EDBT 2026 Demo / reviewers in the wild / expert
Yushi Cheng
dblp:63/4074
· DBLP profile ↗
39ranked-venue papers
9as first author
31since 2021 · last 2026
0000-0002-0888-2322ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 5 first-author · 17 since 2021Computer networks · 9 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Binary Erasure: Soft-Weighted Unlearning for Fairness and RobustnessabstractMachine unlearning, as a post-hoc processing technique, has gained widespread adoption in addressing challenges like bias mitigation and robustness enhancement. However, existing non-privacy unlearning-based solutions persist in using a binary data removal framework designed for privacy-driven motivation, even when repurposed for fairness or robustness improvements. This leads to significant utility loss, a phenomenon known as “over-unlearning”. While over-unlearning has been largely described in many studies as primarily causing utility degradation, we investigate deeper insights in this work through counterfactual leave-one-out analysis. Based on insights, we introduce a soft weighting strategy that assigns tailored weights to each sample by solving a convex quadratic programming problem analytically, which enables fine-grained model adjustments to address the over-unlearning. We demonstrate that the proposed soft-weighted scheme can be seamlessly integrated into most existing unlearning algorithms. Extensive experiments show that in fairness- and robustness-driven tasks, the soft-weighted scheme significantly outperforms hard-weighted schemes in fairness/robustness metrics and alleviates the decline in utility metric, thereby enhancing unlearning algorithm as an effective correction solution. Xinbao Qiao, Ningning Ding, Yushi Cheng, Meng Zhang 0013 |
AAAI | 3 |
| 2026 | Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
Yinan Zhong, Qianhao Miao, Yanjiao Chen, Jiangyi Deng, Yushi Cheng, Wenyuan Xu 0001 |
NDSS | 5 |
| 2025 | MYOPIA: Protecting Face Privacy from Malicious Personalized Text-to-Image Synthesis via Unlearnable ExamplesabstractPersonalized text-to-image synthesis models, such as DreamBooth, have demonstrated significant potential in creating lifelike images tailored to a specific individual by fine-tuning from a limited set of face images and simple prompts. However, if misused, these model could pose a serious risk of privacy infringement by generating harmful images containing violent or pornographic content. To tackle this issue, this paper introduces MYOPIA, a method that renders facial images unlearnable by incorporating error-minimizing perturbations. These meticulously designed perturbations enables the model to quickly overfit to them, resulting in a swift reduction in loss and the cessation of model fine-tuning, effectively preventing the model from capturing genuine facial features. Moreover, to ensure the imperceptibility and robustness of the perturbations, we utilize the Just-Noticeable-Difference and Expectation-of-Transformation techniques to regulate both their location and intensity. Evaluation on two face dataset, i.e., VGGFace2 and CelebA-HQ, with various model versions illustrates the effectiveness of our approach in preserving personal privacy. Furthermore, our method showcases robust transferability across diverse model versions and demonstrates resilience against various image pre-processing techniques. Yushi Cheng, Tianyang Sun, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
AAAI | 2 |
| 2025 | V-Phanton: Voltage-Based Physically-Triggered Backdoor Attack Against Facial RecognitionabstractPhysical backdoor attacks are under increasing scrutiny, yet current methods often necessitate directly applying adversarial perturbations to target objects, like the attacker’s face. These approaches often pose practical challenges and compromise concealment. In this paper, we propose a stealthy, physically-triggered backdoor attack, V-Phanton,enabling attackers to engage in face spoofing and bypass facial recognition without the need for physical alterations to the attacker or model modifications. Specifically, V-Phanton manipulates the power supply voltage of the webcam to introduce adversarial perturbations into the captured image, which undermines the recognition process. Our experiments across three facial recognition models (ArcFace-50, MagFace-18/50) and one commercial facial recognition system (Face++) illustrate that V-Phanton achieves attack and victim success rates of up to 100% and 100% in simulations, and 100% and 99.93% in real-world experiments. Ruishan Li, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICASSP | 3 |
| 2025 | AdvPainting: Clean-text Jailbreaking Against Inpainting ModelsabstractText-guided inpainting models are widely used for image editing, restoration, and content generation due to their ability to produce high-fidelity results aligned with natural language prompts. However, these models remain vulnerable to jailbreaking attacks, where adversaries manipulate inputs to generate pornographic or violent content. While prior attacks rely on adversarial text prompts, they are increasingly mitigated by advanced text-based safety filters and manual review. In this work, we propose a new attack paradigm that bypasses these defenses by leveraging the image modality alone. Specifically, we inject imperceptible adversarial perturbations into the input image, enabling successful jailbreaks even when paired with clean prompts (e.g., ''a woman''). To achieve this, we address two key challenges: (1) stabilizing the optimization of adversarial perturbations via a novel gradient estimator, and (2) ensuring visual imperceptibility through a diffusion-based perturbation generator. Extensive experiments show that our method successfully compromises the Stable Diffusion Inpainting model-despite its built-in image and text safety checkers-achieving an average attack success rate (ASR) of 85.7%, significantly outperforming baselines (58.7%). Moreover, our attack exhibits strong transferability across models and maintains robustness against common image pre-processing defenses. Warning: Blurred or masked NSFW imagery is contained. Bingqian Zhou, Yushi Cheng, Wenyuan Xu 0001 |
ACM Multimedia | 3 |
| 2025 | Laser-Based LiDAR Spoofing: Effects Validation, Capability Quantification, and CountermeasuresabstractAutonomous vehicles (AVs) and robots increasingly exploit light detection and ranging (LiDAR)-based 3-D object detection systems to detect obstacles in the environment. Correct detection and classification are important to ensure safe driving. Although previous work has demonstrated the feasibility of manipulating point clouds to spoof 3-D object detectors, most of these attempts are performed digitally. In this article, we investigate the possibility of physically fooling LiDAR-based 3-D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We further analyze the impact of our attacks on four fusion-based detectors. This article concludes with experiments on defense methods and discussion on potential defense strategies at both the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Multi-Modal Spoofing Attacks on 3D Face Liveness Detection via a Single 2D PhotoabstractFace authentication technology has been widely used in physical access control to critical infrastructures. The security of a face authentication system has been threatened by photo replay attacks and thus the 3D liveness detection techniques have been deployed to safeguard such systems. In this paper, we conduct a comprehensive analysis of the security aspects pertaining to 3D liveness detection systems that employ structured light depth camera, and propose a novel attack surface targeting 3D face authentication systems involving multiple modalities such as Depth, RGB and IR. We propose theDepthFakeattack, a multi-modal spoofing attack against real-world 3D face authentication using only a single 2D photo. To achieve it,DepthFakefirst reconstruct the depth information of the victim's face from his 2D photo. Then,DepthFakeactively projects a carefully-crafted scatter patterns embedded with the face depth information, in order to empower the 2D photo with 3D authentication properties. We address a range of practical challenges, including mitigating depth estimation errors, achieving depth images forgery techniques based on structured light, ensuring accurate alignment between various modalities of face images, and effectively implementingDepthFakein real world. We validatedDepthFakeon 5 commercial face authentication systems (i.e., Tencent Cloud, Baidu Cloud, 3DiVi, Ali Cloud and ArcSoft) and two commercial access control devices. The results over 50 users demonstrate thatDepthFakeachieves an overall Depth attack success rate of 79.4%, RGB-D attack success rate of 59.4%, IR-D attack success rate of 79.4%, and RGB-IR attack success rate of 83.8% in the real world. Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | UniID: Spoofing Face Authentication System by Universal Identity
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 2 |
| 2024 | CamPro: Camera-based Anti-Facial Recognition
Jiani Liu 0009, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 4 |
| 2024 | Understanding and Benchmarking the Commonality of Adversarial ExamplesabstractSpeech recognition system converts audio into texts by utilizing deep learning algorithms. Numerous works have demonstrated various adversarial example (AE) attacks, i.e., adding carefully-crafted noises can trick the speech recognition system into outputting completely incorrect texts. This paper aims to reveal the distinctive properties of adversarial audio in terms of phonetics. We believe analyzing the distinctive properties is critical in understanding adversarial attacks on ASR models, as well as guiding the generation and defense of AEs. Thus, we aim to answer three questions: (1) What are the distinctive properties of adversarial audio that are common to diverse attacks? (2) How to quantify these distinctive properties? (3) How can we use these properties to improve the security of ASR models? To answer these questions, we perform a large-scale measurement based on acoustic features and statistical analysis. By measuring a total of 612,000 acoustic-statistical feature vectors for 2,400 audio samples, we obtain four insights on the distinctive properties, i.e., filling energy gap, speech-like morphology, disordered signal, and abnormal linguistic pattern. Based on these properties, we design a naturalness score to assess the stealthiness of attacks and propose an adversarial example detector with an average accuracy of 91.1%. He Ruiwen, Yushi Cheng, Junning Ze, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
SP | 2 |
| 2024 | Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack
Zizhi Jin, Xuancun Lu, Yushi Cheng, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
WWW | 4 |
| 2024 | Device authentication for 5G terminals via Radio Frequency fingerprintsabstractThe development of wireless communication network technology has provided people with diversified and convenient services. However, with the expansion of network scale and the increase in the number of devices, malicious attacks on wireless communication are becoming increasingly prevalent, causing significant losses. Currently, wireless communication systems authenticate identities through certain data identifiers. However, this software-based data information can be forged or replicated. This article proposes the authentication of device identity using the hardware fingerprint of the terminal’s Radio Frequency (RF) components, which possesses properties of being genuine, unique, and stable, holding significant implications for wireless communication security. Through the collection and processing of raw data, extraction of various features including time-domain and frequency-domain features, and utilizing machine learning algorithms for training and constructing a legal fingerprint database, it is possible to achieve close to a 97% recognition accuracy for Fifth Generation (5G) terminals of the same model. This provides an additional and robust hardware-based security layer for 5G communication security, enhancing monitoring capability and reliability. Namin Hou, Yuting Tang, Yushi Cheng, Xiaoyu Ji 0001 |
High Confid. Comput. | 4 |
| 2024 | Adversarial robustness analysis of LiDAR-included models in autonomous drivingabstractIn autonomous driving systems, perception is pivotal, relying chiefly on sensors like LiDAR and cameras for environmental awareness. LiDAR, celebrated for its detailed depth perception, is being increasingly integrated into autonomous vehicles. In this article, we analyze the robustness of four LiDAR-included models against adversarial points under physical constraints. We first introduce an attack technique that, by simply adding a limited number of physically constrained adversarial points above a vehicle, can make the vehicle undetectable by the LiDAR-included models. Experiments reveal that adversarial points adversely affect the detection capabilities of both LiDAR-only and LiDAR-camera fusion models, with a tendency for more adversarial points to escalate attack success rates. Notably, voxel-based models are more susceptible to deception by these adversarial points. We also investigated the impact of the distance and angle of the added adversarial points on the attack success rate. Typically, the farther the victim object to be hidden and the closer to the front of the LiDAR, the higher the attack success rate. Additionally, we have experimentally proven that our generated adversarial points possess good cross-model adversarial transferability and validated the effectiveness of our proposed optimization method through ablation studies. Furthermore, we propose a new plug-and-play, model-agnostic defense method based on the concept of point smoothness. The ROC curve of this defense method shows an AUC value of approximately 0.909, demonstrating its effectiveness. Zizhi Jin, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
High Confid. Comput. | 3 |
| 2024 | Fast and Lightweight Voice Replay Attack Detection via Time-Frequency Spectrum DifferenceabstractDue to the open nature of voice and voice interface, an adversary can spoof voice recognition systems by replaying pre-recorded voice commands from legitimate users, known as the voice replay attack. Existing detection methods against voice replay attacks mainly rely on extra hardware to determine the sound source or require excessive computing resources to train a classifier with abundant acoustic features. In this paper, we propose Anti-Replay, a fast and lightweight detection system for voice replay attacks. To overcome the challenge of redundant classification features and complex calculation, we first investigate the time-frequency spectrum difference between the genuine human voice and the replayed audio caused by the non-linear distortion of the attacker’s microphones and speakers. Then, we design 5 types with a total of 77 features in both the time and frequency domains and propose a convolutional neural network classifier SE-ResNet50 for attack detection. Evaluations against the datasets of ASVspoof2017, ASVspoof2019, and ASVspoof2021 demonstrate that Anti-Replay can achieve an average equal error rate (EER) of 1.36% across three datasets. Meanwhile, Anti-Replay decreases the training time by 52.3% and 90.2% and decreases the model size by 83.5% and 99.9% compared with the baseline model CQCC-GMM and the state-of-the-art method Res2Net. We have also confirmed that our system is effective in detecting the adaptive replay attack. He Ruiwen, Yushi Cheng, Zhicong Zheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial UltrasoundabstractAutomatic Speaker Recognition Systems (SRSs) have been widely used in voice applications for personal identification and access control. A typical SRS consists of three stages, i.e., training, enrollment, and recognition. Previous work has revealed that SRSs can be bypassed by backdoor attacks at the training stage or by adversarial example attacks at the recognition stage. In this paper, we propose TUNER, a new type of backdoor attack against the enrollment stage of SRS via adversarial ultrasound modulation, which is inaudible, synchronization-free, content-independent, and black-box. Our key idea is to first inject the backdoor into the SRS with modulated ultrasound when a legitimate user initiates the enrollment, and afterward, the polluted SRS will grant access to both the legitimate user and the adversary with high confidence. Our attack faces a major challenge of unpredictable user articulation at the enrollment stage. To overcome this challenge, we generate the ultrasonic backdoor by augmenting the optimization process with random speech content, vocalizing time, and volume of the user. Furthermore, to achieve real-world robustness, we improve the ultrasonic signal over traditional methods using sparse frequency points, pre-compensation, and single-sideband (SSB) modulation. We extensively evaluate TUNER on two common datasets and seven representative SRS models, as well as its robustness against seven kinds of defenses. Results show that our attack can successfully bypass speaker recognition systems while remaining effective to various speakers, speech content, etc. To mitigate this newly discovered threat, we also provide discussions on potential countermeasures, limitations, and future works of this new threat. Xinfeng Li, Junning Ze, Chen Yan 0001, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Adversarial Computer Vision via Acoustic Manipulation of Camera SensorsabstractAutonomous vehicles increasingly rely on camera-based computer vision systems to perceive environments and make critical driving decisions. To improve image quality, image stabilizers with inertial sensors are added to reduce image blurring caused by camera jitters. However, this trend creates a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of emerging image stabilizer hardware susceptible to acoustic manipulation and computer vision algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even when the camera is stable. These blurred images can induce object misclassification, affecting safety-critical decision-making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks: hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against five object detectors (YOLO V3/V4/V5, Faster R-CNN, and Apollo) and two lane detectors (UFLD and LaneAF). We further introduce the concept ofAMpLeattacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware. Yushi Cheng, Xiaoyu Ji 0001, Kevin Fu, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Scoring Metrics of Assessing Voiceprint Distinctiveness Based on Speech Content and RateabstractA voiceprint is the distinctive pattern of human voices widely used for authentication in voice assistants. This paper investigates the impact of speech contents and speech rates on the distinctiveness of voiceprint, and has obtained answers to three questions by studying 2457 speakers and 21,500,000 test samples: 1) What are the influential factors that users can control to affect the distinctiveness of voiceprints? 2) How to quantify the distinctiveness for given speeches, e.g., the speech of wake-up words when activating voice assistants? 3) How to help users select wake-up words and adjust the speech rate to improve distinctiveness levels? To answer those questions, we break down speeches into phones, and experimentally obtain the correlation between false recognition rates and the richness, order, length, and elements of the phones. Then, we define the PROLE Score that can reflect the voice distinctiveness, and evaluate 30 wake-up words of 19 commercial voice assistant products to provide recommendations on selecting secure voiceprint words. We also measure the correlation between false recognition rates and speech rates, and define the TER Score that reveals the distance of distinctiveness from the secure voiceprint, and it guides users to adjust their speech rate to a secure value. He Ruiwen, Yushi Cheng, Junning Ze, Xinfeng Li, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | On Tracing Screen Photos - A Moiré Pattern-Based ApproachabstractCyber-theft of trade secrets has become a serious business threat. Digital watermarking is a popular technique to help identify the source of the file leakage, whereby a unique watermark for each insider is hidden in sensitive files. However, malicious insiders may use smartphones to photograph the secret file displayed on screens to remove the embedded hidden digital watermarks due to the optical noises introduced during photographing. To identify the leakage source despite suchscreen-photo-based leakage attacks, we leverage Moiré pattern, an optical phenomenon resulted from the optical interaction between electronic screens and cameras. As such, we presentmID, a new watermark-like technique that can create a carefully crafted Moiré pattern on the photo when it is taken towards the screen. We design patterns that appear to be natural yet can be linked to the identity of the leaker. We implementedmIDand evaluated it with 7 display devices and 6 smartphones from various manufacturers and models. The results demonstrate thatmIDcan achieve an average bit error rate (BER) of$0.2\%$and can successfully identify an ID with an average accuracy of$98\%$, with little influence from the type of display devices, cameras, IDs, and ambient lights. Wenyuan Xu 0001, Yushi Cheng, Xiaoyu Ji 0001, Yi-Chao Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Evaluating Compressive Sensing on the Security of Computer Vision SystemsabstractThe rising demand for utilizing fine-grained data in deep-learning (DL) based intelligent systems presents challenges for the collection and transmission abilities of real-world devices. Deep compressive sensing, which employs deep learning algorithms to compress signals at the sensing stage and reconstruct them with high quality at the receiving stage, provides a state-of-the-art solution for the problem of large-scale fine-grained data. However, recent works have proven that fatal security flaws exist in current deep learning methods and such instability is universal for DL-based image reconstruction methods. In this article, we assess the security risks introduced by deep compressive sensing in the widely used computer vision system in the face of adversarial example attacks and poisoning attacks. To implement the security inspection in an unbiased and complete manner, we develop a comprehensive methodology and a set of evaluation metrics to manage all potential combinations of attack methods, datasets (application scenarios), categories of deep compressive sensing models, and image classifiers. The results demonstrate that deep compressive sensing models unknown to adversaries can protect the computer vision system from adversarial example attacks and poisoning attacks, whereas the ones exposed to adversaries can cause the system to become more vulnerable. Yushi Cheng, Yanjiao Chen, Yi-Chao Chen 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 1 |
| 2023 | PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous VehicleabstractAutonomous vehicles and robots increasingly exploit LiDAR-based 3D object detection systems to detect obstacles in environment. Correct detection and classification are important to ensure safe driving. Though existing work has demonstrated the feasibility of manipulating point clouds to spoof 3D object detectors, most of the attempts are conducted digitally. In this paper, we investigate the possibility of physically fooling LiDAR-based 3D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, which is 20 times more than prior work, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We also discuss defense strategies at the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
SP | 3 |
| 2023 | DepthFake: Spoofing 3D Face Authentication with a 2D PhotoabstractFace authentication has been widely used in access control, and the latest 3D face authentication systems employ 3D liveness detection techniques to cope with the photo replay attacks, whereby an attacker uses a 2D photo to bypass the authentication. In this paper, we analyze the security of 3D liveness detection systems that utilize structured light depth cameras and discover a new attack surface against 3D face authentication systems. We propose DepthFake attacks that can spoof a 3D face authentication using only one single 2D photo. To achieve this goal, DepthFake first estimates the 3D depth information of a target victim’s face from his 2D photo. Then, DepthFake projects the carefully-crafted scatter patterns embedded with the face depth information, in order to empower the 2D photo with 3D authentication properties. We overcome a collection of practical challenges, e.g., depth estimation errors from 2D photos, depth images forgery based on structured light, the alignment of the RGB image and depth images for a face, and implemented DepthFake in laboratory setups. We validated DepthFake on 3 commercial face authentication systems (i.e., Tencent Cloud, Baidu Cloud, and 3DiVi) and one commercial access control device. The results over 50 users demonstrate that DepthFake achieves an overall Depth attack success rate of 79.4% and RGB-D attack success rate of 59.4% in the real world. Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
SP | 2 |
| 2023 | CAPatch: Physical Adversarial Patch against Image Captioning Systems
Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
USENIX Security Symposium | 2 |
| 2023 | TPatch: A Triggered Physical Adversarial Patch
Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001 |
USENIX Security Symposium | 3 |
| 2023 | No Seeing is Also Believing: Electromagnetic-Emission-Based Application Guessing Attacks via SmartphonesabstractMobile devices have emerged as the most popular platforms to access information. However, they have also become a major concern of privacy violation and previous researches have demonstrated various approaches to infer user privacy based on mobile devices. In this paper, we study the electromagnetic (EM) emission of a laptop that could be harvested by a commercial-off-the-shelf (COTS) mobile device, e.g., a smartphone. We proposeMagAttack, which exploits the electromagnetic side channel of a laptop to guess user activities, i.e., application launching and application operation. The key insight ofMagAttackis that applications are discrepant in essence due to the different compositions of instructions, which can be reflected on the CPU power consumption, and thus the corresponding EM emissions.MagAttackis challenging since that EM signals are noisy due to the dynamics of applications and the limited sampling rate of the built-in magnetometers in COTS mobile devices. We overcome these challenges and convert noisy coarse-grained EM signals to robust fine-grained features. We implementMagAttackon both an iOS and an Android smartphone without any hardware modification, and evaluate its performance with 30 popular applications, 30 YouTube videos, and 50 top websites in China. The results demonstrate thatMagAttackcan recognize aforementioned 30 applications with an average accuracy of 98.6 percent, and identify which video out of the 30 candidates being played with an average accuracy of 97.5 percent and visiting which website among the 50 candidates with an average accuracy of 90.4 percent. Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001, Yuehan Chi, Hao Pan 0003, Zhuangdi Zhu, Chuang-Wen You, Yi-Chao Chen 0001, Lili Qiu |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | PDGes: An Interpretable Detection Model for Parkinson's Disease Using SmartphonesabstractParkinson’s disease (PD) is a neurodegenerative disorder that severely affects the motor system of patients. Early PD detection will greatly improve the quality of lives. However, existing automatic PD detection systems either rely on customized sensors or require users to perform special activities, using machine learning models whose prediction process is not understandable by medical professionals. In this article, we develop a non-disruptive PD detection system on smartphones based on interpretable prediction models. We design an application named PDGes to passively collect touchscreen and Inertial Measurement Unit data of users’ tapping and swiping actions on smartphones. Meaningful features that reflect finger dexterity , tremor , stiffness , and hand movement are extracted to build the prediction model. To better comprehend the decisions made by the model, we conduct a systematic analysis of feature importance to help validate the conformity of the model with clinical PD diagnosis. We collected data from 108 volunteers to evaluate the performance of PDGes . The experiment results show that PDGes achieves a detection accuracy of more than 94.5% on different smartphones. Yanjiao Chen, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 2 |
| 2022 | UltraBD: Backdoor Attack against Automatic Speaker Verification Systems via Adversarial UltrasoundabstractAutomatic speaker verification (ASV) systems have been widely applied in voice user interfaces to conduct person identification and access control via voiceprints. A typical ASV system consists of three stages, i.e., training, enrollment, and verification. Previous work has revealed that the ASV system can be bypassed at the training stage by backdoor attacks and at the verification stage by adversarial example attacks. In this paper, we propose a new type of backdoor attack aimed at the enrollment stage via adversarial ultrasound, named UltraBD, which is highly imperceptible, synchronization-free, and content-independent. By simultaneously injecting the ultrasound backdoor examples when the legitimate user initiates the enrollment, the polluted voiceprints stored in the ASV systems grant access to both the legitimate user and the adversary with relatively high confidence. Despite the challenges, i.e., when, what, and how the legitimate user articulates at the enrollment stage can be remarkably unpredictable and various, we managed to launch UltraBD by augmenting the generation and optimization process of the ultrasound backdoor examples with the randomness of synchronous time and relative amplitude ratio. Furthermore, we optimize the modulation mechanism of adversarial ultrasound by tuning the baseband signal on limited signal frequency points to improve its robustness in the physical world setting. We validate UltraBD on two common datasets together with two open-source ASV models. Results show that UltraBD can be robust to various configurations, e.g., different speakers and utterance content. In sum, our attack calls attention to a new attack surface of ASV systems and sheds light on its fundamental mechanisms. Junning Ze, Xinfeng Li, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICPADS | 3 |
| 2022 | OutletGuarder: Detecting DarkSide Ransomware by Power Factor Correction Signals in an Electrical OutletabstractRansomware is a kind of computer malware that has spread widely in recent years, such as DarkSide, which spread around the world recently. It’s reported that DarkSide extorted ${\$}$ 90 million in nine months. It extorts ransom from users by encrypting user files and other methods, causing huge economic losses to users, including commercial organizations and individuals. Existing ransomware detection methods include the hostbased methods and the network-based methods. However, these methods are either hard to deploy or have the possibility to be evaded. In this paper, we propose OutletGuarder, a non-intrusive detection method against DarkSide ransomware based on the signal generated by the Power Factor Correction module of the host computer’s power supply in electrical outlets, which carries the power consumption information of the host computer during the execution of DarkSide. By utilizing the power consumption variation among different programs, especially the power consumption caused by frequent encryption and I/O operations during the execution of DarkSide, OutletGuarder achieves a detection F1 Score of 97.50%. The impact of classification models and untrained programs, as well as the model transferability and robustness are evaluated. Shan Zou, Juchuan Zhang, Shui Jiang, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICPADS | 4 |
| 2022 | "OK, Siri" or "Hey, Google": Evaluating Voiceprint Distinctiveness via Content-based PROLE Score
He Ruiwen, Xiaoyu Ji 0001, Xinfeng Li, Yushi Cheng, Wenyuan Xu 0001 |
USENIX Security Symposium | 4 |
| 2022 | Device Fingerprinting with Magnetic Induction Signals Radiated by CPU ModulesabstractWith the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally measured device fingerprints, such as device ID, software or hardware-based characteristics. In this article, we propose DeMiCPU , a stimulation-response-based device fingerprinting technique that relies on externally measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power-supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.7% precision and recall on average, and 99.8% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6~s. The performance can be further improved to 99.9% with multi-round fingerprinting. In addition, we implement a prototype of DeMiCPU docker, which can effectively reduce the requirement of test points and enlarge the fingerprinting area. Xiaoyu Ji 0001, Yushi Cheng, Juchuan Zhang, Yuehan Chi, Wenyuan Xu 0001, Yi-Chao Chen 0001 |
ACM Trans. Sens. Networks | 2 |
| 2021 | Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionabstractAutonomous vehicles increasingly exploit computer-vision-based object detection systems to perceive environments and make critical driving decisions. To increase the quality of images, image stabilizers with inertial sensors are added to alleviate image blurring caused by camera jitters. However, such a trend opens a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of the emerging image stabilizer hardware susceptible to acoustic manipulation and the object detection algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even if the camera is stable. The blurred images can then induce object misclassification affecting safety-critical decision making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks, i.e., hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against four academic object detectors (YOLO V3/V4/V5 and Fast R-CNN), and one commercial detector (Apollo). We further introduce the concept of AMpLe attacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware. Xiaoyu Ji 0001, Yushi Cheng, Kai Wang 0073, Chen Yan 0001, Wenyuan Xu 0001, Kevin Fu |
SP | 2 |
| 2021 | mID: Tracing Screen Photos via Moiré Patterns
Yushi Cheng, Xiaoyu Ji 0001, Lixu Wang, Qi Pang, Yi-Chao Chen 0001, Wenyuan Xu 0001 |
USENIX Security Symposium | 1 |
| 2020 | On Detecting Hidden Wireless Cameras: A Traffic Pattern-based ApproachabstractWireless cameras are widely deployed in surveillance systems for security guarding. However, the privacy concerns associated with unauthorized videotaping, are drawing increasing attention recently. Existing detection methods for unauthorized wireless cameras are either limited by their detection accuracy or requiring dedicated devices. In this paper, we propose DeWiCam, a lightweight and effective detection mechanism using smartphones. The basic idea of DeWiCam is to utilize the intrinsic traffic patterns of flows from wireless cameras. Compared with traditional traffic pattern analysis, DeWiCam is more challenging because it cannot access the encrypted information in the data packets. Yet, DeWiCam overcomes the difficulty and can detect nearby wireless cameras reliably. To further identify whether a camera is in an interested room, we propose a human-assisted identification model. Extension functions of DeWiCam further enable the video resolution and audio channel inference to provide extra protection. We implemented DeWiCam on the Android platform and evaluated it with extensive experiments on 20 cameras. The evaluation results show that DeWiCam can detect cameras with an accuracy of 99 percent within 2:7 s. Yushi Cheng, Xiaoyu Ji 0001, Tianyang Lu, Wenyuan Xu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2020 | Identifying Child Users via Touchscreen InteractionsabstractWith the proliferation of smart devices, children can be easily exposed to violent or adult-only content on the Internet. Without any precaution, the premature and unsupervised use of smart devices can be harmful to both children and their parents. Thus, it is critical to employ parent patrol mechanisms such that children are restricted to child-friendly content only. A successful parent patrol strategy has to be user friendly and privacy aware. The apps that require explicit actions from parents are not effective because a parent may forget to enable them, and the ones that use built-in cameras or microphones to detect child users may impose privacy violations. In this article, we propose iCare, a system that can identify child users automatically and seamlessly when users operate smartphones. In particular, iCare investigates the intrinsic differences of screen-touch patterns between child and adult users from the aspect of physiological maturity. We discover that one’s touch behaviors are related to his or her age. Thus, iCare records the touch behaviors and extracts hand geometry, finger dexterity, and hand stability features that capture the age information. We conduct experiments on 100 people including 62 children (3 to 17 years old) and 38 adults (18 to 59 years old). Results show that iCare can achieve 96.6% accuracy for child identification using only a single swipe on the screen, and the accuracy becomes 98.3% with three consecutive swipes. Yushi Cheng, Xiaoyu Ji 0001, Xiaopeng Li 0001, Tianchen Zhang, Sharaf Jameel Malebary, Xianshan Qu, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 1 |
| 2019 | MagAttack: Guessing Application Launching and Operation via SmartphoneabstractMobile devices have emerged as the most popular platforms to access information. However, they have also become a major concern of privacy violation and previous researches have demonstrated various approaches to infer user privacy based on mobile devices. In this paper, we study a new side channel of a laptop that could be harvested by a commercial-off-the-shelf (COTS) mobile device, eg, a smartphone. We propose MagAttack, which exploits the electromagnetic (EM) side channel of a laptop to infer user activities, i.e., application launching and application operation. The key insight of MagAttack is that applications are discrepant in essence due to the different compositions of instructions, which can be reflected on the CPU power consumption, and thus the corresponding EM emissions. MagAttack is challenging since that EM signals are noisy due to the dynamics of applications and the limited sampling rate of the built-in magnetometers in COTS mobile devices. We overcome these challenges and convert noisy coarse-grained EM signals to robust fine-grained features. We implement MagAttack on both an iOS and an Android smartphone without any hardware modification, and evaluate its performance with 13 popular applications and 50 top websites in China. The results demonstrate that MagAttack can recognize aforementioned 13 applications with an average accuracy of 98.6%, and figure out the visiting operation among 50 websites with an average accuracy of 84.7%. Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001, Hao Pan 0003, Zhuangdi Zhu, Chuang-Wen You, Yi-Chao Chen 0001, Lili Qiu |
AsiaCCS | 1 |
| 2019 | DeMiCPU: Device Fingerprinting with Magnetic Signals Radiated by CPUabstractWith the widespread use of smart devices, device authentication has received much attention. One popular method for device authentication is to utilize internally-measured device fingerprints, such as device ID, software or hardware-based characteristics. In this paper, we propose DeMiCPU, a stimulation-response-based device fingerprinting technique that relies on externally-measured information, i.e., magnetic induction (MI) signals emitted from the CPU module that consists of the CPU chip and its affiliated power supply circuits. The key insight of DeMiCPU is that hardware discrepancies essentially exist among CPU modules and thus the corresponding MI signals make promising device fingerprints, which are difficult to be modified or mimicked. We design a stimulation and a discrepancy extraction scheme and evaluate them with 90 mobile devices, including 70 laptops (among which 30 are of totally identical CPU and operating system) and 20 smartphones. The results show that DeMiCPU can achieve 99.1% precision and recall on average, and 98.6% precision and recall for the 30 identical devices, with a fingerprinting time of 0.6 s. In addition, the performance can be further improved to 99.9% with multi-round fingerprinting. Yushi Cheng, Xiaoyu Ji 0001, Juchuan Zhang, Wenyuan Xu 0001, Yi-Chao Chen 0001 |
CCS | 1 |
| 2018 | DeWiCam: Detecting Hidden Wireless Cameras via SmartphonesabstractWireless cameras are widely deployed in surveillance systems for security guarding. However, the privacy concerns associated with unauthorized videotaping, are drawing an increasing attention recently. Existing detection methods for unauthorized wireless cameras are either limited by their detection accuracy or requiring dedicated devices. In this paper, we propose DeWiCam, a lightweight and effective detection mechanism using smartphones. The basic idea of DeWiCam is to utilize the intrinsic traffic patterns of flows from wireless cameras. Compared with traditional traffic pattern analysis, DeWiCam is more challenging because it cannot access the encrypted information in the data packets. Yet, DeWiCam overcomes the difficulty and can detect nearby wireless cameras reliably. To further identify whether a camera is in an interested room, we propose a human-assisted identification model. We implement DeWiCam on the Android platform and evaluate it with extensive experiments on 20 cameras. The evaluation results show that DeWiCam can detect cameras with an accuracy of 99% within 2.7 s. Yushi Cheng, Xiaoyu Ji 0001, Tianyang Lu, Wenyuan Xu 0001 |
AsiaCCS | 1 |
| 2018 | User Presence Inference via Encrypted Traffic of Wireless Camera in Smart HomesabstractWireless cameras are widely deployed in smart homes for security guarding, baby monitoring, fall detection, and so on. Those security cameras, which are supposed to protect users, however, may in turn leak a user’s personal privacy. In this paper, we reveal that attackers are able to infer whether users are at home or not, that is, the user presence, by eavesdropping the traffic of wireless cameras from distance. We propose HomeSpy, a system that infers user presence by inspecting the intrinsic pattern of the wireless camera traffic. To infer the user presence, HomeSpy first eavesdrops the wireless traffic around the target house and detects the existence of wireless cameras with a Long Short-Term Memory (LSTM) network. Then, HomeSpy infers the user presence using the bitrate variation of the wireless camera traffic based on a cumulative sum control chart (CUSUM) algorithm. We implement HomeSpy on the Android platform and validate it on 20 cameras. The evaluation results show that HomeSpy can achieve a successful attack rate of 97.2%. Xiaoyu Ji 0001, Yushi Cheng, Wenyuan Xu 0001 |
Secur. Commun. Networks | 2 |
| 2017 | HomeSpy: Inferring User Presence via Encrypted Traffic of Home Surveillance CameraabstractWireless cameras are widely deployed in homes and offices for security guarding, and play as an important part of smart home devices. Those security cameras, which are supposed to provide protection services, however, may in turn leak personal privacy that can result in security issues. In this paper, we reveal that attackers are able to eavesdrop the traffic of wireless cameras and analyze whether you are at home or not without entering the house. We propose HomeSpy, an attack tool that infers the house status by inspecting the bitrate variation of the wireless camera traffic. We implement HomeSpy on the Android platform and validate it on 3 cameras. The evaluation results show that HomeSpy can achieve a successful attack rate of 97.2%. Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICPADS | 1 |
| 2003 | A Web-Based Intelligent Forecasting System
King Jim Hee, Yushi Cheng |
KES | 3 |