Kai Wang 0073

dblp:78/2022-73 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0001-6391-3286ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 8 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities
Shilin Xiao, Kai Wang 0073, Peiwang Wang, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001
NDSS4
2026 VoltSiren: Exploiting Power Supply Vulnerabilities to Control IoT Devices
abstract
This paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing, actuating, and communicating. Particularly, we discover a vulnerability in power supply modules and propose VoltSiren attacks. To launch a VoltSiren attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Consequently, VoltSiren attacks can cause sensor measurements irrelevant to reality, maneuver actuators in a way disregarding the desired command, or disrupt communications. To understand VoltSiren, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensors, actuators, or communication modules. Based on these findings, we implement and validate VoltSiren on off-the-shelf products: six sensors, three actuators, and two communication modules, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The root cause of this vulnerability lies in the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks.
Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Ruochen Zhou, Kaixiang Zhang 0002, Wenyuan Xu 0001
IEEE Internet Things J.1
2025 PowerRadio: Manipulate Sensor Measurement via Power GND Radiation
Xiaoyu Ji 0001, Yancheng Jiang, Kai Wang 0073, Chenren Xu, Wenyuan Xu 0001
NDSS4
2024 Marionette: Manipulate Your Touchscreen via a Charging Cable
abstract
The security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. This paper presentsMarionette, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables and can manipulate the victim's devices with undesired consequences, e.g., establishing malicious Bluetooth connections. Our study provides a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various USB data blockers and power adapters. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affecting the touch measurement mechanism and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks, i.e., injection, alteration, and Denial-of-Service, and the evaluation of 12 commercial electronics, 6 power adapters, and 13 charging cables demonstrate the feasibility ofMarionette.
Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Analyzing and Defending GhostTouch Attack Against Capacitive Touchscreens
abstract
Capacitive touchscreens have become the primary human-machine interface for personal devices such as smartphones and tablets. In this paper, we presentGhostTouch, the first active contactless attack against capacitive touchscreens.GhostTouchuses electromagnetic interference (EMI) to inject fake touch points into a touchscreen without the requirement to physically touch it. By tuning the parameters of the electromagnetic signal and adjusting the antenna, we can inject two types of basic touch events, taps and swipes, into targeted locations of the touchscreen and control them to manipulate the underlying device. We successfully launch theGhostTouchattacks on nine smartphone models. We can inject targeted taps continuously with a standard deviation of as low as$14.6 \times 19.2$pixels from the target area, and a distance of up to$40mm$. We show the real-world impact of theGhostTouchattacks in a few proof-of-concept scenarios, including pressing the button, answering an eavesdropping phone call, and swiping up to unlock. Finally, we propose touchscreen reinforcement and attack detection mechanisms to mitigate the threat ofGhostTouchattack.
Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.1
2023 Volttack: Control IoT Devices by Manipulating Power Supply Voltage
abstract
This paper analyzes the security of Internet of Things (IoT) devices from the perspective of sensing and actuating. Particularly, we discover a vulnerability in power supply modules and propose Volttack attacks. To launch a Volttack attack, attackers may compromise the power source and inject malicious signals through the power supply module, which is indispensable in most devices. Eventually, Volttack attacks may cause the sensor measurement irrelevant to reality or maneuver the actuator in a way disregarding the desired command. To understand Volttack, we systematically analyze the underlying principle of power supply signals affecting the electronic components, which are building blocks to constitute the sensor or actuator modules. Derived from these findings, we implement and validate Volttack on off-the-shelf products: 6 sensors and 3 actuators, which are used in applications ranging from automobile braking systems, industrial process control to robotic arms. The consequences of manipulating the sensor measurement or actuation include doubled car braking distance and a natural gas leak. The root cause of such a vulnerability stems from the common belief that noises from the power line are unintentional, and our work aims to call for attention to enhancing the security of power supply modules and adding countermeasures to mitigate the attacks.
Kai Wang 0073, Shilin Xiao, Xiaoyu Ji 0001, Chen Yan 0001, Chaohao Li, Wenyuan Xu 0001
SP1
2022 WIGHT: Wired Ghost Touch Attack on Capacitive Touchscreens
abstract
The security of capacitive touchscreens is crucial since they have become the primary human-machine interface on smart devices. To the best of our knowledge, this paper presents WIGHT, the first wired attack that creates ghost touches on capacitive touchscreens via charging cables, and can manipulate the victim devices with undesired consequences, e.g., allowing malicious Bluetooth connections, accepting files with viruses, etc. Our study calls for attention to a new threat vector against touchscreens that only requires connecting to a malicious charging port, which could be a public charging station, and is effective across various power adapters and even USB data blockers. Despite the fact that smartphones employ abundant noise reduction and voltage management techniques, we manage to inject carefully crafted signals that can induce ghost touches within a chosen range. The underlying principle is to inject common-mode noises over the power line to avoid being effectively filtered yet affect the touch measurement mechanism, and synchronize the malicious noise with the screen measurement scanning cycles to place the ghost touches at target locations. We achieve three types of attacks: injection attacks that create ghost touches without users touching the screen, alteration attacks that change the detected legitimate touch position, and Denial-of-Service attacks that prevent the device from identifying legitimate touches. Our evaluation on 6 smartphones, 1 tablet, 2 standalone touchscreen panels, 6 power adapters, and 13 charging cables demonstrates the feasibility of all three type attacks.
Xiaoyu Ji 0001, Kai Wang 0073, Chen Yan 0001, Richard Mitev, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
SP3
2022 GhostTouch: Targeted Attacks on Touchscreens without Physical Touch
Kai Wang 0073, Richard Mitev, Chen Yan 0001, Xiaoyu Ji 0001, Ahmad-Reza Sadeghi, Wenyuan Xu 0001
USENIX Security Symposium1
2021 Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer Vision
abstract
Autonomous vehicles increasingly exploit computer-vision-based object detection systems to perceive environments and make critical driving decisions. To increase the quality of images, image stabilizers with inertial sensors are added to alleviate image blurring caused by camera jitters. However, such a trend opens a new attack surface. This paper identifies a system-level vulnerability resulting from the combination of the emerging image stabilizer hardware susceptible to acoustic manipulation and the object detection algorithms subject to adversarial examples. By emitting deliberately designed acoustic signals, an adversary can control the output of an inertial sensor, which triggers unnecessary motion compensation and results in a blurred image, even if the camera is stable. The blurred images can then induce object misclassification affecting safety-critical decision making. We model the feasibility of such acoustic manipulation and design an attack framework that can accomplish three types of attacks, i.e., hiding, creating, and altering objects. Evaluation results demonstrate the effectiveness of our attacks against four academic object detectors (YOLO V3/V4/V5 and Fast R-CNN), and one commercial detector (Apollo). We further introduce the concept of AMpLe attacks, a new class of system-level security vulnerabilities resulting from a combination of adversarial machine learning and physics-based injection of information-carrying signals into hardware.
Xiaoyu Ji 0001, Yushi Cheng, Kai Wang 0073, Chen Yan 0001, Wenyuan Xu 0001, Kevin Fu
SP4
2021 SenCS: Enabling Real-time Indoor Proximity Verification via Contextual Similarity
abstract
Indoor proximity verification has become an increasingly useful primitive for the scenarios where access is granted to the previously unknown users when they enter a given area (e.g., a hotel room). Existing solutions either rely on homogeneous sensing modalities shared by two parties or require additional human interactions. In this article, we propose a context-based indoor proximity verification scheme, called SenCS, to enable real-time autonomous access for mobile devices, utilizing the available heterogeneous sensors at the user side and at the room side. The intuition is that only when the user is within a room can sensors from both sides observe the same events in the room. Yet such a solution is challenging, because the events may not provide enough entropy within the required time and the heterogeneity in sensing modalities may not always agree on the sensed events. To overcome the challenges, we exploit the time intervals between successively human actions to create heterogeneous contextual fingerprints (HCF) at a millisecond level. By comparing the contextual similarity between the HCF s from both the room and user sides, SenCS accomplishes the indoor proximity verification. Through proof-of-concept implementation and evaluations on 30 participants, SenCS achieves an accuracy of 99.77% and an equal error rate (EER) of 0.23% across various hardware configurations.
Chaohao Li, Xiaoyu Ji 0001, Bin Wang 0062, Kai Wang 0073, Wenyuan Xu 0001
ACM Trans. Sens. Networks4