EDBT 2026 Demo / reviewers in the wild / expert
Chi-Yu Li 0001
dblp:63/4474-1
· DBLP profile ↗
60ranked-venue papers
7as first author
35since 2021 · last 2026
0000-0002-1077-6801ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 49 · 6 first-author · 28 since 2021Security and privacy · 6 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Acoustic Attacks against MEMS Gyroscope on UAVs
Kuan-Cheng Chen, Yen-Chia Chen, Yu-Xun Tang, Li-Ping Tung, Chi-Yu Li 0001 |
ICC | 5 |
| 2026 | Edge Resilient Agent (ERA) : An Edge AI-Driven Framework for B5G and Wi-Fi 6 Heterogeneous MEC Networks
Hsu Liang Shu, Zhengen Chen, Tan Tai Phan, Chi-Yu Li 0001, Li-Chun Wang 0001 |
ICC | 4 |
| 2026 | Hiaeml: A High-Throughput Adaptive Scheduler for EMLSR-Based Multi-Link Operation in Wi-Fi 7
Ming-Huang Hsieh, Yu-Po Wang, Chi-Yu Li 0001 |
INFOCOM | 3 |
| 2026 | Enabling Edge AI Offloading for XR Devices in Cost-Effective Private 5G Networks
Chia-Yen Hsu, Cheng-En Wu, Rui-Quan Zeng, Yu-Xun Tang, Chuan-Yi Cheng, Chi-Yu Li 0001 |
INFOCOM | 6 |
| 2026 | Is Multi-Link Operation TCP-Friendly in Wi-Fi 7 Networks?
Jing-Shiuan Shiang, Min-Chih Hsu, Yu-Xun Tang, Chi-Yu Li 0001 |
INFOCOM | 4 |
| 2026 | Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks, and CountermeasuresabstractLost and stolen phone reporting services are widely deployed to prevent unauthorized device use by blacklisting International Mobile Equipment Identities (IMEIs). However, through an extensive experimental study across three major U.S. carriers and diverse mobile devices, we discover that these services unexpectedly introduce severe and previously unexplored security risks. Specifically, we identify six new vulnerabilities spanning the device, carrier, and cross-carrier domains, which together enable attackers to arbitrarily block cellular devices from accessing carrier networks. Building on these findings, we design and validate two practical denial-of-service (DoS) attacks: Home Security System Freezing, which disables cellular-based home security gateways and blocks alarm delivery, and Zero-Day Flagship Phone Ambush, which preemptively blocks brand-new flagship phones from accessing mobile services at launch. Both attacks are experimentally validated on operational 5G/4G networks. Finally, we propose practical, backward-compatible countermeasures and implement a prototype to evaluate their effectiveness. Min-Yue Chen, Yiwen Hu 0002, Yu-An Chen, Chi-Yu Li 0001, Tian Xie 0001, Guan-Hua Tu |
MobiSys | 4 |
| 2026 | When Mobile Equipment Security Lags Behind Infrastructure: Vulnerabilities, Attacks, and Countermeasures in IMS Services
Jingwen Shi, Min-Yue Chen, Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Yiwen Hu 0002, Man-Hsin Chen, Haitian Yan, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Netw. | 9 |
| 2025 | PDCA: Practical Dynamic Client Association in Wi-Fi Mesh Networks Using EasymeshabstractWi-Fi mesh networks have become critical for extending Wi-Fi coverage. Their underlying technologies have evolved from the decentralized IEEE 802.11s standard to the newly introduced EasyMesh, which operates in a centralized manner. However, neither approach can dynamically adapt Access Point (AP) and client association control to optimize throughput performance. Although EasyMesh can steer clients to a mesh AP from a centralized controller based on Wi-Fi signal strength, it overlooks other key factors such as AP load, channel congestion, and backhaul link capacity. In this paper, we propose a practical solution called Practical Dynamic Client Association (PDCA), which offers dynamic client association control over time to achieve max-min fairness in throughput performance while accounting for these critical factors. PDCA employs a heuristic-based approach to determine the optimal AP-client associations and then uses the EasyMesh client steering feature to execute association control. Our prototype demonstrates that PDCA consistently outperforms the default EasyMesh operation, achieving improvements of up to 165.2 % in minimum throughput and 60.0 % in aggregate throughput. Yu-Shao Su, Ming-Huang Hsieh, Tzu-Chi Yu, Chi-Yu Li 0001, Guan-Hua Tu |
ICC | 5 |
| 2025 | LOMAS: Latency-driven OFDMA Scheduling Design in Wi-Fi 6 Networks
Yi-An Tai, Yao-Wen Liu, Ping-Kuan Kao, Ting-Yu Lee, Cheng-I Hu, Chi-Yu Li 0001 |
ICNP | 6 |
| 2025 | BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol Stacks
Wei-Che Kao, Yen-Chia Chen, Chi-Yu Li 0001, Chun-Ying Huang |
USENIX Security Symposium | 5 |
| 2024 | QUIC-HOA: A Cross-layer, Handover-aware Design for QUIC Connection MigrationabstractQUIC (Quick UDP Internet Connection), a secure general-purpose transport protocol over UDP, has been introduced for a decade and standardized recently. Its operation is akin to the integration of TCP and TLS 1.3, while resolving some conventional transport-layer problems. One key feature is connection migration, which addresses the issue of TCP connections being interrupted when an endpoint’s IP address changes. In this work, we conduct a case study to examine its performance during client handover. The experimental results indicate that QUIC connection migration may fail with a probability as high as 76% during a hard handover, such as when the client disassociates from one Wi-Fi network and connects to another. The root cause of this issue lies in its initialization, which is passively based on the delivery timing of application data and a loss detection mechanism. We thus propose a simple yet effective solution called QUIC-HOA (QUIC Handover-Awareness). It enables the active initialization of connection migration with a cross-layer, handover-aware design. Our evaluation results confirm its effectiveness: QUIC-HOA consistently achieves successful connection migration while reducing average migration time by up to 98% compared to default QUIC. Po-Jui Chen, Ren-Chieh Hsu, Tzu-Chi Yu, Chi-Yu Li 0001 |
GLOBECOM | 4 |
| 2024 | Stealthy Remote Collection of Call Statistics in 4G/5G Mobile NetworksabstractCurrently, 90% of the global population relies on 4G/5G networks, with smartphones being an indispensable part of daily life. Call statistics, which are vital for billing purposes and treated as sensitive personal information, are safeguarded by legal regulations. One method of remotely obtaining call statistics involves initiating consecutive probing phone calls, which results in numerous missed calls on the recipient’s device. This paper adopts a stealthy phone call solution that utilizes the Session Initiation Protocol (SIP) vulnerabilities, enabling data collection without raising alarms for the callee. Through this approach, the paper distinguishes between calling and remaining states by analyzing the data returned from the callee. Furthermore, the paper introduces a two-level classifier to translate each call response into a state prediction, thus forming a sequence of state predictions over time to derive call statistics. To bolster the prediction accuracy of classification, two domains of knowledge, such as call state machines and typical human call behavior tendencies, are considered. This integration significantly enhances prediction accuracy to an impressive 98%. However, despite these advancements, there remain challenges. The prediction accuracy for call duration still requires improvement due to low probing frequency and occasional incorrect state predictions. Kai-Wen Chen, Li-Ping Tung, Tai Tan Phan, Chi-Yu Li 0001 |
ISCC | 4 |
| 2024 | Automatic Bridging for Mobile Wireless Backhaul SystemabstractBackhaul networks, serving as the intermediary link from the front-end radio network to the central core network, play a crucial role in end-to-end communication by transporting significant traffic volumes. Apparently, packet transmission efficiency depends on their deployment scenarios; indeed, the more flexibility often translates to the better user experience for the end-user in critical situations. In this work, we propose an automatic bridging system for mobile wireless backhaul designed for high flexibility and compatibility. It features a fully automated establishment of wireless backhaul links, supported by a VXLAN-based packet transmission pipeline and an auto-binding mechanism. We prototype the system on Linux-based operating system with standard packages to ensure the compatibility operation and WiGig modules; the evaluation demonstrates that the VXLAN-based system can achieve lower latency, with a reduction ranging from 15% to 38% compared to the static forwarding-based system. Tan Tai Phan, Shang-Chun Tai, Yu-Shuo Chang, Wei-Xun Chen, Chi-Yu Li 0001 |
ISCC | 5 |
| 2024 | Uncovering Problematic Designs Hindering Ubiquitous Cellular Emergency Services AccessabstractCellular networks provide the most accessible emergency services with ubiquitous coverage, yet their emergency-specific designs remain largely unexplored. To systematically explore potential design defects that lead to failures or delays in emergency services, we introduce M911-Verifier, an emergency-specific model checking tool. It reveals many counterintuitive findings regarding the ubiquitous access support for cellular emergency services. Our study shows that, despite sufficient wireless signal coverage, users may still experience prolonged emergency call setup times, call initiation failures, or call drops due to flaws in the design of cellular emergency services. These design defects arise from three major causes: problematic network selection for initiating emergency calls, emergency-unaware call operation, and network escalation forbidden during emergency calls. The impacts of these defects have been experimentally validated across three U.S. carriers and two Taiwan carriers using commodity smartphones. Finally, we propose solutions and evaluate their effectiveness. Yiwen Hu 0002, Min-Yue Chen, Haitian Yan, Chuan-Yi Cheng, Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Chunyi Peng 0001, Li Xiao 0001, Jiliang Tang |
MobiCom | 6 |
| 2024 | IMS is Not That Secure on Your 5G/4G PhonesabstractIMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities. Jingwen Shi, Sihan Wang 0002, Min-Yue Chen, Guan-Hua Tu, Tian Xie 0001, Man-Hsin Chen, Yiwen Hu 0002, Chi-Yu Li 0001, Chunyi Peng 0001 |
MobiCom | 8 |
| 2024 | Practical Latency-Aware Scheduling for Low-Latency Elephant VR Flows in Wi-Fi NetworksabstractVirtual reality (VR) applications are increasingly popular. With high-quality video streams and interactive content, they require both low-latency and high-bandwidth performance demands on the communication from the edge-based VR server to the VR headsets. Although most VR headsets are equipped with dedicated wired or wireless modules connected to the VR server, using common Wi-Fi networks to support them can be a promising trend due to convenience and low cost. However, current Wi-Fi Access Points (APs) cannot meet latency demands of low-latency elephant VR flows, especially in traffic congestion cases. We thus design a practical Wi-Fi scheduling solution, designated as LAST-PQ (Latency-Aware Scheduler with Two-level Priority Queueing), to support VR flows at the Wi-Fi AP. It monitors the runtime latency performance of VR flows while prioritizing scheduling for urgent flows, whose latency demands are at risk of violation. We implement LAST-PQ in Linux on a commodity Wi-Fi platform using an open-source Wi-Fi driver; it is compliant to the current Wi-Fi scheduling framework. The evaluation result shows that it can reduce latency by up to 79.89% in various congested scenarios; moreover, it consistently meets the latency demands of VR flows in cases of mobility at runtime. Shao-Jung Lu, Wei-Xun Chen, Yu-Shao Su, Yu-Shou Chang, Yao-Wen Liu, Chi-Yu Li 0001, Guan-Hua Tu |
PerCom | 6 |
| 2024 | IPA-DASH: Intelligent Proactive Adaptation for DASH Video Streaming at 5G Network EdgeabstractEdge computing has been determined as a key feature for achieving low-latency performance in 5G networks. It enables application servers to be deployed next to base stations, thus offering services without experiencing Internet delays or congestion. Thanks to the O-RAN (Open Radio Access Network) architecture, the edge server can obtain RAN information at run time and employ it to enhance the quality of edge-based services. In this work, we develop a proactive adaptation solution, designated as IPA-DASH (Intelligent Proactive Adaptation for Dynamic Adaptive Streaming over HTTP), for DASH video streaming services. By utilizing the radio access information for each UE (User Equipment), IPA-DASH applies deep reinforcement learning to estimate the best video quality at present, while enabling video segment reselection along with an in-band, low-overhead segment cancellation method. This allows IPA-DASH to proactively adapt video streaming before its quality suffers, in contrast to conventional video adaptation solutions that reactively adapt video streaming based solely on application-layer performance. These solutions have no access to radio access conditions, so the adaptation is triggered after the video quality degrades. We implement and evaluate IPA-DASH on both a simulator and an emulated 5G edge platform. The results demonstrate that IPA-DASH outperforms other video adaptation solutions, achieving gains of 1.1% to 55.6% in terms of average QoE (Quality of Experience) and reducing rebuffering time by 35.0% to 97.3%. Shun-Ting Lei, Yu-An Chen, Ren-Cheng Chen, Chih-Chien Lo, Chi-Yu Li 0001 |
PIMRC | 5 |
| 2024 | Transparent Third-Party Authentication With Application Mobility for 5G Mobile-Edge ComputingabstractMobile Edge Computing (MEC) is a key technology for supporting low latency applications close to the end user. Users can access application servers in MEC instead of routing to the Internet by passing through a core cellular network. Few security challenges arise as the traffic does not traverse through the core network, and these can be solved by providing authentication services in the MEC. However, authentication and application mobility issues arise in the case of multiple MECs where a user is mobile and needs continuous service from application servers, without needing to establish a new session and providing authentication information repeatedly to every new MEC the user connects with. In this work, we propose two solutions, a TC3A (Token-based Cookie transfer & 3rd-party Authentication) and a TS3A (Token-based State transfer & 3rd-party Authentication) for resolution of authentication and application mobility issues while achieving low latency. We conducted experiments on a testbed that had MECs deployed in a real-time cellular network (emulated via OpenAirInterface) and performed user handover between two MECs. The experimental results show that TC3A and TS3A successfully re-authenticate the users, without provision of login credentials with target MEC, while reducing the latency by approximately 49.76–59.72% as compared to simple login method. The TC3A and TS3A also eliminate the need of keeping multiple accounts for applications at different MECs and most importantly provide application service continuity, through state transfer during cross-system handover, which is not provided by a simple login method. TC3A provides the application service continuity without any loss of session state, which is suitable for applications that cannot afford state loss, and TS3A provides the same while reducing the latency by 47.05–51.25% as compared to TC3A, which is suitable for applications that require low latency. Ying-Dar Lin, Chi-Yu Li 0001, Yuan-Cheng Lai |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure DesignsabstractCellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities. Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
IEEE/ACM Trans. Netw. | 4 |
| 2024 | Dissecting Operational Cellular IoT Service Security: Attacks and DefensesabstractMore than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to${\$}226$with less than 120 MB spam traffic, increase an IoT text bill at a rate of${\$}5$per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Tian Xie 0001, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2024 | Reliability Engineering in a Time of Rapidly Converging TechnologiesabstractThe convergence of technologies is happening across various aspects, such as communication, computing, medicine, and transportation. The smartphone is a perfect example of convergence, packing features, such as a camera, GPS, artificial intelligence, and Internet connectivity into one sleek device. Autonomous driving is another good example. In a time of rapidly converging technologies, reliability engineering must take into account the potential for cyber threats, the need for cyber trust, the importance of cyber security, and the criticality of cyber resilience. In this way, reliability engineers can ensure the confidentiality, integrity, and availability of computer systems and networks in the face of evolving threats and changing technologies. In this article, we introduce the challenges and current progress of reliability engineering in emerging technologies, including practices and applications of cyber trust and security, AI-empowered autonomous driving systems, modern mobile networks, blockchains and distributed ledger technologies, prognostic and health management, integrated circuit and hardware, and enterprise cybersecurity and threat hunting. Shiuh-Pyng Shieh, Jeffrey M. Voas, Phillip A. Laplante, Jason W. Rupe, Christian K. Hansen, Yu-Sung Wu, Yi-Ting Chen 0001, Chi-Yu Li 0001, Kai-Chiang Wu |
IEEE Trans. Reliab. | 8 |
| 2023 | Congestion-Avoidance Adaptation for Edge-based UAV Video Frame DeliveryabstractMany critical UAV (Unmanned Aerial Vehicle) applications, such as military and infrastructure inspection, offload the detection of video frames captured at each UAV to an edge server, and then feedback next actions based on detection results to the UAV. Apparently, the response time, which is from the capture of a video frame to the receipt of the corresponding feedback at the UAV, needs to be as low as possible so that the UAV can be agile to take actions guided by the edge server. However, we experimentally discover that conventional video streaming methods that do not downgrade frame quality to hurt detection accuracy may lead to either long response time or very small processed FPS (Frame Per Second), which may cause missing information. We then propose a congestion-avoidance adaptation (CAA) method for the UAV video frame delivery to minimize the response time while maximizing the processed FPS. We prototype the CAA on a UAV platform; the evaluation result confirms its effectiveness by showing that it can keep response times low while maintaining high processed FPS. Meng-Shou Wu, Tan Tai Phan, Ping-Kuan Kao, Chi-Yu Li 0001 |
GLOBECOM | 4 |
| 2023 | MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked SystemsabstractNowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework,${{\sf MPKIX}}$, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509).${{\sf MPKIX}}$secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of${{\sf MPKIX}}$and implement an${{\sf MPKIX}}$prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of${{\sf MPKIX}}$with low overhead. Tian Xie 0001, Sihan Wang 0002, Jingwen Shi, Guan-Hua Tu, Chi-Yu Li 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2023 | Insecurity of Operational IMS Call Systems: Vulnerabilities, Attacks, and CountermeasuresabstractIMS (IP Multimedia Subsystem) is an essential 4G/5G component to offer multimedia services. It is used worldwide to support two call services: VoLTE (Voice over LTE) and VoWiFi (Voice over WiFi). In this study, it is shown that the signaling and voice sessions of VoWiFi can both be hijacked by a malicious adversary. By hijacking the signaling session, s(he) gains the ability to make ghost calls to launch stealthy DoS (Denial of Service) or caller-ID spoofing attacks against specific cellular users. Such attacks can be carried out without any malware or network information, and require only the victim’s phone number to be known. It is shown that phones vulnerable to the call DoS attacks can be detected at run time by exploiting a vulnerability of cellular network infrastructures referred to as call information leakage, which is exposed based on a machine learning method. Especially, the call DoS attacks can prevent victims from receiving incoming calls for up to 99.0% time without user awareness. Moreover, by hijacking the voice session, an adversary can launch stealthy free data transfer attacks based on phone numbers alone rather than IP addresses. The identified vulnerabilities/attacks are validated in the operational 4G networks of four top-tier carriers across Asia and North America with seven phone brands. The study concludes by presenting a suite of solutions to address them. Yu-Han Lu, Sandy H. Hsiao, Chi-Yu Li 0001, Yi-Chen Hsieh, Po-Yi Chou, Yao-Yu Li, Tian Xie 0001, Guan-Hua Tu |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | Prioritized Traffic Shaping for Low-latency MEC Flows in MEC-enabled Cellular NetworksabstractMulti-access edge computing (MEC) has been introduced as an enabler of low-latency performance in 4G/5G cellular networks. For the MEC-enabled cellular networks, several deployment options have been proposed by ETSI. One promising deployment option called Bump-in-the-wire does not require changes on the base station or the core network, so it has the advantage of easy deployment and low cost. However, the unchanged base station connecting to an MEC platform cannot differentiate MEC traffic from Internet traffic or prioritize it; its traffic congestion may thus cause the MEC traffic to suffer from high latency. In this work, we thus design a solution, designated PTS-MEC (Prioritized Traffic Shaping for MEC), to control the forwarding of downlink MEC/Internet traffic at the MEC and prioritize the MEC traffic based on a hierarchical MEC-prioritized fair service model. PTS-MEC alleviates the base station’s traffic congestion with a latency-aware service rate adaptor at run time by applying the service curve concept to delaying or/and skipping the Internet traffic. We prototype PTS-MEC on an open source MEC platform and evaluate it with congested cases. The evaluation result confirms the effectiveness of PTS-MEC; it can satisfy latency goals, e.g., 50 ms at the 90th percentile, within 3.70% error for MEC flows while fairly allocating remaining resource to non-MEC UEs. Po-Hao Huang, Fu-Cheng Hsieh, Wen-Jen Hsieh, Chi-Yu Li 0001, Ying-Dar Lin |
CCNC | 4 |
| 2022 | UAV-FAP: User Fairness-Driven Access Point on UAV for Wi-Fi NetworksabstractUnmanned aerial vehicle (UAV) has been an emerging technology used for various applications. Enabling wireless base station (e.g., Wi-Fi AP) on UAV can be one of promising UAV applications. In this work, we focus on a performance fairness issue on ground Wi-Fi users and aim to maximize the minimum throughput performance among them. To this end, we propose a solution, designated UAV-FAP (UAV with user Fairness-driven AP), to drive UAV-AP to reach a location that can offer max-min throughput performance. It employs a heuristic-based hierarchical search method to search for the target location efficiently. By conducting experiments on a real UAV-AP platform, we first study the issues of antenna pointing direction and vertical/horizontal UAV-AP placement, and then collect Wi-Fi throughput statistics for a trace-driven simulator in the evaluation. The evaluation result shows that UAV-FAP can outperform the default case, where the UAV-AP stays at the center of a serving area, by 2.0%-21.5% throughput gains; in some cases, it takes as small as only 7% of the moving distance needed by a fine-grained exhaustive search to reach target max-min locations. Yung-Chuan Wu, Hong-Rong Chang, Meng-Shou Wu, Chi-Yu Li 0001, Kuochen Wang |
CCNC | 4 |
| 2022 | Uncovering insecure designs of cellular emergency services (911)abstractCellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities. Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
MobiCom | 4 |
| 2022 | Modeling Control Delays for Edge-Enabled UAVs in Cellular NetworksabstractReal-time control solutions for unmanned aerial vehicles (UAVs) have attracted great interest in recent years. Most existing control methods use Wi-Fi technology. While Wi-Fi is inexpensive and easy to use, it has only a limited transmission range. Thus, 4G/5G cellular networks have been proposed as an alternative enabling technology. This study focuses on the problem of improving the appropriateness of the control commands sent by the ground control station (GCS) to the UAV over the control and nonpayload communication (CNPC) link of the UAV through the cellular network. To satisfy the low-latency requirement of the CNPC link, multiaccess edge computing (MEC) technology is leveraged to collocate the GCS and base station. The effectiveness of the proposed edge-based approach is demonstrated by conducting experiments on two LTE platforms with different MEC deployment methods. An edge-enabled UAV control solution is proposed in which each end-to-end control delay in the UAV-GCS system is estimated based on the preceding delay such that the location of the UAV at the moment it receives the control command from the GCS can be predicted in advance and taken into consideration by the GCS when formulating an appropriate control decision. To this end, an analytical modeling method is proposed for estimating the expected error range of each control delay based on a bimodal distribution approximation of the empirical control delays observed at the UAV. Finally, an event-driven simulator is developed to confirm the accuracy of the analytical predictions of the control delay based on the expected error between consecutive delays. Yu-Hsuan Wu, Chi-Yu Li 0001, Yi-Bing Lin, Kuochen Wang, Meng-Shou Wu |
IEEE Internet Things J. | 2 |
| 2022 | P4-TINS: P4-Driven Traffic Isolation for Network Slicing With Bandwidth Guarantee and ManagementabstractNetwork slicing is an essential technology for 5G mobile networks. It partitions network resource logically into multiple isolated slices, each of which can satisfy a suite of network requirements for one specific service. However, it cannot be fulfilled by the current SDN (Software-Defined Networks), since the conventional SDN data-plane technology, OpenFlow, is not flexible enough to offer fine-grained network resource control or queue/packet scheduling. It leads to many research studies developing corresponding solutions on programmable switches. In this work, we focus on the support of the bandwidth guarantee and management for network slices. Although several studies with the similar goal have been proposed, they do not consider interference among different flow types or use the built-in meter for easy deployment on COTS (Commercial Off-The-Shelf) P4 switches. To this end, we first conduct a case study to examine the interference cases. We then propose a solution, designated as P4-TINS (P4-driven Traffic Isolation for Network Slicing), to resolve the interference by isolating different types of traffic flows in priority queues and set the P4 switch’s bucket size based on the time granularity of its bandwidth management operation. It cannot only ensure the guaranteed bandwidth for each slice but also enable coexistent slices to fairly share residual bandwidth. We have confirmed its effectiveness experimentally based on our prototype over an ONOS (Open Network Operating System) controller and a COTS P4 switch. Chi-Yu Li 0001, Chien-Chao Tseng, Min-Zhi Hu |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and CountermeasuresabstractNowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards. Yiwen Hu 0002, Sihan Wang 0002, Guan-Hua Tu, Li Xiao 0001, Tian Xie 0001, Chi-Yu Li 0001 |
CODASPY | 7 |
| 2021 | An Experience Driven Design for IEEE 802.11ac Rate Adaptation based on Reinforcement LearningabstractThe IEEE 802.11ac supports gigabit speeds by extending 802.11n air-interface features and increases the number of rate options by more than two times. Enabling so many rate options can be a challenge to rate adaptation (RA) solutions. Particularly, they need to adapt rates to various fast-changing channels; they would suffer without scalability. In this work, we identify three limitations of current 802.11ac RAs on commodity network interface cards (NICs): no joint rate and bandwidth adaptation, lack of scalability, and no online learning capability. To address the limitations, we apply deep reinforcement learning (DRL) into designing a scalable, intelligent RA, designated as experience driven rate adaptation (EDRA). DRL enables the online learning capability of EDRA, which not only automatically identifies useful correlations between important factors and performance for the rate search, but also derives low-overhead avenues to approach highest-goodput (HG) rates by learning from experience. It can make EDRA scalable to timely locate HG rates among many rate options over time. We implement and evaluate EDRA using the Intel Wi-Fi driver and Google TensorFlow on Intel 802.11ac NICs. The evaluation result shows that EDRA can outperform the Intel and Linux default RAs by up to 821.4% and 242.8%, respectively, in various cases. Syuan-Cheng Chen, Chi-Yu Li 0001, Chui-Hao Chiu |
INFOCOM | 2 |
| 2021 | Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresabstractMore than 150 cellular networks worldwide have rolled out massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover five vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices and launch data/text spamming attacks against them. We experimentally validate these vulnerabilities and attacks with three major U.S. IoT carriers. The attack evaluation result shows that the adversary can raise an IoT data bill by up to $226 with less than 120 MB spam traffic and increase an IoT text bill at a rate of $5 per second; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions. Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001 |
MobiCom | 5 |
| 2021 | How Can IoT Services Pose New Security Threats In Operational Cellular Networks?abstractCarriers are rolling out Internet of Things (IoT) services including various IoT devices and use scenarios. Compared with conventional non-IoT devices such as smartphones and tablets, IoT devices have limited network capabilities (e.g., low rates) and specific use scenarios (e.g., inside vehicles only). These specialized use scenarios lead to carries often offering cheaper device access fees for IoT devices. However, the aforementioned disparity of service charging between IoT and non-IoT devices may lead to security issues. In this work, we conduct the first empirical security study on cellular IoT service charging over two major US carriers and make three major contributions. First, we discover four security vulnerabilities and analyze their root causes, which help us identify two significant security threats, IoT masquerading and IoT use scenario abuse. Second, we devise three proof-of-concept attacks and assess their real-world impact. We determine that they can be exploited to allow adversaries to pay 43.75-80.00 percent less for cellular data services. Third, we analyze the challenges in addressing these vulnerabilities and develop an anti-abuse solution to mitigate attack incentives. The solution is standard-compliant and can be used immediately in practice. Our prototype and evaluation confirm its effectiveness. Tian Xie 0001, Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | The Untold Secrets of WiFi-Calling Services: Vulnerabilities, Attacks, and CountermeasuresabstractSince 2016, all of four major U.S. operators have rolled out Wi-Fi calling services. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrusted Wi-Fi networks and the Internet. This exposure to insecure networks can cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA, IPSec, etc. However, are they sufficient to secure Wi-Fi calling services? Unfortunately, our study yields a negative answer. We conduct the first security study on the operational Wi-Fi calling services in three major U.S. operators networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof and uncover three vulnerabilities. By exploiting the vulnerabilities, we devise two proof-of-concept attacks: telephony harassment or denial of voice service and user privacy leakage; both of them can bypass the existing security defenses. We have confirmed their feasibility using real-world experiments, as well as assessed their potential damages and proposed a solution to address all identified vulnerabilities. Tian Xie 0001, Guan-Hua Tu, Bangjie Yin, Chi-Yu Li 0001, Chunyi Peng 0001, Mi Zhang 0002, Hui Liu 0031, Xiaoming Liu 0002 |
IEEE Trans. Mob. Comput. | 4 |
| 2021 | Privacy Leakage and Protection of InputConnection Interface in Android
Chi-Yu Li 0001, Hsin-Yi Wang, Wei-Ching Wang, Chun-Ying Huang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | WBF-PS: WiGig Beam Fingerprinting for UAV Positioning System in GPS-denied EnvironmentsabstractUnmanned aerial vehicles (UAVs) are being investigated to substitute for labor in many indoor applications, e.g., asset tracking and surveillance, where the global positioning system (GPS) is not available. Also, emerging autonomous UAVs are expected to land in indoor parking aprons automatically. Such GPS-denied environments require alternative non-GPS positioning methods. Although there have been some vision-based solutions for UAVs, they perform poorly in the scenes with bad illumination conditions or estimate only relative locations but not global positions. Other common indoor localization methods do not cover UAV factors, such as low power and flying behaviors. To this end, we propose a practical non-GPS positioning system for UAVs, named WBF-PS (WiGig Beam Fingerprinting based Positioning System), using low-power, off-the-shelf WiGig devices. We formulate a 3-dimensional beam fingerprint for the positioning by leveraging the diversity of available transmitter/receiver beams and the link quality. To augment the positioning accuracy, we not only use a weighted k-nearest neighbors algorithm to overcome partial fingerprint inaccuracy but also apply the particle filtering technique into considering the UAV motion. We prototype and evaluate WBF-PS on a UAV platform. The result shows that the positioning errors at the 90th percentile are below 1 m in various cases. Pei-Yuan Hong, Chi-Yu Li 0001, Hong-Rong Chang, YuanHao Hsueh, Kuochen Wang |
INFOCOM | 2 |
| 2020 | Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureabstractIMS (IP Multimedia Subsystem) is an essential framework for providing 4G/5G multimedia services. It has been deployed worldwide to support two call services: VoLTE (Voice over LTE) and VoWi-Fi (Voice over Wi-Fi). VoWi-Fi enables telephony calls over the Wi-Fi network to complement VoLTE. In this work, we uncover that the VoWi-Fi signaling session can be hijacked to maliciously manipulate the IMS call operation. An adversary can easily make ghost calls to launch a stealthy call DoS (Denial of Service) attack against specific cellular users. Only phone numbers, but not any malware or network information, are required from the victims. This sophisticated attack harnesses a design defect of the IMS call state machine, but not simply flooding or a crash trigger. To stealthily detect attackable phones at run time, we exploit a vulnerability of the 4G network infrastructure, call information leakage, which we explore using machine learning. We validate these vulnerabilities in operational 4G networks of 4 top-tier carriers across Asia and North America countries with 7 phone brands. Our result shows that the call DoS attack can prevent the victims from receiving incoming calls up to 99.0% time without user awareness. We finally propose and evaluate recommended solutions. Yu-Han Lu, Chi-Yu Li 0001, Yao-Yu Li, Sandy H. Hsiao, Tian Xie 0001, Guan-Hua Tu, Wei-Xun Chen |
MobiCom | 2 |
| 2020 | SecWIR: securing smart home IoT communications via wi-fi routers with embedded intelligenceabstractSmart home Wi-Fi IoT devices are prevalent nowadays and potentially bring significant improvements to daily life. However, they pose an attractive target for adversaries seeking to launch attacks. Since the secure IoT communications are the foundation of secure IoT devices, this study commences by examining the extent to which mainstream security protocols are supported by 40 of the best selling Wi-Fi smart home IoT devices on the Amazon platform. It is shown that 29 of these devices have either no security protocols deployed, or have problematic security protocol implementations. Seemingly, these vulnerabilities can be easily fixed by installing security patches. However, many IoT devices lack the requisite software/hardware resources to do so. To address this problem, the present study proposes a SecWIR (Secure Wi-Fi IoT communication Router) framework designed for implementation on top of the users' existing home Wi-Fi routers to provide IoT devices with a secure IoT communication capability. However, it is way challenging for SecWIR to function effectively on all home Wi-Fi routers since some routers are resource-constrained. Thus, several novel techniques for resolving this implementation issue are additionally proposed. The experimental results show that SecWIR performs well on a variety of commercial off-the-shelf (COTS) Wi-Fi routers at the expense of only a small reduction in the non-IoT data service throughput (less than 8%), and small increases in the CPU usage (4.5%~7%), RAM usage (1.9 MB~2.2 MB), and the IoT device access delay (24 ms~154 ms) while securing 250 IoT devices. Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Mi Zhang 0002 |
MobiSys | 3 |
| 2019 | Mobility Support for Networks on Trains Using Commercial Off-the-shelf RoutersabstractThe following topics are dealt with: telecommunication traffic; software defined networking; learning (artificial intelligence); resource allocation; virtualisation; quality of service; cloud computing; computer network security; Internet; mobile computing. Sandy H. Hsiao, Hong-Rong Chang, Yu-Han Lu, Chi-Yu Li 0001 |
APNOMS | 4 |
| 2018 | V2PSense: Enabling Cellular-Based V2P Collision Warning Service through Mobile SensingabstractThe C-V2X (Cellular Vehicle-to-Everything) technology is developing in full swing. One of its mainstream services can be the Vehicle-to- Pedestrian (V2P) service. It can protect pedestrians who are mostly vulnerable on the road. In this work, we seek to enable a V2P service that can identify which pedestrians may be nearby a dangerous driving event and then notify them of warning messages. To enable this V2P service, there are two major challenges. First, a low-latency V2P message transport is required for this infrastructure-based service. Second, the pedestrian's smartphone requires an energy- efficient outdoor positioning method instead of power-hungry GPS due to its limited battery life. We thus propose a novel solution, V2PSense, which trades off positioning precision for energy savings while achieving low-latency message transport with LTE high-priority bearers. It does a coarse-grained positioning by leveraging intermittent GPS information and mobile sensing data, which includes step count from the pedometer and cellular signal strength changes. Though the V2PSense's positioning is not as precise as the GPS, it can still ensure that all the pedestrians nearby dangerous spots can be notified. Our results show that it can achieve the average precision ratio 92.6% for estimating where the pedestrian is while saving 20.8% energy, compared with the GPS always-on case. Chi-Yu Li 0001, Giovanni Salinas, Po-Hao Huang, Guan-Hua Tu, Guo-Huang Hsu, Tien-Yuan Hsieh |
ICC | 1 |
| 2018 | How Voice Service Threatens Cellular-Connected IoT Devices in the Operational 4G LTE NetworksabstractLTE networks are rolling out cellular Internet-of- Things (IoT) services. Cellular-connected IoT devices are becoming increasingly popular and the number is forecasted to grow almost fourfold from 2015 to 2021. Since they share the same infrastructure with non-IoT devices such as smartphones, we may expect no big differences between them in terms of voice/data service accounting/charging (e.g., paying for what you get) and security risks. However, our study shows that cellular IoT users may pay more than what they get, as well as are vulnerable to voice signaling spams and thus suffer from an overcharging attack which leads to financial loss or denial of service. We validate our proof-of- concept attack in a major U.S. cellular network operator which takes higher than 35% market share. We finally propose a solution to address the identified security vulnerabilities. Tian Xie 0001, Chi-Yu Li 0001, Jiliang Tang, Guan-Hua Tu |
ICC | 2 |
| 2018 | A Fast Converging Mechanism for Load Balancing among SDN Multiple ControllersabstractLoad balancing among multiple controllers is a critical issue in the software-defined networking (SDN), since traffic dynamics prevent control-plane loads from being evenly distributed among controllers. Load imbalance may cause some controllers to be overloaded while the other controllers are still underutilized. Though there have been several proposed solutions, theydo not consider the convergence time of load balancing. We thus propose a fast-converging loadbalancing (FCLB) mechanism that seeks to achieve fast convergence for balancing loads (i.e., assigning switches) among the SDN controllers. Fast convergence can rapidly release controllersfrom being overloaded, thereby shortly recovering network performance and preventing some unanticipated results (e.g., controller crash). Searching for the optimal solution from a large set of switch-controller combinations can lead to a large delay, which can aggravate negative impacts from overloading. We thus leverage the genetic algorithm to lind a near-optimal solutionOur simulation results show that FCLB has at least 20.7% faster convergence time than the other mechanisms while achieving better load balancing performance. Chi-Yu Li 0001, Kuochen Wang |
ISCC | 2 |
| 2017 | ReSDN: A lightweight solution for data-plane state recovery in software-defined networksabstractSoftware-Defined Networking (SDN) benefits from the development flexibility of control-plane applications (SDN-Apps), which allows third parties to make contributions. Such flexibility may expose SDN networks to security threats, since SDN-Apps may be malicious or prone to implementation bugs. These buggy/malicious SDN-Apps may contaminate the data plane with abnormal network actions, which may not be prevented before they are committed to the data plane. This contamination may lead to network crash or poor network performance. We thus present ReSDN, a lightweight solution for data-plane state recovery, to recover an SDN data plane from a contaminated state. It requires neither switch modification nor the intervention of SDN-Apps, both of which current recovery solutions rely on. It leverages the concept of FP-tree (Frequent Pattern tree) to maintain the dependency of event transactions and network actions to achieve correct recovery. Our evaluations validate the viability of our ReSDN design, and show that it can recover more than twice as fast as the other type of recovery approach, rollback recovery. Chi-Yu Li 0001, Kuochen Wang |
ICC | 2 |
| 2017 | Enabling seamless WiGig/WiFi handovers in tri-band wireless systemsabstractWiGig enables wireless multi-gigabit communication over 60GHz band. However, its usage scenarios may be constrained by two major limitations: line-of-sight propagation and very short transmission range. We seek to boost the WiGig's usability by using WiFi to complement its limitations in tri-band (2.4/5/60GHz) wireless systems. Our goal is to let a tri-band client have multimedia services at the WiGig's very high speed without any hassle. When the WiGig link is down or performs bad, not only can the client temporarily handover to WiFi without service interruption, but its ongoing multimedia services can also adapt to the WiFi's slower link. Though the IEEE 802.11ad standard has proposed an FST (Fast Session Transfer) mechanism to support handover operations at the link layer, it does not satisfy our goal due to two reasons. First, it does not specify when to perform WiGig/WiFi handovers. Second, it is not application-aware to achieve the service adaptation. To this end, we design and implement an application-aware, seamless WiGig/WiFi handover solution above the network layer. It ensures timely handover trigger for the WiGig's abrupt link interruption, keeps service continuity during handovers, and adapts multimedia service qualities to different WiGig/WiFi links. Our demo confirms its viability. We show that a video streaming service at the client is not interrupted during WiGig/WiFi handovers, which are triggered by mobility or the WiGig's signal blockage, but smoothly switches between different resolutions according to different links. Yao-Yu Li, Chi-Yu Li 0001, Chia-Jui Yeh, Kuochen Wang |
ICNP | 2 |
| 2016 | New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksabstractSMS (Short Messaging Service) is a text messaging service for mobile users to exchange short text messages. It is also widely used to provide SMS-powered services (e.g., mobile banking). With the rapid deployment of all-IP 4G mobile networks, the underlying technology of SMS evolves from the legacy circuit-switched network to the IMS (IP Multimedia Subsystem) system over packet-switched network. In this work, we study the insecurity of the IMS-based SMS. We uncover its security vulnerabilities and exploit them to devise four SMS attacks: silent SMS abuse, SMS spoofing, SMS client DoS, and SMS spamming. We further discover that those SMS threats can propagate towards SMS-powered services, thereby leading to three malicious attacks: social network account hijacking, unauthorized donation, and unauthorized subscription. Our analysis reveals that the problems stem from the loose security regulations among mobile phones, carrier networks, and SMS-powered services. We finally propose remedies to the identified security issues. Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001, Yuanjie Li, Songwu Lu |
CCS | 2 |
| 2016 | An Energy Efficiency Perspective on Rate Adaptation for 802.11n NICabstractRate adaptation (RA) has been traditionally used to achieve high goodput. In this work, we design RA for 802.11n NICs from an energy-efficiency perspective. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We then propose EERA and EERA+, two energy-based RA schemes that trade off goodput for energy savings at NICs. EERA applies multidimensional ternary search and simultaneous pruning to speed up its runtime convergence in single-client operations, and uses fair airtime sharing to handle multiple-client operations. EERA+ further searches for multiple, staged rates to yield more energy savings over EERA. Our experiments have confirmed their effectiveness in various scenarios. Chi-Yu Li 0001, Chunyi Peng 0001, Peng Cheng 0005, Songwu Lu, Xinbing Wang, Fengyuan Ren, Tao Wang 0004 |
IEEE Trans. Mob. Comput. | 1 |
| 2016 | Detecting Problematic Control-Plane Protocol Interactions in Mobile NetworksabstractThe control-plane protocols in 3G/4G mobile networks communicate with each other, and provide a rich set of control functions, such as radio resource control, mobility support, connectivity management, to name a few. Despite their significance, the problem of verifying protocol correctness remains largely unaddressed. In this paper, we examine control-plane protocol interactions in mobile networks. We propose CNetVerifier, a two-phase signaling diagnosis tool to detect problematic interactions in both design and practice. CNetVerifier first performs protocol screening based on 3GPP standards via domain-specific model checking, and then conducts phone-based empirical validation in operational 3G/4G networks. With CNetVerifier, we have uncovered seven types of troublesome interactions, along three dimensions of cross (protocol) layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. Some are caused by necessary yet problematic cooperation (i.e., protocol interactions are needed but they misbehave), whereas others are due to independent yet unnecessary coupled operations (i.e., protocols interactions are not required but actually coupled). These instances span both design defects in 3GPP standards and operational slips by carriers and vendors. They all result in performance penalties or functional incorrectness. We deduce root causes, present empirical results, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
IEEE/ACM Trans. Netw. | 4 |
| 2015 | Insecurity of Voice Solution VoLTE in LTE Mobile NetworksabstractVoLTE (Voice-over-LTE) is the designated voice solution to the LTE mobile network, and its worldwide deployment is underway. It reshapes call services from the traditional circuit-switched telecom telephony to the packet-switched Internet VoIP. In this work, we conduct the first study on VoLTE security before its full rollout. We discover several vulnerabilities in both its control-plane and data-plane functions, which can be exploited to disrupt both data and voice in operational networks. In particular, we find that the adversary can easily gain free data access, shut down continuing data access, or subdue an ongoing call, etc. We validate these proof-of-concept attacks using commodity smartphones (rooted and unrooted) in two Tier-1 US mobile carriers. Our analysis reveals that, the problems stem from both the device and the network. The device OS and chipset fail to prohibit non-VoLTE apps from accessing and injecting packets into VoLTE control and data planes. The network infrastructure also lacks proper access control and runtime check. Chi-Yu Li 0001, Guan-Hua Tu, Chunyi Peng 0001, Zengwen Yuan, Yuanjie Li, Songwu Lu, Xinbing Wang |
CCS | 1 |
| 2015 | Latency-aware rate adaptation in 802.11n home networksabstractLatency-sensitive applications (e.g., wireless gaming and TV remote play) are increasingly popular in home WiFi networks. Such millisecond-level latency requirements call for new fine-grained approaches at the link layer. In this paper, we show that current solutions work well for throughput but not for latency due to the long tail of the packet delay distribution. We thus propose LLRA, a new latency-aware rate adaptation scheme that reduces the tail latency for delay-sensitive applications. LLRA takes concerted design in rate control, frame aggregation scheduling and software/hardware retransmission dispatching. Our implementation and evaluation confirm the viability of LLRA in 802.11n home networks. Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang, Ranveer Chandra |
INFOCOM | 1 |
| 2014 | Real Threats to Your Data Bills: Security Loopholes and Defenses in Mobile Data ChargingabstractSecure mobile data charging (MDC) is critical to cellular network operations. It must charge the right user for the right volume that (s)he authorizes to consume (i.e., requirements of authentication, authorization, and accounting (AAA)). In this work, we conduct security analysis of the MDC system in cellular networks. We find that all three can be breached in both design and practice, and identify three concrete vulnerabilities: authentication bypass, authorization fraud and accounting volume inaccuracy. The root causes lie in technology fundamentals of cellular networks and the Internet IP design, as well as imprudent implementations. We devise three showcase attacks to demonstrate that, even simple attacks can easily penetrate the operational 3G/4G cellular networks. We further propose and evaluate defense solutions. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu |
CCS | 2 |
| 2014 | Control-plane protocol interactions in cellular networksabstractControl-plane protocols are complex in cellular networks. They communicate with one another along three dimensions of cross layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. In this work, we propose signaling diagnosis tools and uncover six instances of problematic interactions. Such control-plane issues span both design defects in the 3GPP standards and operational slips by carriers. They are more damaging than data-plane failures. In the worst-case scenario, users may be out of service in 4G, or get stuck in 3G. We deduce root causes, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
SIGCOMM | 4 |
| 2013 | CMES: Collaborative Energy Save for MIMO 802.11 wireless networksabstractThis work experimentally studies the energy consumption of multiple-antenna MIMO 802.11 devices. Our measurements reveal an increase in power consumption and speed with the number of antennas. State of the art proposals have limitations to save energy in MIMO 802.11 networks. First, they focus on either maximizing speed or minimizing power consumption. Second, they only seek to minimize energy for the receiver side of mobile devices. As a result, they present limitations to utilize MIMO speed gains and to save energy in MIMO 802.11 infrastructure. To this end, we design Collaborative MIMO Energy Save (CMES), which seeks to identify the transmitter-receiver most energy efficient antenna setting, at runtime. Our experiments with commodity MIMO 802.11n testbeds confirm that CMES can provide energy savings in real scenarios. Ioannis Pefkianakis, Chi-Yu Li 0001, Chunyi Peng 0001, Suk-Bok Lee, Songwu Lu |
ICNP | 2 |
| 2013 | How voice calls affect data in operational LTE networksabstractBoth voice and data are indispensable services in current cellular networks. In this work, we study the inter-play of voice and data in operational LTE networks. We assess how the popular CSFB-based voice service affects the IP-based data sessions in 4G LTE networks, and visa versa. Our findings reveal that the interference between them is mutual. On one hand, voice calls may incur throughput drop, lost 4G connectivity, and application aborts for data sessions. One the other hand, users may miss incoming voice calls when turning on data access. The fundamental problem is that, signaling and control for circuit-switched voice and packet-switched data have dependency and coupling effect via the LTE phone client. We further propose fixes to the identified issues. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 4 |
| 2013 | Accounting for roaming users on mobile data access: issues and root causesabstractIn this paper, we study how mobility affects mobile data accounting, which records the usage volume for each roaming user. We find out that, current 2G/3G/4G systems have well-tested mobility support solutions and generally work well. However, under certain biased, less common yet possible scenarios, accounting gap between the operator's log and the user's observation indeed exists. The gap can be as large as 69.6% in our road tests. We further discover that the root causes are diversified. In addition to the no-signal case reported in the prior work [23], they also include handoffs, as well as insufficient coverage of hybrid 2G/3G/4G systems. Inter-system handoffs (that migrate user devices between radio access technologies of 2G, 3G, and 4G) may incur non-negligible accounting discrepancy. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Tao Wang 0004, Songwu Lu |
MobiSys | 3 |
| 2012 | Mobile data charging: new attacks and countermeasuresabstract3G/4G cellular networks adopt usage-based charging. Mobile users are billed based on the traffic volume when accessing data service. In this work, we assess both this metered accounting architecture and application-specific charging policies by operators from the security perspective. We have identified loopholes in both, and discovered two effective attacks exploiting the loopholes. The "toll-free-data-access-attack" enables the attacker to access any data service for free. The "stealth-spam-attack" incurs any large traffic volume to the victim, while the victim may not be even aware of such spam traffic.Our experiments on two operational 3G networks have confirmed the feasibility and simplicity of such attacks. We also propose defense remedies. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu, Lixia Zhang 0001 |
CCS | 2 |
| 2012 | A multimedia service migration protocol for single user multiple devicesabstractThis paper describes a new protocol SMP, which supports multimedia transfer for single-user, multiple-device scenarios. Through its novel naming and control/data plane designs, SMP is able to retain the current client and server protocol operations while placing new functions at the proxy. Our initial evaluation has confirmed its viability. Chi-Yu Li 0001, Ioannis Pefkianakis, Bojie Li, Chenghui Peng, Songwu Lu |
ICC | 1 |
| 2012 | Energy-based rate adaptation for 802.11nabstractRate adaptation (RA) has been used to achieve high goodput. In this work, we explore to use RA for energy efficiency in 802.11n NICs. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We propose EERA, an energy-based RA solution that trades off goodput for energy savings at NICs. Our experiments have confirmed its energy savings at NICs while keeping the cost at the device level and across clients acceptable. Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang |
MobiCom | 1 |
| 2012 | Can we pay for what we get in 3G data access?abstractData-plan subscribers are charged based on the used traffic volume in 3G/4G cellular networks. This usage-based charging system has been operational and received general success. In this work, we conduct experiments to critically assess both this usage-based accounting architecture and application-specific charging policies by operators. Our evaluation compares the network-recorded volume with the delivered traffic at the end device. We have found that, both generally work in common scenarios but may go wrong in the extreme cases: We are charged for what we never get, and we can get what we want for free. In one extreme case, we are charged for at least three hours and 450MB or more data despite receiving no single bit. In another extreme case, we are able to transfer 200MB or any amount we specify for free. The root causes lie in lack of both coordination between the charging system and the end device, and prudent policy enforcement by certain operators. We propose immediate fixes and discuss possible future directions. Chunyi Peng 0001, Guan-Hua Tu, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 3 |
| 2011 | What is wrong/right with IEEE 802.11n Spatial Multiplexing Power Save feature?abstractThe IEEE 802.11n standard has proposed a new Spatial Multiplexing Power Save (SMPS) feature, which allows for a station to retain one active receive chain, to mitigate MIMO circuitry power consumption. But does it work in all cases? Our experiments reveal that SMPS may not always save power compared with multiple active chains at the receiver. Even when it does, it may be proven more energy hungry. In this work, we seek to uncover the “good”, the “bad” and the “ugly” of SMPS using real experiments. We further devise a MIMO Receiver Energy Save (MRES) algorithm, which seeks to identify and set the most energy-efficient receive chain setting, by using a novel, low-overhead sampling scheme. Our prototype experiments show that, MRES outperforms SMPS with energy savings up to 37%. Ioannis Pefkianakis, Chi-Yu Li 0001, Songwu Lu |
ICNP | 2 |
| 2011 | Release-time-based multi-channel MAC protocol for wireless mesh networks
Andy An-Kai Jeng, Rong-Hong Jan, Chi-Yu Li 0001, Chien Chen |
Comput. Networks | 3 |