram (ECG) signal is the most suitable one due to its medical properties. However, the security and privacy objectives of ECG-based authentication usually fail in practice due to the noise interferences in the collected ECG data and the privacy breach of the ECG database. In this paper, we propose a practical scheme that can reliably authenticate patients with noisy ECG signals and provide differentially private protection simultaneously. The effectiveness and efficiency of our scheme are thoroughly analyzed and evaluated over online datasets. We also conduct a pilot study on human subjects experiencing different exercise levels to validate our scheme. Pei Huang 0005, Linke Guo, Ming Li 0006, Yuguang Fang |
IEEE Internet Things J. | 1 |
| 2019 | Social-Aware Energy-Efficient Data Offloading With Strong StabilityabstractThe exploding popularity of mobile devices enables people to enjoy the benefits brought by various interesting mobile apps. The ever-increasing data traffic has exacerbated energy consumption on both cellular service providers and mobile users. It has become an urgent need to reducing the energy consumption in the cellular network while satisfying users' increasing traffic demands. Mobile data offloading is an effective energy-saving paradigm to tackle the above-mentioned problem. However, the current approaches cannot fully address the issue in terms of user demands and offloaded traffic. With the observation that duplicated data transmission often happens in the crowd with similar social interests, we deploy device-to-device (D2D) data offloading to achieve the energy efficiency at the user side while adapting their increasing traffic demands. Specifically, we investigate the stochastic optimization of the long-term time-averaged expected energy consumption while guaranteeing the strong stability of the network by utilizing the social-aware and energy-efficient D2D mobile offloading. By jointly considering interference among D2D users, social-aware caching, link scheduling, and routing, an offline finite-queue-aware energy minimization problem is formulated, which is a time-coupling stochastic mixed-integer non-linear programming (MINLP) problem. We propose an online finite-queue-aware energy algorithm by employing the Lyapunov drift-plus-penalty theory. Extensive analysis and simulations are conducted to validate the proposed scheme. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Yuguang Fang |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | CREAM: Unauthorized Secondary User Detection in Fading EnvironmentsabstractDynamic Spectrum Access (DSA) has emerged as a major technology in the future wireless system to alleviate the worldwide spectrum scarcity issue. Authorized secondary users can take advantages of underutilized spectrum for communication. However, due to the open nature of the wireless medium, the DSA system suffers spectrum misuse by unauthorized secondary users, and thus fewer users would participate in DSA. Although many existing works have implemented misuse detection schemes into DSA, practical concerns, such as channel fading issues, are not well addressed. Therefore, how to ensure the reliable communication among authorized secondary users in a practical channel model becomes a challenging issue. In this paper, we propose CREAM, a physical-layer based misuse detection scheme specifically in the fading environment, which conceals the unforgeable spectrum permit into the message by superposition modulation for verification. Given the pre-shared secret information, the third-party verifier can perform efficient detection on unauthorized spectrum access. Detailed analysis and simulation results demonstrate the security, accuracy, efficiency, and low intrusion to message transmission in fading environments. Xiaonan Zhang 0001, Pei Huang 0005, Qi Jia 0002, Linke Guo |
MASS | 2 |
| 2017 | Securing a UAV using individual characteristics from an EEG signalabstractUnmanned aerial vehicles (UAVs) have been applied for both civilian and military applications; scientific research involving UAVs has encompassed a wide range of scientific study. However, communication with unmanned vehicles are subject to attack and compromise. Such attacks have been reported as early as 2009, when a Predator UAV's video stream was compromised. Since UAVs extensively utilize autonomous behavior, it is important to develop an autopilot system that is robust to potential cyber-attack. In this work, we present a biometric system to encrypt communication between a UAV and a computerized base station. This is accomplished by generating a key derived from the Beta component of a user's EEG. When communication with a UAV is attacked, a safety mechanism directs the UAV to a safe ‘home’ location. This system has been validated on a commercial UAV under malicious attack conditions. Ashutosh Singandhupe, Hung Manh La, David Feil-Seifer, Pei Huang 0005, Linke Guo, Ming Li 0006 |
SMC | 4 |
| 2016 | A Robust and Reusable ECG-Based Authentication and Data Encryption Scheme for eHealth SystemsabstracteHealth systems generate from the integration of information and communication technologies with traditional healthcare systems. They have widely replaced paper-based systems due to their prominent features of convenience and accuracy. However, eHealth systems also face many challenges, such as the privacy and security concerns over patients' identities and their personal health records (PHRs). Traditional cryptographic approaches are only capable of verifying ``what you possess" or ``what you remember" with the help of trust authorities. As a result, they are not suitable for medical applications and cannot handle above concerns effectively. Using biometrics can verify ``who you are" due to permanence, distinctiveness, and undeniability properties of biometrics. It outstands conventional authentication and encryption approaches in eHealth systems. A promising one among all is the ECG (ElectroCardioGram) signal, which is easier to implement than other biometrics. Unfortunately, most of existing works do not take the nonuniformity of ECG signals into consideration. Besides, they do not protect ECG signals well despite their sensitivity. Hence, we propose a robust and reusable authentication and encryption scheme based on ECG signals for eHealth systems. Our scheme can authenticate patients' identities and protect their PHRs, enable the reuse of the same ECG signal, and preserve the privacy of ECG signals. Theoretical and empirical evaluations demonstrate the security, effectiveness, and efficiency of the proposed scheme. Pei Huang 0005, Borui Li 0002, Linke Guo, Zhanpeng Jin, Yu Chen 0002 |
GLOBECOM | 1 |