EDBT 2026 Demo / reviewers in the wild / expert
Hongbo Liu 0002
dblp:78/6365-2
· DBLP profile ↗
89ranked-venue papers
17as first author
41since 2021 · last 2026
0000-0003-1162-839XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 63 · 12 first-author · 28 since 2021Systems, architecture and hardware · 12 · 1 first-author · 6 since 2021Security and privacy · 6 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Distance-Invariant Radio Frequency Fingerprinting via Augmented Unsupervised LearningabstractRadio Frequency Fingerprinting (RFF) exploits inherent hardware-level imperfections of wireless transmitters as unclonable identifiers for device identification. These unique signatures, concealed in transmitted signals, inevitably experience complex distortions during wireless propagation (i.e., coupled with ambient noise and channel fading), making it extremely challenging for reliable extraction. Despite substantial research efforts dedicated to advancing effective fingerprint extraction techniques, current approaches still struggle in handling fingerprint robustness under distance variations, leading to severe SNR fluctuations and complex multipath effects. To address this gap, we propose the first unsupervised framework for distance-invariant radio frequency fingerprinting, eliminating dependence on labeled target domain data. Specifically, we first preprocess raw RF samples by confining them within a specified variation range and filtering noisy high-frequency components while avoiding aliasing. For source domain data, we then propose a set of physics-inspired data augmentation techniques designed to emulate realistic wireless signal propagation effects. Building on this, we introduce a dual alignment contrastive learning method to explicitly decouple identity-discriminative features, ensuring the model focuses on device-specific traits. Furthermore, we incorporate a pseudo-labeling-based domain adaptation module to refine the model for the unlabeled target domain, enhancing its generalization to unseen distances. Extensive experiments on public datasets show that our method achieves the identification accuracy outperforming state-of-the-art approaches by 40%, while maintaining computational efficiency suitable for edge deployment. Shiyue Huang, Yuchen Su 0001, Hongbo Liu 0002, Zikang Ding, Xuewan He, Yanzhi Ren, Haitao Jia |
AAAI | 3 |
| 2026 | Privacy-Preserving Similarity Queries for Outsourced Trajectory DataabstractTrajectory similarity query can retrieve a set of trajectories similar to the user's query from the database and is widely used in various fields such as travel recommendations. Previous studies mainly focused on accelerating trajectory similarity search in plaintext. However, with the increasing concern about privacy protection in outsourced cloud environments, conducting trajectory similarity queries while preserving privacy becomes a significant challenge. This paper proposes efficient privacy-preserving top-$k$and range similarity queries over trajectory data. We leverage Discrete Synchronous Euclidean Distance (DSED) to measure the spatio-temporal similarity of trajectory data, and employ a filter-then-refine strategy to enhance efficiency. Specifically, Hilbert curve-based filtering is first applied to exclude a large portion of dissimilar trajectories, followed by homomorphic encryption-based refinement to retrieve precise results. Security analysis demonstrates that our schemes protect the privacy of trajectory data, query requests, and query results. Finally, extensive experimental results indicate that the proposed methods achieve a trade-off between data availability and privacy, achieving over 99% average precision while initially filtering out 90% of dissimilar trajectories, and improving query efficiency by at least an order of magnitude. Kelai Yi, Yuchen Su 0001, Shiyue Huang, Yuefeng Chen, Xiong Li 0002, Hongbo Liu 0002 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Physical Layer Secret Key Generation Leveraging Variable-Length Segment Matching in Wireless NetworksabstractPhysical layer secret key generation has emerged as a promising approach for secret key establishment in wireless networks. Unlike traditional quantization-based methods, recent studies have explored matching the patterns of segmented channel samples of equal length for key agreement. However, equal-length segmentation either suffers from inconsistencies between users for short segments or a reduced key generation rate for long ones. To address these issues, we propose a Variable-length Segment Matching-based Secret Key Generation method, VSM-SKG, which adaptively partitions channel samples into variable-length segments to enhance overall matching accuracy, key generation rate, and encryption strength. Specifically, we introduce a dissimilarity-enhanced segmentation and calibration strategy that partitions channel samples into variable-length segments to enlarge segment-wise dissimilarity. To achieve consistent key recovery between users, we develop a dynamic path-aware key generation method that identifies potential segmentation patterns and generates agreed-upon secret keys using a recursive approach combined with a fast retrieval mechanism. Theoretical analyses and real-world experiments validate the attributes of VSM-SKG in terms of accuracy, efficiency, and security in key generation. Yicong Du, Yuchen Su 0001, Haitao Jia, Shuai Li 0002, Yanzhi Ren, Hongbo Liu 0002 |
IEEE Trans. Mob. Comput. | 7 |
| 2026 | Phase-Proof: Robust Mobile Two-Factor Authentication via Phase Fingerprinting
Tingyuan Yang, Shuyu Liu, Yanzhi Ren, Haitao Jia, Ziyu Shao, Hongbo Liu 0002, Jiadi Yu, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2026 | Chirp-Level Information-Based Collaborative Key Generation for LoRa Networks via Perturbed Compressed SensingabstractPhysical-layer key generation holds significant potential in establishing cryptographic key pairs for emerging LoRa networks. Nevertheless, current key generation solutions may underperform due to critically impaired channel reciprocity, attributed to the low data rate and long range inherent in LoRa networks. In this study, we presentChirpKey, a novel key generation scheme for LoRa networks. We pinpoint the key hurdles as the coarse-grained channel measurement, inefficient quantization methods, and out-of-range device constraints. To capture fine-grained channel information, we introduce a unique, LoRa-specific channel measurement method that focuses on analyzing chirp-level variations in LoRa packets. We also propose a LoRa channel state estimation algorithm to neutralize asynchronous channel sampling. Instead of the traditional quantization approach, we propose an innovative key delivery method based on perturbed compressed sensing, offering enhanced robustness and security. For LoRa devices beyond each other's communication reach, we integrate relay nodes to ensure reliable key generation. To foster secure group communication, we formulate two protocols that facilitate collaborative key generation across both star and chain configurations. Evaluation across diverse real-world scenarios reveals thatChirpKeyenhances the key matching rate by 11.03–26.58% and increases the key generation rate by 27–49× in comparison to existing leading systems. Our security analysis shows thatChirpKeycan effectively withstand a variety of prevalent attacks. Furthermore, we implement aChirpKeyprototype, demonstrating its capability to operate within 0.2 s. Huanqi Yang, Zehua Sun, Hongbo Liu 0002, Xianjin Xia, Yu Zhang 0093, Tao Gu 0001, Gerhard P. Hancke 0002, Weitao Xu |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Proactive Radio Frequency Fingerprinting-Based Authentication Leverage IQ PerturbationabstractPhysical layer authentication (PLA), which leverages device-specific physical layer features to achieve information-theoretic security with low complexity, offers a hardware-rooted security solution for next-generation Internet of Things (IoT) networks. While existing PLA approaches primarily rely on passive extraction of inherent hardware-induced radio frequency features, they remain vulnerable to adversarial spoofing that replicates legitimate radio frequency fingerprints (RFF). To address this critical vulnerability, we propose an active PLA framework that employs a challenge–response protocol to embed session-specific perturbation into each transmission. Upon receiving a nonce from the receiver, the legitimate transmitter generates a hash value and embeds a corresponding in-phase and quadrature (IQ) imbalance-based perturbation into the baseband signal. This design conceals inherent hardware-specific RFF and injects dynamic, unpredictable fingerprints that vary across sessions and are resilient to forgery. At the receiver, authentication is performed using a learning-based method that combines a CNN-based feature extractor with a lightweight logistic regression classifier trained on augmented samples. Extensive simulations demonstrate that the proposed framework achieves high authentication accuracy under both static and dynamic channel conditions, while effectively resisting advanced spoofing attacks, including GAN-based impersonation. These results confirm the robustness, generalization capability, and applicability of the proposed scheme for secure IoT communications. Siqi Pei, Shiyue Huang, Hongbo Liu 0002, Haitao Jia, Yanzhi Ren, Jiadi Yu |
TrustCom | 3 |
| 2025 | ArmSpy++: Enhanced PIN Inference through Video-based Fine-grained Arm Posture AnalysisabstractAs one of the most common ways for user authentication, Personal Identification Number (PIN), due to its simplicity and convenience, has suffered from plenty of side-channel attacks, which pose a severe threat to people’s privacy and property. The success of existing attacks is usually built upon the premise of no occlusion between the attacker and the victim’s hand gesture, but it increases the difficulty of launching the attack and the possibility of exposure. To overcome such limitation, we propose ArmSpy++, an improved video-assisted PIN inference attack built upon our previous research, ArmSpy. Specifically, ArmSpy++ employs new modules to leverage more features like the keystroke-induced elbow bending, wrist speed variation, and the spatial relationship between different arm joints, to correctly detect Keystrokes. ArmSpy++ delves into the perspective relationship and natural typing habits to ensure a high success rate of PIN inference. We also re-designed the inferred PIN pattern coordination mechanism to accurately deduce the PINs. By using a pre-trained HigherHRNet model for posture estimation ArmSpy++ eliminates the necessity of additional training. The extensive experiments demonstrate that ArmSpy++ can achieve over 83.1% average accuracy with 3 attempts and even 92.5% for some victims, indicating the severity of the threat posed by ArmSpy++. Yuefeng Chen, Yicong Du, Luping Wang 0001, Ziyu Shao, Hongbo Liu 0002, Yanzhi Ren, Jiadi Yu, Bo Liu 0006 |
ACM Trans. Priv. Secur. | 6 |
| 2025 | Efficient and Error-Free Secret Key Generation Leveraging Sorted Indices MatchingabstractSecret key generation exploiting inherent channel randomness stands as an important paradigm for physical-layer security in wireless networks. However, existing work relying on quantization has some difficulties in eliminating inconsistent key bits due to the impact of ambient noise. Recent studies propose to match the segmented channel samples (i.e., channel episodes) of similar variation patterns between legitimate peers to achieve error-free key generation, but they also suffer from high computational overhead and reduced accuracy for large key lengths. This work proposes a secret key generation method based on sorted indices matching (SIM-SKG), aiming at efficient and error-free key generation. Specifically, we sort the channel samples to ensure each channel episode with a unique variation pattern for accurate matching. To avoid the impact of half-duplex communication mode and ambient noise, we propose to match the indices instead of the channel samples as in existing studies. We also develop a noise perturbation scheme that further mitigates the ambiguity during indices matching. Extensive experimental studies demonstrate the high efficiency and accuracy of SIM-SKG under various scenarios for both RSS and CSI channel measurements. Specifically, SIM-SKG achieves error-free key generation with a length of 2048 bits within as little as 1.7$msec$. Moreover, theoretical analyses and experiments also confirm the security of the SIM-SKG method against various attacks. Yicong Du, Hongbo Liu 0002, Guyue Li, Yanzhi Ren, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | User Authentication on Smart Speakers Leveraging Acoustic Imaging
Yanzhi Ren, Zhiliang Xia, Hongbo Liu 0002, Jiadi Yu, Shuai Li 0002, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Two-Factor Authentication Based on Acoustic Fingerprinting in Modulation DomainabstractThe two-factor authentication (2FA) has been increasingly used with the popularity of mobile devices. Currently, many existing 2FA schemes extract the devices’ acoustic fingerprints as the second factor. Nevertheless, they mainly consider deriving fingerprints from the raw acoustic waveforms for authentication, which are susceptible to the fingerprint variations caused by the environmental noise or the varying distance between devices. To address these vulnerabilities, we propose a robust system utilizing the distortions of modulated signals, which are incurred by the acoustic elements of mobile devices, as the proof for 2FA. Specifically, our system first designs a channel delay estimation scheme to accurately estimate the propagation delay from the speaker to the microphone by deriving the phase change of the received sinusoidal signal. To perform a robust authentication, we design a new acoustic fingerprinting scheme to remove the impacts of the varying distance and environmental noise from the demodulated PSK signals for fingerprint extraction. Moreover, our device authentication component designs a transfer learning-based scheme to capture the subtle differences in devices’ fingerprints for accurate device authentication. To the best of our knowledge, this is the first 2FA system that could extract acoustic fingerprints in modulation domain and can effectively withstand the impacts of channel distortions. We also confirm the accuracy and security of our system through extensive user experiments. Yanzhi Ren, Tingyuan Yang, Hongbo Liu 0002, Jiadi Yu, Haomiao Yang, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Heart of Betrayal: A PIN Inference Attack Leveraging Photoplethysmography on WearablesabstractThe widespread adoption of wrist wearables featuring a range of sensors has led to a substantial user base. Among these sensors, Photoplethysmography (PPG) sensors have gained prominence for their affordability and non-intrusive nature, particularly in the context of vital signs monitoring. However, PPG sensors, with their potential for gesture recognition, also have the ability to extract sensitive private information from users. As the authentication method for many critical scenarios, once a PIN is compromised, it can lead to unbearable consequences. In this study, we introduce PPGLogger, a new side-channel attack that leverages PPG sensors for PIN inference. PPGLogger effectively separates signals originating from heartbeats and keystrokes to minimize noise interference. Additionally, we devise a keystroke detection technique capable of identifying and segmenting individual keystroke signals within the waveforms. For the keystroke inference component, we employ an Rocket-based classifier to achieve precise keystroke recognition. Through extensive real-world experiments, our findings are compelling. PPGLogger achieves an impressive accuracy rate of 76.3% in recognizing 10 digits. Furthermore, we demonstrate that PPGLogger can attain over 50% accuracy in classifying single keystrokes with a minimal dataset of just 28 samples, equivalent to merely 7 PIN entries. This underscores the efficacy and potential threat posed by PPGLogger in compromising user security. Shiyue Huang, Yuchen Su 0001, Hongbo Liu 0002, Bo Liu 0058 |
CSCWD | 3 |
| 2024 | Secret Key Generation with Adaptive Pilot Manipulation for Matching-Based MethodabstractSecret key generation plays an important role in device-to-device communication security in wireless networks. For consistent key generation between two communicating parties, existing matching-based key generation methods match segmented channel measurements (channel episodes) of similar patterns between two parties. However, these methods suffer diminished accuracy for large key lengths or in the presence of ambient noise. This work takes a different perspective to produce the desired channel measurements through adaptive manipulation of pilot signals for robust and accurate physical layer secret key generation. Specifically, an adaptive pilot manipulation scheme is designed not only to ensure that each channel episode has a unique pattern but also to improve pattern similarity between a pair of matched channel episodes, thus enabling high matching consistency. To validate the effectiveness of our method, we implement it by re-configuring software modules in GNU radio running on the USRP platform. Extensive experiments demonstrate that our method outperforms existing representative quantization-based and matching-based methods with improved key generation performance. Yicong Du, Hongbo Liu 0002, Yanzhi Ren, Bo Liu 0058 |
ICC | 3 |
| 2024 | mmHand: 3D Hand Pose Estimation Leveraging mmWave SignalsabstractHand pose estimation is a key support for a variety of interactive applications including user interface control, sign language understanding, virtual reality modeling, etc. Existing approaches mainly exploit wearable devices such as gloves or bracelets to estimate hand poses, which may introduce high deploying costs and intrusive user experience. Others rely on vision technologies whereas they could face complicated illuminations and privacy leakage. In this paper, we present a millimeter wave (mmWave) signal-based 3D hand pose estimation system, mmHand, which utilizes a mmWave radar to generate 3D hand skeletons and reconstruct 3D hand meshes. mmHand first leverages mmWave signals to sense a hand and pre-process the signals. Then, mmHand extracts spatial and temporal features using a designed attention-based hourglass network (mmSpaceNet) and Long Short-Term Memory (LSTM), respectively. Based on the extracted features, mmHand further regresses hand joints in 3D space to generate 3D hand skeletons. Finally, 3D hand meshes that continuously describe hand poses with detailed surfaces are reconstructed through a hand Model with Articulated and Non-rigid defOrmations (MANO). Extensive experiments demonstrate that mmHand can accurately generate 3D hand skeletons with 18.3mm mean per joint position error and 95.1 % of correct key points, which indicates the effectiveness of mmHand on hand pose estimation. Hao Kong 0004, Haoxin Lyu, Jiadi Yu, Linghe Kong, Junlin Yang, Yanzhi Ren, Hongbo Liu 0002, Yingying Chen 0001 |
ICDCS | 7 |
| 2024 | Physical Layer Secret Key Generation Leveraging Proactive Pilot ContaminationabstractPhysical layer-based secret key generation has garnered significant attention due to its inherent advantages of lightweight implementation, information-theoretic security, and broad applicability for mobile devices. The reciprocal randomness of the wireless channel ensures the consistent generation of secret bits between two communicating parties. However, it also suffers from the degradation of the efficiency of key generation attributed to the adverse impact of ambient noise, despite sustained efforts to mitigate the inconsistency during quantization. We find that a slight perturbation of the pilot signal, without affecting the correct reception of data frames, induces a corresponding change in the channel response, making it possibly adaptable to the target quantization strategies, thereby reducing the probability of key mismatch. Therefore, we take a different viewpoint on proactive contamination of the pilot signals to obtain the desired channel measurements for accurate physical layer secret key generation. Specifically, we design an adaptive pilot manipulation to avoid the expected channel measurements being too close to the quantization thresholds, enabling high quantization consistency. Furthermore, we also develop a random cross-threshold mechanism to prevent attackers from inferring the quantization results by monitoring the trend of pilot signal variations. A reliable long training sequence (LTS) modification mechanism is incorporated into our method to ensure communication performance by adaptively adjusting the scale of the pilot signal. To validate the effectiveness of our proposed method, we implement a prototype by re-configuring software modules in GNU radio running on the USRP platform. Extensive experiments demonstrate that our scheme outperforms existing representative quantization schemes with better key generation performance. Hongbo Liu 0002, Yicong Du, Ziyu Shao, Haomiao Yang, Yanzhi Ren |
ICDCS | 2 |
| 2024 | Practical Adversarial Attack on WiFi Sensing Through Unnoticeable Communication Packet PerturbationabstractThe pervasive use of WiFi has driven the recent research in WiFi sensing, converting communication tech into sensing for applications such as activity recognition, user authentication, and vital sign monitoring. Despite the integration of deep learning into WiFi sensing systems, potential security vulnerabilities to adversarial attacks remain unexplored. This paper introduces the first physical attack focusing on deep learning-based WiFi sensing systems, demonstrating how adversaries can subtly manipulate WiFi packet preambles to affect channel state information (CSI), a critical feature in such systems, and thereby influence underlying deep learning models without disrupting regular communication. To realize the proposed attack in practical scenarios, we rigorously analyze and derive the intricate relationship between the pilot symbol and CSI. A novel mechanism is proposed to facilitate quantitive control of receiver-side CSI through minimal modifications to the pilot symbols of WiFi packets at the transmitter. We further develop a perturbation optimization method based on the Carlini & Wagner (CW) attack and a penalty-based training process to ensure the attack's universal efficacy across various CSI responses and noise. The physical attack is implemented and evaluated in two representative WiFi sensing systems (i.e., activity recognition and user authentication) with 35 participants over 3 months. Extensive experiments demonstrate the remarkable attack success rates of 90.47% and 83.83% for activity recognition and user authentication, respectively. Mingjing Xu, Yicong Du, Cong Shi 0004, Yan Wang 0003, Hongbo Liu 0002, Yingying Chen 0001 |
MobiCom | 7 |
| 2024 | OISMic: Acoustic Eavesdropping Exploiting Sound-induced OIS Vibrations in SmartphonesabstractOptical image stabilization (OIS), powered by a special micro-electromechanical structure in the camera lenses to compensate for the optical distortion caused by camera shakes, has become an indispensable feature in many smartphones. However, we discover that this seemingly benign component can be exploited to eavesdrop on nearby audio signals, posing a significant threat to people's privacy during conversations or phone calls. Specifically, the OIS component can be influenced by external acoustic stimuli leading to slight vibrations, and at the same time, the coil and magnetized components inside the OIS induce electromagnetic leakage as they vibrate, according to Faraday's Law of Electromagnetic Induction. This electro-magnetic leakage contains voice information that can be used to recover the audio signals if intercepted by individuals with malicious intent. Inspired by the above discovery, we propose OISMic, a new acoustic eavesdropping attack that takes advantage of sound-induced OIS vibrations on smartphones. Unlike other existing acoustic eavesdropping attacks, eavesdropping exploiting OIS vibrations not only overcomes the constraints imposed by system permissions for many sensor-based approaches but is also immune to ultrasonic jammer that hinders the methods relying on microwave or light reflections to sense sound-induced vibrations. To execute this non-trivial attack in practical scenarios, we developed a prototype circuit that has a compact design capable of capturing the electromagnetic leakage caused by OIS vibrations. After converting the collected leaked electromagnetic signals into audio signals, a software-based phase-locked loop (PLL) method is developed to enhance the representation of voice components. Meanwhile, to reconstruct the weak audio signals, we also designed a diffusion-based neural network to learn the distribution of electromagnetic noise within the audio spectrum. Extensive experiments indicate that OISMic can accurately reconstruct voice under various scenarios, achieving an average word correct rate of 90.57 % across different devices. Ziyu Shao, Yuchen Su 0001, Yicong Du, Shiyue Huang, Tingyuan Yang, Hongbo Liu 0002, Yanzhi Ren, Bo Liu 0058, Shuai Li 0002 |
SECON | 6 |
| 2024 | Beyond Security: Achieving Fairness in Mailmen-Assisted Timed Data DeliveryabstractTimed data delivery is a critical service for time-sensitive applications that allows a sender to deliver data to a recipient, but only be accessible at a specific future time. This service is typically accomplished by employing a set of mailmen to complete the delivery mission. While this approach is commonly used, it is vulnerable to attacks from realistic adversaries, such as a greedy sender (who accesses the delivery service without paying the service charge) and malicious mailmen (who release the data prematurely without being detected). Although some research works have been done to address these adversaries, most of them fail to achieve fairness. In this paper, we formally define the fairness requirement for mailmen-assisted timed data delivery and propose a practical scheme, dubbed DataUber, to achieve fairness. DataUber ensures that honest mailmen receive the service charge, lazy mailmen do not receive the service charge, and malicious mailmen are punished. Specifically, DataUber consists of two key techniques: 1) a new cryptographic primitive, i.e., Oblivious and Verifiable Threshold Secret Sharing (OVTSS), enabling a dealer to distribute a secret among multiple participants in a threshold and verifiable way without knowing any one of the shares; and 2) a smart-contract-based complaint mechanism, allowing anyone to become a reporter to complain about a mailman’s misbehavior to a smart contract and receive a reward. Furthermore, we formally prove the security of DataUber and demonstrate its practicality through a prototype implementation. Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Hongbo Liu 0002, Nan Cheng 0001, Dahai Tao, Hongwei Li 0001, Kan Yang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Secret Key Generation Based on Manipulated Channel Measurement MatchingabstractThe physical layer secret key generation exploiting wireless channel reciprocity has demonstrated its viability and effectiveness in various wireless scenarios, such as the Internet of Things (IoT) network, mobile communication network, and industrial control system. Most of the existing studies rely on the quantization technique to convert channel measurements into secret bits for confidential communications. However, non-simultaneous packet exchanges in time-division duplex systems and noise effects usually induce inconsistent quantization results and mismatched secret bits. Although recent research has spent significant effort mitigating such non-reciprocity, it is still far from practical error-free key generation. Unlike previous quantization-based approaches, we take a different viewpoint to match the randomly manipulated (i.e., permuted or edited) channel measurements between a pair of users by minimizing their discrepancy holistically. Specifically, two novel secret key generation algorithms based on bipartite graph matching (BMSKG) and edited sequence alignment (SA-SKG) are developed. BM-SKG allows two users to generate the same secret key based on the permutation order of channel measurements, while SASKG aims to align the edited channel measurements between a pair of users for secret key agreement. In both algorithms, one user can preset the secret key and embed encrypted messages in the exchanged data packets, which reduces communication overheads in key generation. Extensive experimental results show that both BM-SKG and SA-SKG algorithms achieve error-free key agreement on channel measurements at a low cost under various scenarios. Yicong Du, Hongbo Liu 0002, Yan Wang 0003, Guyue Li, Yanzhi Ren, Yingying Chen 0001, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Secure and Controllable Secret Key Generation Through CSI Obfuscation Matrix EncapsulationabstractPhysical-layer key generation has emerged as a promising avenue for establishing secret keys using reciprocal channel measurements between wireless devices. However, channel reciprocity may suffer degradation from ambient noise and cause mismatched secret bits, while existing methods mitigating this issue may yet face limitations in key efficiency. The root cause behind such limitations is the heavy reliance on channel measurements, which can be naturally susceptible to channel non-reciprocity attributed to environmental factors. Instead of direct key extraction from channel measurements, we seek to share a pre-defined key and utilize channel measurements as a bearer to facilitate key transmission. We propose an accurate and efficient key generation method (KeyCome) to ensure secure key sharing by encapsulating it with channel state information (CSI) obfuscation matrices through circulant convolution. To this end, we develop a reliable key derivation through a quadratic programming method with matrix equilibration, ensuring stable and rapid solutions. Notably, the transmitter can control the key beforehand for enhanced communication efficiency and combine it with an error correction mechanism for accurate key derivation. Furthermore, a lightweight reconciliation scheme is designed to minimize mismatched bits caused by occasional non-reciprocity. Comprehensive experiments demonstrate KeyCome's high accuracy and efficiency in key generation. Yicong Du, Hongbo Liu 0002, Ziyu Shao, Yanzhi Ren, Shuai Li 0002, Jiadi Yu |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Secure Mobile Two-Factor Authentication Leveraging Active Sound SensingabstractThe two-factor authentication ($2$FA) has drawn increasingly attention as the mobile devices become more prevalent. For example, the user's possession of the enrolled phone could be used by the$2$FA system as the second proof to protect his/her online accounts. Existing$2$FA solutions mainly require some form of user-device interaction, which may severely affect user experience and creates extra burdens to users. In this work, we propose a secure$2$FA system utilizing the proximity of a user's enrolled phone and the login device as the second proof without requiring the user's interactions. The basic idea of our$2$FA system is to derive location signatures based on acoustic beep signals emitted alternately by both devices and sensing the echoes with microphones, and compare the extracted signatures for proximity detection. Moreover, to further enhance the security of our system, we also design a device authentication scheme which derives the acoustic fingerprint between the login device and enrolled phone to verify the identity of two devices. Given the received beep signal, our system designs a period selection scheme to identify two sound segments accurately: the chirp period is the sound segment propagating directly from the speaker to the microphone whereas the echo period is the sound segment reflected back by surrounding objects. To achieve an accurate proximity detection, we develop a new energy loss compensation extraction scheme by utilizing the extracted chirp periods to estimate the intrinsic differences of energy loss between microphones of the enrolled phone and the login device. Our proximity detection component then conducts the similarity comparison between the identified two echo periods after the energy loss compensation to effectively determine whether the enrolled phone and the login device are in proximity for$2$FA. Moreover, to provide higher security, our device fingerprint-assisted proximity detection further utilizes the overall energy loss between the login device and enrolled phone as their hardware fingerprint to authenticate the identity of two devices. Our experimental results show that our system is accurate in providing$2$FA and robust to both man-in-the-middle (MiM) and co-located attacks across different scenarios and device models. Yanzhi Ren, Chen Chen 0092, Hongbo Liu 0002, Jiadi Yu, Zhourong Zheng, Yingying Chen 0001, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Robust Indoor Location Identification for Smartphones Using Echoes From Dominant ReflectorsabstractThe indoor location awareness has drawn increasing attention as the mobile apps are used extensively in our daily lives. Existing indoor localization solutions either require a pre-installed infrastructure or can only achieve room-level accuracy, which could not provide a function-location service for mobile devices. In this work, we propose a new active sensing system that enables smartphones to identify some pre-defined indoor locations robustly without requiring any additional sensors or pre-installed infrastructure. The main idea behind our system is to utilize the acoustic signatures, which are derived from the mobile device by emitting a beep signal and selecting its echoes created by dominant reflectors, as the robust fingerprint for location identification. Given the microphone samplings, our system designs a correlation based technique to accurately detect the beginning points of echoes from the received beep signal. To achieve a robust location identification, we develop a new echo selection scheme to select echoes created by dominant reflectors by exploiting the relationships between propagation delays of different orders of echoes. To deal with the variable number of selected echoes, our location identification component then derives histograms from selected echoes and uses the one-against-all SVM classifiers to determine the current location. Our experimental results show that our proposed system is accurate and robust for location identification under various real-world scenarios. Yanzhi Ren, Chen Chen 0092, Hongbo Liu 0002, Jiadi Yu, Yingying Chen 0001, Haomiao Yang, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Robust Mobile Two-Factor Authentication Leveraging Acoustic FingerprintingabstractThe two-factor authentication (2FA) has become pervasive as the mobile devices become prevalent. Existing 2FA solutions usually require some form of user involvement, which could severely affect user experience and bring extra burdens to users. In this work, we propose a secure 2FA that utilizes the individual acoustic fingerprint of the speaker/microphone on enrolled device as the second proof. The main idea behind our system is to use both magnitude and phase fingerprints derived from the frequency response of the enrolled device by emitting acoustic beep signals alternately from both enrolled and login devices and receiving their direct arrivals for 2FA. Given the input microphone samplings, our system designs an arrival time detection scheme to accurately identify the beginning point of the beep signal from the received signal. To achieve a robust authentication, we develop a new distance mitigation scheme to eliminate the impact of transmission distances from the sound propagation model for extracting stable fingerprint in both magnitude and phase domain. Our device authentication component then calculates a weighted correlation value between the device profile and fingerprints extracted from run-time measurements to conduct the device authentication for 2FA. Moreover, to thwart the possible co-located attacks, our proximity detection component further makes the enrolled phone to generate an active random vibration signal by its built-in motor, and then matches the signal received by the microphone of login device with the signal received by the accelerometer of enrolled phone to verify the proximity of two devices. Our experimental results show that our proposed system is accurate and robust to various attacks across different scenarios and device models. Yanzhi Ren, Tingyuan Yang, Zhiliang Xia, Hongbo Liu 0002, Jiadi Yu, Bo Liu 0006, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Indoor Location Identification for Smart Speakers Leveraging 3-D Acoustic ImagesabstractThe indoor location awareness has drawn increasing attention for smart speakers as they become essential to provide function-location services. Existing indoor localization solutions either require add-on equipment or could only achieve room-level accuracy, which could not provide a function-location service for smart speakers. In this work, we propose a location identification system utilizing 3-D acoustic images, which are derived from the smart speaker by emitting a beep signal and sensing echoes created by objects in the surrounding environment with its microphone array, as the proof to identify some pre-defined indoor locations. Given the recorded acoustic samplings captured by the microphone array, our image construction component constructs a virtual imaging hemisphere and steers the array towards each grid of the hemisphere to generate a 3-D acoustic image of the surrounding environment. Moreover, we design a transfer-learning based model to derive effective features from the constructed images, and propose a data augmentation scheme for generating synthesized training images. To achieve a more accurate location identification, we further design a distance estimation scheme to identify the distances between the smart speaker and some major surrounding objects by utilizing the constructed 3-D acoustic image, and then adopt such distance information for location identification. Our experimental results show that our proposed system is accurate and robust for location identification under various real world scenarios. Zhiliang Xia, Yanzhi Ren, Jiachen Ou, Hongbo Liu 0002, Yingying Chen 0001, Shu Fu, Hongwei Li 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Scenario-Adaptive Key Establishment Scheme for LoRa-Enabled IoV CommunicationsabstractIn recent years, the Internet of Vehicles (IoV) has experienced significant growth, but the lack of effective secret key establishment remains a security concern due to the dynamic and ad-hoc nature of IoV communications. Physical layer key generation has emerged as a promising solution for establishing a pair of cryptographic keys in a lightweight and information-theoretic secure manner. However, previous works have primarily focused on legacy communication technologies, such as Wi-Fi, ZigBee, and 5 G, which are limited to short-range IoV communications. With the emergence of Long-range (LoRa) communication technology, which features long-range, low power, and extremely low data rates, new challenges arise for key generation in long-range IoV scenarios. This paper presentsVehicle-Key, a secret key generation system designed to secure LoRa-enabled IoV communications.Vehicle-Keypresents an innovative scenario adaptive deep learning model that performs channel prediction and quantization concurrently while reducing the training cost through a data augmentation pipeline and enhancing the model's generalization using a domain-adaption method. Additionally, we propose a bloom filter-assisted autoencoder-based reconciliation method to significantly improve the key agreement rate. Comprehensive real-world experiments show thatVehicle-Keysurpasses the State-of-the-Art, achieving a 15.26%–50.35% improvement in key agreement rate and a 9–15× increase in key generation rate. Moreover, the proposed method attains a 4.37--9.33% improvement when adapted to new scenarios with limited data sizes. A security analysis demonstrates thatVehicle-Keyis resilient against several common attacks. Furthermore, we implementVehicle-Keyon a Raspberry Pi and demonstrate its ability to execute within 3.5 ms. Huanqi Yang, Di Duan, Hongbo Liu 0002, Chengwen Luo 0001, Yuezhong Wu, Wei Li 0058, Albert Y. Zomaya, Linqi Song, Weitao Xu |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | EchoImage: User Authentication on Smart Speakers Using Acoustic SignalsabstractThe user authentication has drawn increasingly attention as the smart speaker becomes more prevalent. For example, smart speakers that can verify who is sending voice commands can mitigate various types of attacks such as replay attack or impersonation attack. Existing user authentication solutions either cannot be applicable to smart speakers directly or require certain additional user-device interaction or pre-installed infrastructure, which may severely affect the user experience and create extra burdens to users. In this work, we propose a user authentication system EchoImage utilizing acoustic images, which are derived from the smart speaker by emitting beep signals and sensing echoes from the user's body with its microphone array, as the proof for user authentication. Given the acoustic samplings of the reflected beep signal, our system designs a distance estimation component by applying a correlation based technique on the beamformed signal to estimate the distance between the user and microphone array. Our image construction component then constructs a virtual imaging plane using the estimated distance and steers the array towards each grid of the plane to generate an acoustic image of the user. Moreover, we propose a transfer learning-based method to derive efficient features from the constructed images, and employ SVM classifiers for accurate user authentication. Our extensive experiments demonstrate that our system is robust and accurate across various scenarios. Yanzhi Ren, Zhiliang Xia, Hongbo Liu 0002, Yingying Chen 0001, Shuai Li 0002, Hongwei Li 0001 |
ICDCS | 4 |
| 2023 | P2Auth: Two-Factor Authentication Leveraging PIN and Keystroke-Induced PPG MeasurementsabstractPersonal Identification Number (PIN), as one of the primary means of protecting digital properties and privacy on mobile devices, has been suffering from shoulder surfing attacks and weak password guessing for the long term. Recent years witness the growing interest in two-factor authentication that takes advantage of two different ways for mutual verification, thereby strengthening user authentication's accuracy and reliability. Especially with the popularity of smartwatches, more physiological signals are readily available to facilitate two-factor authentication. This paper presents a lightweight and unobtrusive two-factor authentication scheme, P2Auth, integrating the PIN and unique keystroke-related Photoplethysmography (PPG) measurement on wearables. Specifically, we propose the transformation of the multivariate PPG signal induced by the keystrokes to extract reliable biometric features. We develop short-time energy-based methods to identify the input cases, thus enabling support the authentication for both one-handed and two-handed input cases. Furthermore, we also consider the situation where there is no fixed PIN and design a new enhanced privacy scheme by combining the PPG measurements of different keystrokes to improve authentication security. The experiments involving 15 volunteers demonstrate that our prototype system can achieve an average authentication accuracy of over 95% for one-handed cases and over 90% for two-handed cases. Yuchen Su 0001, Guoqing Jiang, Yicong Du, Yuefeng Chen, Hongbo Liu 0002, Yanzhi Ren, Yan Wang 0003, Shuai Li 0002, Yingying Chen 0001 |
ICDCS | 5 |
| 2023 | Secure and Robust Two Factor Authentication via Acoustic FingerprintingabstractThe two-factor authentication (2FA) has become pervasive as the mobile devices become prevalent. Existing 2FA solutions usually require some form of user involvement, which could severely affect user experience and bring extra burdens to users. In this work, we propose a secure 2FA that utilizes the individual acoustic fingerprint of the speaker/microphone on enrolled device as the second proof. The main idea behind our system is to use both magnitude and phase fingerprints derived from the frequency response of the enrolled device by emitting acoustic beep signals alternately from both enrolled and login devices and receiving their direct arrivals for 2FA. Given the input microphone samplings, our system designs an arrival time detection scheme to accurately identify the beginning point of the beep signal from the received signal. To achieve a robust authentication, we develop a new distance mitigation scheme to eliminate the impact of transmission distances from the sound propagation model for extracting stable fingerprint in both magnitude and phase domain. Our device authentication component then calculates a weighted correlation value between the device profile and fingerprints extracted from run-time measurements to conduct the device authentication for 2FA. Our experimental results show that our proposed system is accurate and robust to both random impersonation and Man-in-the-middle (MiM) attack across different scenarios and device models. Yanzhi Ren, Tingyuan Yang, Zhiliang Xia, Hongbo Liu 0002, Yingying Chen 0001, Nan Jiang 0013, Zhaohui Yuan, Hongwei Li 0001 |
INFOCOM | 4 |
| 2023 | ChirpKey: A Chirp-level Information-based Key Generation Scheme for LoRa Networks via Perturbed Compressed SensingabstractPhysical-layer key generation is promising in establishing a pair of cryptographic keys for emerging LoRa networks. However, existing key generation systems may perform poorly since the channel reciprocity is critically impaired due to low data rate and long range in LoRa networks. To bridge this gap, this paper proposes a novel key generation system for LoRa networks, named ChirpKey. We reveal that the underlying limitations are coarse-grained channel measurement and inefficient quantization process. To enable fine-grained channel information, we propose a novel LoRa-specific channel measurement method that essentially analyzes the chirp-level changes in LoRa packets. Additionally, we propose a LoRa channel state estimation algorithm to eliminate the effect of asynchronous channel sampling. Instead of using quantization process, we propose a novel perturbed compressed sensing based key delivery method to achieve a high level of robustness and security. Evaluation in different real-world environments shows that ChirpKey improves the key matching rate by 11.03–26.58% and key generation rate by 27–49× compared with the state-of-the-arts. Security analysis demonstrates that ChirpKey is secure against several common attacks. Moreover, we implement a ChirpKey prototype and demonstrate that it can be executed in 0.2 s. Huanqi Yang, Zehua Sun, Hongbo Liu 0002, Xianjin Xia, Yu Zhang 0093, Tao Gu 0001, Gerhard P. Hancke 0002, Weitao Xu |
INFOCOM | 3 |
| 2022 | Vehicle-Key: A Secret Key Establishment Scheme for LoRa-enabled IoV CommunicationsabstractRecent years have witnessed the remarkable growth of the Internet of Vehicles (IoV). Due to the high dynamics and ad-hoc nature of IoV communication, the lack of effective secret key establishment in IoV remains a security bottleneck. Physical layer key generation has emerged as a promising technology to establish a pair of cryptographic keys in a lightweight and information-theoretic secure way. However, prior works mainly focus on legacy communication technologies such as Wi-Fi, ZigBee, and 5G which can only achieve short range IoV communications. The emergence of Long-range (LoRa) communication technology that features long-range, low power, and extremely low data rate, brings new challenges for key generation in long range IoV scenarios. In this paper, we present Vehicle-Key, which is a secret key generation system to secure LoRa-enabled IoV communications. In Vehicle-Key, we design a novel deep learning model that can achieve channel prediction and quantization simultaneously. Additionally, we propose an autoencoder-based reconciliation method that improves the key agreement rate significantly. Extensive real-world experiments show that Vehicle-Key improves the key agreement rate by 15.10%–49.81% and key generation rate by 9–14× compared with the state-of-the-art. Security analysis demonstrates that Vehicle-Key is secure against several common attacks. Moreover, we implement Vehicle-Key on a Raspberry Pi and show that it can be executed in 3.4 ms. Huanqi Yang, Hongbo Liu 0002, Chengwen Luo 0001, Yuezhong Wu, Wei Li 0058, Albert Y. Zomaya, Linqi Song, Weitao Xu |
ICDCS | 2 |
| 2022 | An Improved Least-square based Jammer Localization AlgorithmabstractDue to the shared nature of wireless mediums, jamming attacks have long been a great hazard to the security of wireless networks. A plethora of efforts have been spent to mitigate the impact of jamming attacks, and especially the localization technique of malicious jammer emerges in the last decade and enables us to remove the interfering devices from the physical layer. Since it is impossible to directly measure the interfering signal in a jamming scenario, many existing methods rely on inaccurate ranging estimation to locate the jammers. In this paper, we propose an improved least-square jammer localization method leveraging the network distribution properties. Specifically, we exploit the stochastic geometry theory to analyze the coverage changes of wireless devices around the jammer, which are then used to improve the accuracy of ranging estimation. Extensive numerical results demonstrate the effectiveness and robustness of the proposed jammer localization methods under various scenarios. Notably, the improved leastsquares method has a decreasing of 35 % on the mean localization error comparing to the traditional least-square method. Ruiqiong Tong, Yicong Du, Hongbo Liu 0002, Yingying Chen 0001 |
ICPADS | 3 |
| 2022 | ArmSpy: Video-assisted PIN Inference Leveraging Keystroke-induced Arm Posture ChangesabstractPIN inference attack leveraging keystroke-induced side-channel information poses a substantial threat to the security of people’s privacy and properties. Among various PIN inference attacks, video-assisted method provide more intuitive and robust side-channel information to infer PINs. But it usually requires there is no visual occlusion between the attacker and the victims or their hand gestures, making the attackers either easy to expose themselves or inapplicable to the scenarios such as ATM or POS terminals. In this paper, we present a novel and practical video-assisted PIN inference system, ArmSpy, which infers victim’s PIN by observing from behind the victims in a stealthy way. Specifically, ArmSpy explores the subtle keystroke-induced arm posture changes, including elbow bending angle changes and the spatial relationship between different arm joints, to infer the PIN entries. We develop the keystroke inference mechanism to detect the keystroke events and pinpoint the keystroke positions, and then accurately infer the PINs with the proposed inferred PIN coordination mechanism. Extensive experimental results demonstrate that ArmSpy can achieve over 67% average accuracy on inferring the PIN with 3 attempts and even over 80% for some victims, indicating the severity of the threat posed by ArmSpy. Yuefeng Chen, Yicong Du, Chunlong Xu, Yanghai Yu, Hongbo Liu 0002, Yanzhi Ren, Jiadi Yu |
INFOCOM | 5 |
| 2022 | Fast and Secure Key Generation with Channel Obfuscation in Slowly Varying EnvironmentsabstractPhysical-layer secret key generation has emerged as a promising solution for establishing cryptographic keys by leveraging reciprocal and time-varying wireless channels. However, existing approaches suffer from low key generation rates and vulnerabilities under various attacks in slowly varying environments. We propose a new physical-layer secret key generation approach with channel obfuscation, which improves the dynamic property of channel parameters based on random filtering and random antenna scheduling. Our approach makes one party obfuscate the channel to allow the legitimate party to obtain similar dynamic channel parameters, yet prevents a third party from inferring the obfuscation information. Our approach allows more random bits to be extracted from the obfuscated channel parameters by a joint design of the K-L transform and adaptive quantization. Results from a testbed implementation show that our approach, compared to the existing ones that we evaluate, performs the best in generating high entropy bits at a fast rate and is able to resist various attacks in slowly varying environments. Specifically, our approach can achieve a significantly faster secret bit generation rate at roughly 67 bit/pkt, and the key sequences can pass the randomness tests of the NIST test suite. Guyue Li, Haiyu Yang, Junqing Zhang, Hongbo Liu 0002, Aiqun Hu |
INFOCOM | 4 |
| 2022 | mmECG: Monitoring Human Cardiac Cycle in Driving Environments Leveraging Millimeter WaveabstractThe continuously increasing time spent on car trips in recent years brings growing attention to the physical and mental health of drivers on roads. As one of the key vital signs, the heartbeat is a critical indicator of drivers' health states. Most existing studies on heartbeat monitoring either require sensor attachment or could only provide sketchy heart rates. Moreover, most approaches require the subject to remain stationary or a quiet measuring environment, which is hard to apply to dynamic driving environments. In this paper, we propose a contactless cardiac cycle monitoring system, mmECG, which leverages Commercial-Off-The-Shelf mmWave radar to estimate the fine-grained heart movements of drivers in moving vehicles. By exploring the principle of mmWave signal-based sensing, we first perform studies in static environments and find the fine-grained heart movements, represented as stages of atria and ventricles in repetitive cardiac cycles, can be captured by the FMCW-based mmWave radar as phase changes in signals. Whereas in driving environments, such phase changes are caused and influenced by not only the heartbeat of drivers but also driving operations and vehicle dynamics. To further extract the minute heart movements of drivers and eliminate other influences in phase changes, we construct a movement mixture model to represent the phase changes caused by different movements, and further design a hierarchy variational mode decomposition (VMD) approach to extract and estimate the essential heart movement in mmWave signals. Finally, based on the extracted phase changes, mmECG reconstructs the cardiac cycle by estimating fine-grained movements of atria and ventricles leveraging a template-based optimization method. Experimental results involving 25 drivers in real driving scenarios demonstrate that mmECG can accurately estimate not only heart rates but also cardiac cycles of drivers in real driving environments. Xiangyu Xu 0001, Jiadi Yu, Chengguang Ma, Yanzhi Ren, Hongbo Liu 0002, Yanmin Zhu 0006, Yingying Chen 0001, Feilong Tang 0001 |
INFOCOM | 5 |
| 2022 | Acoustic-Sensing-Based Location Semantics Identification Using SmartphonesabstractThe location awareness becomes increasingly important as mobile devices such as smartphones are used extensively in our daily lives. Existing indoor localization solutions either require certain preinstalled infrastructures or add-on devices, which could not provide a location semantics identification service for smartphones to infer both type and size of a geographic location. In this work, we propose a new active sensing system that enables smartphones to identify its location semantics without requiring any additional infrastructure. The main idea behind our system is to utilize the acoustic signatures, which are derived from the smartphone by emitting a predesigned beep signal and identifying two echo sets which correspond to sidewalls and other static objects respectively, as the proof to achieve both spatial size estimation and room-type prediction simultaneously for indoor location semantics identification. Given the microphone samplings, our system designs a correlation-based scheme to identify beginning points of echoes corresponding to static reflectors accurately from the received signal. To achieve an accurate location semantics identification, we develop a new echo selection scheme to discriminate echoes created by sidewalls and other static reflectors by utilizing the geometrical relationships between the delays of echoes. To deal with the varying number of identified echoes, our location semantics prediction scheme then derives histograms from echo sets and adopt a deep-learning-based classifier to determine the current location semantics. Our experimental results show that our proposed system is accurate and robust for location semantics identification under various real-world scenarios. Chen Chen 0092, Yanzhi Ren, Hongbo Liu 0002, Yingying Chen 0001, Hongwei Li 0001 |
IEEE Internet Things J. | 3 |
| 2022 | SpoVis: Decision Support System for Site Selection of Sports Facilities in Digital Twinning CitiesabstractThe site selection of sports facilities is a pivotal link in the construction of city livable environment and the development of sports business in digital-twinning cities. Recent years have witnessed data mining and visualization technologies bringing the convenience as well as opportunities for intelligent site selection. However, the lack of effective and reliable systematic analysis leads to difficulties in developing sports facilities planning schemes and constructing the site-selection system. In this article, we design Sport facility Visual analysis system (SpoVis), an interactive visual analysis system for planning sports facilities as well as site selection. SpoVis provides users with the distribution status and statistical analysis of various sports facilities. Based on a comprehensive consideration of city population distribution, construction cost, existing sports facilities, traffic situation, and development potential, SpoVis provides users with a reasonable site-selection scheme of sports facilities from both macro and microperspectives and recommends results through topology and map. Meanwhile, based on the distribution of existing sports facilities and city influencing factors, a set of visual analysis components are designed to facilitate users to evaluate the status and information of existing sports facilities. We have carried out extensive experiments on a real platform with real-world data. The experimental results show that the proposed site-selection models and algorithms have excellent accuracy and operation efficiency. Ke Zhang 0022, Hongning Dai, Hongbo Liu 0002, Zhongrui Lin |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Enabling Secret Key Distribution Over Screen-to-Camera Channel Leveraging Color Shift PropertyabstractRecent years witnessed the emergence of visible light communication (VLC) over screen-to-camera channel, such as barcode and unobtrusive optical pattern, due to the widely adoption of screen and camera in plenty of electronic devices. The prevalence of wide viewing angle screen and high standard cameras also imposes great threat for visible light communication, and the information leakage over screen-to-camera channel has been rarely explored. In this paper, we propose a secret key distribution system leveraging the unique color shift property over screen-to-camera channel. To facilitate such design, two practical secret key distribution methods, key matching-based and nearest next hop-based, are developed to map the secret key into a unique optical pattern on screen, which can only be correctly decoded by the legitimate user situated at an accessible region. We also provide theoretical analysis on the security of both methods. The performance of the proposed system is implemented with off-the-shelf devices and validated under various experimental scenarios. The results demonstrate that our system can achieve high bit-decoding accuracy for the legitimate users while maintaining low recovery accuracy for the attackers. Hongbo Liu 0002, Cong Shi 0004, Yingying Chen 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | Breathing Sound-based Exercise Intensity Monitoring via SmartphonesabstractExercise intensity monitoring of physical activities has drawn increasingly attention as the awareness of the exercise intensity is of great importance for a person to achieve optimal training outcomes. For example, over-training could lead to excessive fatigue and loss of motivation for exercise. Traditional exercise intensity monitoring systems utilize GPS data to track the user’s intensity of cardio activities through his/her position and speed. Such systems however become invalid for indoor exercises on stationary fitness equipments such as the treadmill or exercise bike. Recent work in using body-worn sensors to track the user’s heart rate for exercise intensity monitoring usually involves additional wearable sensors which are only available on some particular fitness equipments, and thus are hard to be used in all occasions. This work presents an exercise intensity monitoring system which is capable of detecting a person’s exercise intensity via smartphones. Our system exploits the off-the-shelf smartphone and its headphone to capture the user’s breathing sound. Given the captured acoustic data, our system performs data pre-processing to remove the environmental noise and identify the non-silent acoustic frames based on the signal energy. Our system then conducts breathing event detection for non-silent frames, and further calibrates the detection results by utilizing the high correlation between breathing cycles to improve the detection accuracy. Moreover, our system can estimate the person’s exercise intensity based on features extracted from the frames which contain breathing sound. Our experiments involving 9 subjects over four-month time period demonstrate that our proposed exercise intensity monitoring system is robust and accurate in both indoor and outdoor environments. Yanzhi Ren, Zhourong Zheng, Hongbo Liu 0002, Yingying Chen 0001, Hongwei Li 0001, Chen Wang 0009 |
ICCCN | 3 |
| 2021 | Bipartite Graph Matching Based Secret Key GenerationabstractThe physical layer secret key generation exploiting wireless channel reciprocity has attracted considerable attention in the past two decades. On-going research have demonstrated its viability in various radio frequency (RF) systems. Most of existing work rely on quantization technique to convert channel measurements into digital binaries that are suitable for secret key generation. However, non-simultaneous packet exchanges in time division duplex systems and noise effects in practice usually create random channel measurements between two users, leading to inconsistent quantization results and mismatched secret bits. While significant efforts were spent in recent research to mitigate such non-reciprocity, no efficient method has been found yet. Unlike existing quantization-based approaches, we take a different viewpoint and perform the secret key agreement by solving a bipartite graph matching problem. Specifically, an efficient dual-permutation secret key generation method, DP-SKG, is developed to match the randomly permuted channel measurements between a pair of users by minimizing their discrepancy holistically. DP-SKG allows two users to generate the same secret key based on the permutation order of channel measurements despite the non-reciprocity over wireless channels. Extensive experimental results show that DP-SKG could achieve error-free key agreement on received signal strength (RSS) with a low cost under various scenarios. Hongbo Liu 0002, Yan Wang 0003, Yanzhi Ren, Yingying Chen 0001 |
INFOCOM | 1 |
| 2021 | Proximity-Echo: Secure Two Factor Authentication Using Active Sound SensingabstractThe two-factor authentication (2FA) has drawn increasingly attention as the mobile devices become more prevalent. For example, the user's possession of the enrolled phone could be used by the 2FA system as the second proof to protect his/her online accounts. Existing 2FA solutions mainly require some form of user-device interaction, which may severely affect user experience and creates extra burdens to users. In this work, we propose Proximity-Echo, a secure 2FA system utilizing the proximity of a user's enrolled phone and the login device as the second proof without requiring the user's interactions or pre-constructed device fingerprints. The basic idea of Proximity-Echo is to derive location signatures based on acoustic beep signals emitted alternately by both devices and sensing the echoes with microphones, and compare the extracted signatures for proximity detection. Given the received beep signal, our system designs a period selection scheme to identify two sound segments accurately: the chirp period is the sound segment propagating directly from the speaker to the microphone whereas the echo period is the sound segment reflected back by surrounding objects. To achieve an accurate proximity detection, we develop a new energy loss compensation extraction scheme by utilizing the extracted chirp periods to estimate the intrinsic differences of energy loss between microphones of the enrolled phone and the login device. Our proximity detection component then conducts the similarity comparison between the identified two echo periods after the energy loss compensation to effectively determine whether the enrolled phone and the login device are in proximity for 2FA. Our experimental results show that our Proximity-Echo is accurate in providing 2FA and robust to both man-in-the-middle (MiM) and co-located attacks across different scenarios and device models. Yanzhi Ren, Ping Wen, Hongbo Liu 0002, Zhourong Zheng, Yingying Chen 0001, Hongwei Li 0001 |
INFOCOM | 3 |
| 2021 | WiFi-Enabled User Authentication through Deep Learning in Daily ActivitiesabstractUser authentication is a critical process in both corporate and home environments due to the ever-growing security and privacy concerns. With the advancement of smart cities and home environments, the concept of user authentication is evolved with a broader implication by not only preventing unauthorized users from accessing confidential information but also providing the opportunities for customized services corresponding to a specific user. Traditional approaches of user authentication either require specialized device installation or inconvenient wearable sensor attachment. This article supports the extended concept of user authentication with a device-free approach by leveraging the prevalent WiFi signals made available by IoT devices, such as smart refrigerator, smart TV, and smart thermostat, and so on. The proposed system utilizes the WiFi signals to capture unique human physiological and behavioral characteristics inherited from their daily activities, including both walking and stationary ones. Particularly, we extract representative features from channel state information (CSI) measurements of WiFi signals, and develop a deep-learning-based user authentication scheme to accurately identify each individual user. To mitigate the signal distortion caused by surrounding people’s movements, our deep learning model exploits a CNN-based architecture that constructively combines features from multiple receiving antennas and derives more reliable feature abstractions. Furthermore, a transfer-learning-based mechanism is developed to reduce the training cost for new users and environments. Extensive experiments in various indoor environments are conducted to demonstrate the effectiveness of the proposed authentication system. In particular, our system can achieve over 94% authentication accuracy with 11 subjects through different activities. Cong Shi 0004, Jian Liu 0001, Hongbo Liu 0002, Yingying Chen 0001 |
ACM Trans. Internet Things | 3 |
| 2021 | Towards Low-Cost Sign Language Gesture Recognition Leveraging WearablesabstractDifferent from traditional gestures, sign language gestures involve a lot of finger-level gestures without wrist or arm movements. They are hard to detect using existing motion sensors-based approaches. We introduce the first low-cost sign language gesture recognition system that can differentiate fine-grained finger movements using the Photoplethysmography (PPG) and motion sensors in commodity wearables. By leveraging the motion artifacts in PPG, our system can accurately recognize sign language gestures when there are large body movements, which cannot be handled by the traditional motion sensor-based approaches. We further explore the feasibility of using both PPG and motion sensors in wearables to improve the sign language gesture recognition accuracy when there are limited body movements. We develop a gradient boost tree (GBT) model and deep neural network-based model (i.e., ResNet) for classification. The transfer learning technique is applied to ResNet-based model to reduce the training effort. We develop a prototype using low-cost PPG and motions sensors and conduct extensive experiments and collect over 7000 gestures from 10 adults in the static and body-motion scenarios. Results demonstrate that our system can differentiate nine finger-level gestures from the American Sign Language with an average recognition accuracy over 98 percent. Tianming Zhao 0001, Jian Liu 0001, Yan Wang 0003, Hongbo Liu 0002, Yingying Chen 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2020 | LiveScreen: Video Chat Liveness Detection Leveraging Skin ReflectionabstractThe rapid advancement of social media and communication technology enables video chat to become an important and convenient way of daily communication. However, such convenience also makes personal video clips easily obtained and exploited by malicious users who launch scam attacks. Existing studies only deal with the attacks that use fabricated facial masks, while the liveness detection that targets the playback attacks using a virtual camera is still elusive. In this work, we develop a novel video chat liveness detection system, LiveScreen, which can track the weak light changes reflected off the skin of a human face leveraging chromatic eigenspace differences. We design an inconspicuous challenge frame with minimal intervention to the video chat and develop a robust anomaly frame detector to verify the liveness of the remote user in the video chat using the response to the challenge frame. Furthermore, we propose resilient defense strategies to defeat both naive and intelligent playback attacks leveraging spatial and temporal verification. We implemented a prototype over both laptop and smartphone platforms and conducted extensive experiments in various realistic scenarios. We show that our system can achieve robust liveness detection with accuracy and false detection rates 97.7% (94.8%) and 1% (1.6%) on smartphones (laptops), respectively. Hongbo Liu 0002, Yucheng Xie, Ruizhe Jiang, Yan Wang 0003, Xiaonan Guo 0003, Yingying Chen 0001 |
INFOCOM | 1 |
| 2020 | User authentication on mobile devices: Approaches, threats and trends
Chen Wang 0009, Yan Wang 0003, Yingying Chen 0001, Hongbo Liu 0002, Jian Liu 0001 |
Comput. Networks | 4 |
| 2019 | Poster: Video Chat Scam Detection Leveraging Screen Light ReflectionabstractThe rapid advancement of social media and communication technology enables video chat to become an important and convenient way of daily communication. However, such convenience also makes personal video clips easily obtained and exploited by malicious users who launch scam attacks. Existing studies only deal with the attacks that use fabricated facial masks, while the liveness detection that targets the playback attacks using a virtual camera is still elusive. In this work, we develop a novel video chat liveness detection system, which can track the weak light changes reflected off the skin of a human face leveraging chromatic eigenspace differences. We design an inconspicuous challenge frame with minimal intervention to the video chat and develop a robust anomaly frame detector to verify the liveness of remote user in a video chat session. Furthermore, we propose a resilient defense strategy to defeat both naive and intelligent playback attacks leveraging spatial and temporal verification. The evaluation results show that our system can achieve accurate and robust liveness detection with the accuracy and false detection rate as high as 97.7% (94.8%) and 1% (1.6%) on smartphones (laptops), respectively. Hongbo Liu 0002, Yucheng Xie, Ruizhe Jiang, Yan Wang 0003, Xiaonan Guo 0003, Yingying Chen 0001 |
MobiCom | 1 |
| 2019 | CardioCam: Leveraging Camera on Mobile Devices to Verify Users While Their Heart is PumpingabstractWith the increasing prevalence of mobile and IoT devices (e.g., smartphones, tablets, smart-home appliances), massive private and sensitive information are stored on these devices. To prevent unauthorized access on these devices, existing user verification solutions either rely on the complexity of user-defined secrets (e.g., password) or resort to specialized biometric sensors (e.g., fingerprint reader), but the users may still suffer from various attacks, such as password theft, shoulder surfing, smudge, and forged biometrics attacks. In this paper, we propose, CardioCam, a low-cost, general, hard-to-forge user verification system leveraging the unique cardiac biometrics extracted from the readily available built-in cameras in mobile and IoT devices. We demonstrate that the unique cardiac features can be extracted from the cardiac motion patterns in fingertips, by pressing on the built-in camera. To mitigate the impacts of various ambient lighting conditions and human movements under practical scenarios, CardioCam develops a gradient-based technique to optimize the camera configuration, and dynamically selects the most sensitive pixels in a camera frame to extract reliable cardiac motion patterns. Furthermore, the morphological characteristic analysis is deployed to derive user-specific cardiac features, and a feature transformation scheme grounded on Principle Component Analysis (PCA) is developed to enhance the robustness of cardiac biometrics for effective user verification. With the prototyped system, extensive experiments involving $25$ subjects are conducted to demonstrate that CardioCam can achieve effective and reliable user verification with over $99%$ average true positive rate (TPR) while maintaining the false positive rate (FPR) as low as $4%$. Jian Liu 0001, Cong Shi 0004, Yingying Chen 0001, Hongbo Liu 0002, Marco Gruteser |
MobiSys | 4 |
| 2019 | Implications of smartphone user privacy leakage from the advertiser's perspective
Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003, Hongbo Liu 0002, Jie Yang 0003 |
Pervasive Mob. Comput. | 4 |
| 2019 | Lip Reading-Based User Authentication Through Acoustic Sensing on SmartphonesabstractTo prevent users privacy from leakage, more and more mobile devices employ biometric-based authentication approaches, such as fingerprint, face recognition, voiceprint authentications, and so on, to enhance the privacy protection. However, these approaches are vulnerable to replay attacks. Although the state-of-art solutions utilize liveness verification to combat the attacks, existing approaches are sensitive to ambient environments, such as ambient lights and surrounding audible noises. Toward this end, we explore liveness verification of user authentication leveraging users mouth movements, which are robust to noisy environments. In this paper, we propose a lip reading-based user authentication system, LipPass, which extracts unique behavioral characteristics of users speaking mouths through acoustic sensing on smartphones for user authentication. We first investigate Doppler profiles of acoustic signals caused by users' speaking mouths and find that there are unique mouth movement patterns for different individuals. To characterize the mouth movements, we propose a deep learning-based method to extract efficient features from Doppler profiles and employ softmax function, support vector machine and support vector domain description to construct multi-class identifier, binary classifiers and spoofer detectors for mouth state identification, user identification and spoofer detection, respectively. Afterward, we develop a balanced binary tree-based authentication approach to accurately identify each individual leveraging these binary classifiers and spoofer detectors with respect to registered users. Through extensive experiments involving 48 volunteers in four real environments, LipPass can achieve 90.2% accuracy in user identification and 93.1% accuracy in spoofer detection. Li Lu 0008, Jiadi Yu, Yingying Chen 0001, Hongbo Liu 0002, Yanmin Zhu 0006, Linghe Kong, Minglu Li 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | LipPass: Lip Reading-based User Authentication on Smartphones Leveraging Acoustic SignalsabstractTo prevent users' privacy from leakage, more and more mobile devices employ biometric-based authentication approaches, such as fingerprint, face recognition, voiceprint authentications, etc., to enhance the privacy protection. However, these approaches are vulnerable to replay attacks. Although state-of-art solutions utilize liveness verification to combat the attacks, existing approaches are sensitive to ambient environments, such as ambient lights and surrounding audible noises. Towards this end, we explore liveness verification of user authentication leveraging users' lip movements, which are robust to noisy environments. In this paper, we propose a lip reading-based user authentication system, LipPass, which extracts unique behavioral characteristics of users' speaking lips leveraging build-in audio devices on smartphones for user authentication. We first investigate Doppler profiles of acoustic signals caused by users' speaking lips, and find that there are unique lip movement patterns for different individuals. To characterize the lip movements, we propose a deep learning-based method to extract efficient features from Doppler profiles, and employ Support Vector Machine and Support Vector Domain Description to construct binary classifiers and spoofer detectors for user identification and spoofer detection, respectively. Afterwards, we develop a binary tree-based authentication approach to accurately identify each individual leveraging these binary classifiers and spoofer detectors with respect to registered users. Through extensive experiments involving 48 volunteers in four real environments, LipPass can achieve 90.21% accuracy in user identification and 93.1% accuracy in spoofer detection. Li Lu 0008, Jiadi Yu, Yingying Chen 0001, Hongbo Liu 0002, Yanmin Zhu 0006, Minglu Li 0001 |
INFOCOM | 4 |
| 2018 | Multi - Touch in the Air: Device-Free Finger Tracking and Gesture Recognition via COTS RFIDabstractRecently, gesture recognition has gained considerable attention in emerging applications (e.g., AR/VR systems) to provide a better user experience for human-computer interaction. Existing solutions usually recognize the gestures based on wearable sensors or specialized signals (e.g., WiFi, acoustic and visible light), but they are either incurring high energy consumption or susceptible to the ambient environment, which prevents them from efficiently sensing the fine-grained finger movements. In this paper, we present RF-finger, a device-free system based on Commercial-Off-The-Shelf (COTS) RFID, which leverages a tag array on a letter-size paper to sense the fine-grained finger movements performed in front of the paper. Particularly, we focus on two kinds of sensing modes: finger tracking recovers the moving trace of finger writings; multi-touch gesture recognition identifies the multi-touch gestures involving multiple fingers. Specifically, we build a theoretical model to extract the fine-grained reflection feature from the raw RF -signal, which describes the finger influence on the tag array in cm- level resolution. For the finger tracking, we leverage K-Nearest Neighbors (KNN) to pinpoint the finger position relying on the fine-grained reflection features, and obtain a smoothed trace via Kalman filter. Additionally, we construct the reflection image of each multi-touch gesture from the reflection features by regarding the multiple fingers as a whole. Finally, we use a Convolutional Neural Network (CNN) to identify the multi-touch gestures based on the images. Extensive experiments validate that RF -finger can achieve as high as 88% and 92% accuracy for finger tracking and multi-touch gesture recognition, respectively. Jian Liu 0001, Yingying Chen 0001, Hongbo Liu 0002, Lei Xie 0004, Wei Wang 0002, Bingbing He, Sanglu Lu |
INFOCOM | 4 |
| 2018 | PPG-based Finger-level Gesture Recognition Leveraging WearablesabstractThis paper subverts the traditional understanding of Photoplethysmography (PPG) and opens up a new direction of the utility of PPG in commodity wearable devices, especially in the domain of human computer interaction of fine-grained gesture recognition. We demonstrate that it is possible to leverage the widely deployed PPG sensors in wrist-worn wearable devices to enable finger-level gesture recognition, which could facilitate many emerging human-computer interactions (e.g., sign-language interpretation and virtual reality). While prior solutions in gesture recognition require dedicated devices (e.g., video cameras or IR sensors) or leverage various signals in the environments (e.g., sound, RF or ambient light), this paper introduces the first PPG-based gesture recognition system that can differentiate fine-grained hand gestures at finger level using commodity wearables. Our innovative system harnesses the unique blood flow changes in a user's wrist area to distinguish the user's finger and hand movements. The insight is that hand gestures involve a series of muscle and tendon movements that compress the arterial geometry with different degrees, resulting in significant motion artifacts to the blood flow with different intensity and time duration. By leveraging the unique characteristics of the motion artifacts to PPG, our system can accurately extract the gesture-related signals from the significant background noise (i.e., pulses), and identify different minute finger-level gestures. Extensive experiments are conducted with over 3600 gestures collected from 10 adults. Our prototype study using two commodity PPG sensors can differentiate nine finger-level gestures from American Sign Language with an average recognition accuracy over 88%, suggesting that our PPG-based finger-level gesture recognition system is promising to be one of the most critical components in sign language translation using wearables. Tianming Zhao 0001, Jian Liu 0001, Yan Wang 0003, Hongbo Liu 0002, Yingying Chen 0001 |
INFOCOM | 4 |
| 2018 | Authenticating Users Through Fine-Grained Channel InformationabstractUser authentication is the critical first step in detecting identity-based attacks and preventing subsequent malicious attacks. However, the increasingly dynamic mobile environments make it harderto always apply cryptographic-based methods for user authentication due to their infrastructural and key management overhead. Exploiting non-cryptographic based techniques grounded on physical layer properties to perform user authentication appears promising. In this work, the use of channel state information (CSI), which is available from off-the-shelf WiFi devices, to perform fine-grained user authentication is explored. Particularly, a user-authentication framework that can work with both stationary and mobile users is proposed. When the user is stationary, the proposed framework builds a user profile for user authentication that is resilient to the presence of a spoofer. The proposed machine learning based user-authentication techniques can distinguish between two users even when they possess similar signal fingerprints and detect the existence of a spoofer. When the user is mobile, it is proposed to detect the presence of a spoofer by examining the temporal correlation of CSI measurements. Both office building and apartment environments show that the proposed framework can filter out signal outliers and achieve higher authentication accuracy compared with existing approaches using received signal strength (RSS). Hongbo Liu 0002, Yan Wang 0003, Jian Liu 0001, Jie Yang 0003, Yingying Chen 0001, H. Vincent Poor |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | SubTrack: Enabling Real-Time Tracking of Subway Riding on Mobile DevicesabstractReal-time tracking of subway riding will provide great convenience to millions of commuters in metropolitan areas. Traditional approaches using timetables need continuous attentions from the subway riders and are limited to the poor accuracy of estimating the travel time. Recent approaches using mobile devices rely on GSM and WiFi, which are not always available underground. In this work, we present SubTrack, utilizing sensors on mobile devices to provide automatic tracking of subway riding in real time. The real-time automatic tracking covers three major aspects of a passenger: detection of entering a station, tracking the passenger's position, and estimating the arrival time of subway stops. In particular, SubTrack employs the cell ID to first detect a passenger entering a station and exploits inertial sensors on the passenger's mobile device to track the train ride. Our algorithm takes the advantages of the unique vibrations in acceleration and typical moving patterns of the train to estimate the train's velocity and the corresponding position, and further predict the arrival time in real time. Our extensive experiments in two cities in China and USA respectively demonstrate that our system can accurately track the position of subway riders, predict the arrival time and push the arrival notification in a timely manner. Guo Liu, Jian Liu 0001, Fangmin Li, Xiaolin Ma, Yingying Chen 0001, Hongbo Liu 0002 |
MASS | 6 |
| 2017 | Smart User Authentication through Actuation of Daily Activities Leveraging WiFi-enabled IoTabstractUser authentication is a critical process in both corporate and home environments due to the ever-growing security and privacy concerns. With the advancement of smart cities and home environments, the concept of user authentication is evolved with a broader implication by not only preventing unauthorized users from accessing confidential information but also providing the opportunities for customized services corresponding to a specific user. Traditional approaches of user authentication either require specialized device installation or inconvenient wearable sensor attachment. This paper supports the extended concept of user authentication with a device-free approach by leveraging the prevalent WiFi signals made available by IoT devices, such as smart refrigerator, smart TV and thermostat, etc. The proposed system utilizes the WiFi signals to capture unique human physiological and behavioral characteristics inherited from their daily activities, including both walking and stationary ones. Particularly, we extract representative features from channel state information (CSI) measurements of WiFi signals, and develop a deep learning based user authentication scheme to accurately identify each individual user. Extensive experiments in two typical indoor environments, a university office and an apartment, are conducted to demonstrate the effectiveness of the proposed authentication system. In particular, our system can achieve over 94% and 91% authentication accuracy with 11 subjects through walking and stationary activities, respectively. Cong Shi 0004, Jian Liu 0001, Hongbo Liu 0002, Yingying Chen 0001 |
MobiHoc | 3 |
| 2017 | WiFi-Enabled Smart Human Dynamics MonitoringabstractThe rapid pace of urbanization and socioeconomic development encourage people to spend more time together and therefore monitoring of human dynamics is of great importance, especially for facilities of elder care and involving multiple activities. Traditional approaches are limited due to their high deployment costs and privacy concerns (e.g., camera-based surveillance or sensor-attachment-based solutions). In this work, we propose to provide a fine-grained comprehensive view of human dynamics using existing WiFi infrastructures often available in many indoor venues. Our approach is low-cost and device-free, which does not require any active human participation. Our system aims to provide smart human dynamics monitoring through participant number estimation, human density estimation and walking speed and direction derivation. A semi-supervised learning approach leveraging the non-linear regression model is developed to significantly reduce training efforts and accommodate different monitoring environments. We further derive participant number and density estimation based on the statistical distribution of Channel State Information (CSI) measurements. In addition, people's walking speed and direction are estimated by using a frequency-based mechanism. Extensive experiments over 12 months demonstrate that our system can perform fine-grained effective human dynamic monitoring with over 90% accuracy in estimating participants number, density, and walking speed and direction at various indoor environments. Xiaonan Guo 0003, Bo Liu 0058, Cong Shi 0004, Hongbo Liu 0002, Yingying Chen 0001, Mooi Choo Chuah |
SenSys | 4 |
| 2017 | Enabling Self-Healing Smart Grid Through Jamming Resilient Local Controller SwitchingabstractA key component of a smart grid is its ability to collect useful information from a power grid for enabling control centers to estimate the current states of the power grid. Such information can be delivered to the control centers via wireless or wired networks. It is envisioned that wireless technology will be widely used for local-area communication subsystems in the smart grid (e.g., in distribution networks). However, various attacks with serious impact can be launched in wireless networks such as channel jamming attacks and denial-of-service attacks. In particular, jamming attacks can cause significant damages to power grids, e.g., delayed delivery of time-critical messages can prevent control centers from properly controlling the outputs of generators to match load demands. In this paper, a communication subsystem with enhanced self-healing capability in the presence of jamming is designed via intelligent local controller switching while integrating a retransmission mechanism. The proposed framework allows sufficient readings from smart meters to be continuously collected by various local controllers to estimate the states of a power grid under various attack scenarios. The jamming probability is also analyzed considering the impact of jammer power and shadowing effects. In addition, guidelines on optimal placement of local controllers to ensure effective switching of smart meters under jamming are provided. Via theoretical, experimental and simulation studies, it is demonstrated that our proposed system is effective in maintaining communications between smart meters and local controllers even when multiple jammers are present in the network. Hongbo Liu 0002, Yingying Chen 0001, Mooi Choo Chuah, Jie Yang 0003, H. Vincent Poor |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Uber-in-light: Unobtrusive visible light communication leveraging complementary color channelabstractRecently, Visible Light Communication (VLC) over a screen-camera channel has drawn considerable attention to unobtrusive design. It overcomes the distractive nature of traditional coded image approaches (e.g., barcodes). Previous unobtrusive methods fall into two categories: 1) utilizing alpha channel, a well known concept in computer graphics, to encode bits into the pixel translucency change with off-the-shelf smart devices; and 2) leveraging the spatial-temporal flicker-fusion property of human vision system with the fast frame rate of modern displays. However, these approaches heavily rely on high-end devices to achieve both unobtrusive and high accuracy screen-camera-based data communication without affecting video-viewing experience. Unlike previous approaches, we propose Uber-in-light, a novel unobtrusive and accurate VLC system, that enables real-time screen-camera communication, applicable to any screen and camera. The proposed system encodes the data as complementary intensity changes over Red, Green, and Blue (RGB) color channels that could be successfully decoded by camera while leaving the human visual perception unaffected. We design a MFSK modulation scheme with dedicated frame synchronization signal embedded in an orthogonal color channel to achieve high throughput. Furthermore, together with the complementary color intensity, an enhanced MUSIC-based demodulation scheme is developed to ensure highly accurate data transmission. Our user experience experiments confirmed the effectiveness of delivering unobtrusive data across different types of video content and resolutions. Extensive real-time performance evaluations are conducted using our prototype implementation to demonstrate the efficiency and reliability of the proposed system under diverse wireless environments. Mostafa Izz, Zhong Yuan Li, Hongbo Liu 0002, Yingying Chen 0001 |
INFOCOM | 3 |
| 2016 | Determining Driver Phone Use by Exploiting Smartphone Integrated SensorsabstractThis paper utilizes smartphone sensing of vehicle dynamics to determine driver phone use, which can facilitate many traffic safety applications. Our system uses embedded sensors in smartphones, i.e., accelerometers and gyroscopes, to capture differences in centripetal acceleration due to vehicle dynamics. These differences combined with angular speed can determine whether the phone is on the left or right side of the vehicle. Our low infrastructure approach is flexible with different turn sizes and driving speeds. Extensive experiments conducted with two vehicles in two different cities demonstrate that our system is robust to real driving environments. Despite noisy sensor readings from smartphones, our approach can achieve a classification accuracy of over 90 percent with a false positive rate of a few percent. We also find that by combining sensing results in a few turns, we can achieve better accuracy (e.g., 95 percent) with a lower false positive rate. In addition, we seek to exploit the electromagnetic field measurement inside a vehicle to complement vehicle dynamics for driver phone sensing under the scenarios when little vehicle dynamics is present, for example, driving straight on highways or standing at roadsides. Yan Wang 0003, Yingying Chen 0001, Jie Yang 0003, Marco Gruteser, Richard P. Martin, Hongbo Liu 0002, Çagdas Karatas |
IEEE Trans. Mob. Comput. | 6 |
| 2015 | Towards Understanding the Advertiser's Perspective of Smartphone User PrivacyabstractMany smartphone apps routinely gather various private user data and send them to advertisers. Despite recent study on protection mechanisms and analysis on apps' behavior, the understanding about the consequences of such privacy losses remains limited. In this paper we investigate how much an advertiser can infer about users' social and community relationships by combining data from multiple applications and across many users. After one month's user study involving about 200 most popular Android apps, we find that an advertiser can infer 90% of the social relationships. We further propose a privacy leakage inference framework and use real mobility traces and Foursquare data to quantify the consequences of privacy leakage. We find that achieving 90% inference accuracy of the social and community relationships requires merely 3 weeks' user data. The discoveries underscore the importance of early adoption of privacy protection mechanisms. Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003, Jie Yang 0003, Hongbo Liu 0002 |
ICDCS | 5 |
| 2015 | Distributed Consensus-Based Weight Design for Cooperative Spectrum SensingabstractWe study the distributed spectrum sensing in cognitive radio networks. Existing distributed consensus-based fusion algorithms only ensure equal gain combining of local measurements, whose performance may be incomparable to various centralized soft combining schemes. Motivated by this fact, we consider practical channel conditions and link failures, and develop new weighted soft measurement combining without a centralized fusion center. Following the measurement by its energy detector, each secondary user exchanges its own measurement statistics with its local one-hop neighbors, and chooses the information exchanging rate according to the measurement channel condition, e.g., the signal-to-noise ratio (SNR). We rigorously prove the convergence of the new consensus algorithm, and show all secondary users hold the same global decision statistics from the weighted soft measurement combining throughout the network. We also provide distributed optimal weight design under uncorrelated measurement channels. The convergence rate of the consensus iteration is given under the assumption that each communication link has an independent probability to fail, and the upper bound of the iteration number of the$ \epsilon$-convergence is explicitly given as a function of system parameters. Simulation results show significant improvement of the sensing performance compared to existing consensus-based approaches, and the performance of the distributed weighted design is comparable to the centralized weighted combining scheme. Yi Guo 0004, Hongbo Liu 0002, Yingying Chen 0001, Zheng Wang 0009, Joseph Mitola III |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | Practical user authentication leveraging channel state information (CSI)abstractUser authentication is the critical first step to detect identity-based attacks and prevent subsequent malicious attacks. However, the increasingly dynamic mobile environments make it harder to always apply the cryptographic-based methods for user authentication due to their infrastructural and key management overhead. Exploiting non-cryptographic based techniques grounded on physical layer properties to perform user authentication appears promising. In this work, we explore to use channel state information (CSI), which is available from off-the-shelf WiFi devices, to conduct fine-grained user authentication. We propose an user-authentication framework that has the capability to build the user profile resilient to the presence of the spoofer. Our machine learning based user-authentication techniques can distinguish two users even when they possess similar signal fingerprints and detect the existence of the spoofer. Our experiments in both office building and apartment environments show that our framework can filter out the signal outliers and achieve higher authentication accuracy compared with existing approaches using received signal strength (RSS). Hongbo Liu 0002, Yan Wang 0003, Jian Liu 0001, Jie Yang 0003, Yingying Chen 0001 |
AsiaCCS | 1 |
| 2014 | E-eyes: device-free location-oriented activity identification using fine-grained WiFi signaturesabstractActivity monitoring in home environments has become increasingly important and has the potential to support a broad array of applications including elder care, well-being management, and latchkey child safety. Traditional approaches involve wearable sensors and specialized hardware installations. This paper presents device-free location-oriented activity identification at home through the use of existing WiFi access points and WiFi devices (e.g., desktops, thermostats, refrigerators, smartTVs, laptops). Our low-cost system takes advantage of the ever more complex web of WiFi links between such devices and the increasingly fine-grained channel state information that can be extracted from such links. It examines channel features and can uniquely identify both in-place activities and walking movements across a home by comparing them against signal profiles. Signal profiles construction can be semi-supervised and the profiles can be adaptively updated to accommodate the movement of the mobile devices and day-to-day signal calibration. Our experimental evaluation in two apartments of different size demonstrates that our approach can achieve over 96% average true positive rate and less than 1% average false positive rate to distinguish a set of in-place and walking activities with only a single WiFi access point. Our prototype also shows that our system can work with wider signal band (802.11ac) with even higher accuracy. Yan Wang 0003, Jian Liu 0001, Yingying Chen 0001, Marco Gruteser, Jie Yang 0003, Hongbo Liu 0002 |
MobiCom | 6 |
| 2014 | Tracking human queues using single-point signal monitoringabstractWe investigate using smartphone WiFi signals to track human queues, which are common in many business areas such as retail stores, airports, and theme parks. Real-time monitoring of such queues would enable a wealth of new applications, such as bottleneck analysis, shift assignments, and dynamic workflow scheduling. We take a minimum infrastructure approach and thus utilize a single monitor placed close to the service area along with transmitting phones. Our strategy extracts unique features embedded in signal traces to infer the critical time points when a person reaches the head of the queue and finishes service, and from these inferences we derive a person's waiting and service times. We develop two approaches in our system, one is directly feature-driven and the second uses a simple Bayesian network. Extensive experiments conducted both in the laboratory as well as in two public facilities demonstrate that our system is robust to real-world environments. We show that in spite of noisy signal readings, our methods can measure service and waiting times to within a $10$ second resolution. Yan Wang 0003, Jie Yang 0003, Yingying Chen 0001, Hongbo Liu 0002, Marco Gruteser, Richard P. Martin |
MobiSys | 4 |
| 2014 | Accurate WiFi Based Localization for Smartphones Using Peer AssistanceabstractHighly accurate indoor localization of smartphones is critical to enable novel location based features for users and businesses. In this paper, we first conduct an empirical investigation of the suitability of WiFi localization for this purpose. We find that although reasonable accuracy can be achieved, significant errors (e.g., 6 8m) always exist. The root cause is the existence of distinct locations with similar signatures, which is a fundamental limit of pure WiFi-based methods. Inspired by high densities of smartphones in public spaces, we propose a peer assisted localization approach to eliminate such large errors. It obtains accurate acoustic ranging estimates among peer phones, then maps their locations jointly against WiFi signature map subjecting to ranging constraints. We devise techniques for fast acoustic ranging among multiple phones and build a prototype. Experiments show that it can reduce the maximum and 80-percentile errors to as small as 2m and 1m, in time no longer than the original WiFi scanning, with negligible impact on battery lifetime. Hongbo Liu 0002, Jie Yang 0003, Simon Sidhom, Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003 |
IEEE Trans. Mob. Comput. | 1 |
| 2014 | Group Secret Key Generation via Received Signal Strength: Protocols, Achievable Rates, and ImplementationabstractSecret key generation among wireless devices using physical layer information of radio channel has been an attractive alternative for ensuring security in mobile environments. Received signal strength (RSS) based secret key extraction gains much attention due to its easy accessibility in wireless infrastructure. However, the problem of using RSS to generate keys among multiple devices to ensure secure group communication in practice remains open. In this work, we propose a framework for collaborative key generation among multiple wireless devices leveraging RSS. To deal with mobile devices not within each other’s communication range, we employ relay nodes to achieve reliable key extraction. To enable secure group communication, two protocols are developed to perform collaborative group key generation via star and chain topologies respectively. We further provide the theoretic analysis on the achievable secrecy rate for both star and chain topologies in the presence of an eavesdropper. Our prototype development using MICAz motes and extensive experiments using fading trend based key extraction demonstrate the feasibility of using RSS for group key generation in both indoor and outdoor environments, and concurrently achieving a lower bit mismatch rate compared to existing studies. Hongbo Liu 0002, Jie Yang 0003, Yan Wang 0003, Yingying Chen 0001, Can Emre Koksal |
IEEE Trans. Mob. Comput. | 1 |
| 2014 | Defending against Frequency-Based Attacks on Distributed Data Storage in Wireless NetworksabstractAs wireless networks become more pervasive, the amount of the wireless data is rapidly increasing. One of the biggest challenges of wide adoption of distributed data storage is how to store these data securely. In this work, we study the frequency-based attack, a type of attack that is different from previously well-studied ones, that exploits additional adversary knowledge of domain values and/or their exact/approximate frequencies to crack the encrypted data. To cope with frequency-based attacks, the straightforward 1-to-1 substitution encryption functions are not sufficient. We propose a data encryption strategy based on 1-to- n substitution via dividing and emulating techniques to defend against the frequency-based attack, while enabling efficient query evaluation over encrypted data. We further develop two frameworks, incremental collection and clustered collection, which are used to defend against the global frequency-based attack when the knowledge of the global frequency in the network is not available. Built upon our basic encryption schemes, we derive two mechanisms, direct emulating and dual encryption, to handle updates on the data storage for energy-constrained sensor nodes and wireless devices. Our preliminary experiments with sensor nodes and extensive simulation results show that our data encryption strategy can achieve high security guarantee with low overhead. Hongbo Liu 0002, Wendy Hui Wang, Yingying Chen 0001, Dayong Jia |
ACM Trans. Sens. Networks | 1 |
| 2014 | An Error-Minimizing Framework for Localizing Jammers in Wireless NetworksabstractJammers can severely disrupt the communications in wireless networks, and jammers' position information allows the defender to actively eliminate the jamming attacks. Thus, in this paper, we aim to design a framework that can localize one or multiple jammers with a high accuracy. Most of existing jammer-localization schemes utilize indirect measurements (e.g., hearing ranges) affected by jamming attacks, which makes it difficult to localize jammers accurately. Instead, we exploit a direct measurement-the strength of jamming signals (JSS). Estimating JSS is challenging as jamming signals may be embedded in other signals. As such, we devise an estimation scheme based on ambient noise floor and validate it with real-world experiments. To further reduce estimation errors, we define an evaluation feedback metric to quantify the estimation errors and formulate jammer localization as a nonlinear optimization problem, whose global optimal solution is close to jammers' true positions. We explore several heuristic search algorithms for approaching the global optimal solution, and our simulation results show that our error-minimizing-based framework achieves better performance than the existing schemes. In addition, our error-minimizing framework can utilize indirect measurements to obtain a better location estimation compared with prior work. Zhenhua Liu 0005, Hongbo Liu 0002, Wenyuan Xu 0001, Yingying Chen 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | A Study of Localization Accuracy Using Multiple Frequencies and PowersabstractWireless localization using the received signal strength (RSS) can have tremendous savings over using specialized positioning infrastructures. In this work, we explore improving RSS localization performance in multipath environments by varying the transmitter's signal power and frequency. We first derive and analyze the Cramér-Rao Lower Bound (CRLB) of RSS-based localization based on the frequency dependent path loss propagation model that considers the transmitter's signal power and frequency. The derived CRLB shows the feasibility of improving localization performance by applying frequency and power level selection for RSS-based localization. Using this analysis, we develop two new selection metrics based on the observed standard deviations of RSS as well as residuals. We then show a set of selection methods that attempt to select the combinations of power and frequencies which minimize the localization error in a representative class of localization algorithms. Our simulation results confirm the proposed selection methods can improve the localization accuracy under CRLB. Additionally, using active RFID tags, we experimentally characterize the effect of using multiple signal powers and frequencies on a wide spectrum of RSS-based algorithms. We found that the performance of all the algorithms improves when leveraging on multiple power levels and frequencies, although different algorithms present different sensitivity in terms of localization accuracy under different selection methods. Xiuyuan Zheng, Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001, Richard P. Martin |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Fast and practical secret key extraction by exploiting channel responseabstractSecuring wireless communication remains challenging in dynamic mobile environments due to the shared nature of wireless medium and lacking of fixed key management infrastructures. Generating secret keys using physical layer information thus has drawn much attention to complement traditional cryptographic-based methods. Although recent work has demonstrated that Received Signal Strength (RSS) based secret key extraction is practical, existing RSS-based key generation techniques are largely limited in the rate they generate secret bits and are mainly applicable to mobile wireless networks. In this paper, we show that exploiting the channel response from multiple Orthogonal Frequency-Division Multiplexing (OFDM) subcarriers can provide fine-grained channel information and achieve higher bit generation rate for both static and mobile cases in real-world scenarios. We further develop a Channel Gain Complement (CGC) assisted secret key extraction scheme to cope with channel non-reciprocity encountered in practice. Our extensive experiments using WiFi networks in both indoor as well as outdoor environments demonstrate that our approach can achieve significantly faster secret bit generation rate at 60 ~ 90bit/packet, and is resilient to malicious attacks identified to be harmful to RSS-based techniques including predictable channel attack and stalking attack. Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001 |
INFOCOM | 1 |
| 2013 | Measuring human queues using WiFi signalsabstractWe investigate using smartphone WiFi signals to track human queues, which are common in many business areas such as retail stores, airports, and theme parks. Real-time monitoring of such queues would enable a wealth of new applications, such as bottleneck analysis, shift assignments, and dynamic workflow scheduling. We take a minimum infrastructure approach and thus utilize a single monitor placed close to the service area along with transmitting phones. Our strategy extracts unique features embedded in the signal traces to infer the critical time points when a person reaches the head of the queue and finishes service, and from these inferences we derive a person's waiting and service times. We develop a feature driven approach in our system. Extensive experiments conducted both in the laboratory demonstrate that our system is robust to queues with different waiting time. We show that in spite of noisy signal readings, our methods can measure important time periods in queue (e.g., service and waiting times) to within a $10$ second resolution. Yan Wang 0003, Jie Yang 0003, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser, Richard P. Martin |
MobiCom | 3 |
| 2013 | Sensing vehicle dynamics for determining driver phone useabstractThis paper utilizes smartphone sensing of vehicle dynamics to determine driver phone use, which can facilitate many traffic safety applications. Our system uses embedded sensors in smartphones, i.e., accelerometers and gyroscopes, to capture differences in centripetal acceleration due to vehicle dynamics. These differences combined with angular speed can determine whether the phone is on the left or right side of the vehicle. Our low infrastructure approach is flexible with different turn sizes and driving speeds. Extensive experiments conducted with two vehicles in two different cities demonstrate that our system is robust to real driving environments. Despite noisy sensor readings from smartphones, our approach can achieve a classification accuracy of over $90\%$ with a false positive rate of a few percent. We also find that by combining sensing results in a few turns, we can achieve better accuracy (e.g., $95\%$) with a lower false positive rate. Yan Wang 0003, Jie Yang 0003, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser, Richard P. Martin |
MobiSys | 3 |
| 2013 | Neighborhood prediction based decentralized key management for mobile wireless networks
Xiuyuan Zheng, Yingying Chen 0001, Wendy Hui Wang, Hongbo Liu 0002 |
Wirel. Networks | 4 |
| 2012 | Collaborative secret key extraction leveraging Received Signal Strength in mobile wireless networksabstractSecuring communication in mobile wireless networks is challenging because the traditional cryptographic-based methods are not always applicable in dynamic mobile wireless environments. Using physical layer information of radio channel to generate keys secretly among wireless devices has been proposed as an alternative in wireless mobile networks. And the Received Signal Strength (RSS) based secret key extraction gains much attention due to the RSS readings are readily available in wireless infrastructure. However, the problem of using RSS to generate keys among multiple devices to ensure secure group communication remains open. In this work, we propose a framework for collaborative key generation among a group of wireless devices leveraging RSS. The proposed framework consists of a secret key extraction scheme exploiting the trend exhibited in RSS resulted from shadow fading, which is robust to outsider adversary performing stalking attacks. To deal with mobile devices not within each other's communication range, we employ relay nodes to achieve reliable key extraction. To enable secure group communication, two protocols, namely star-based and chain-based, are developed in our framework by exploiting RSS from multiple devices to perform group key generation collaboratively. Our experiments in both outdoor and indoor environments confirm the feasibility of using RSS for group key generation among multiple wireless devices under various mobile scenarios. The results also demonstrate that our collaborative key extraction scheme can achieve a lower bit mismatch rate compared to existing works when maintaining the comparable bit generation rate. Hongbo Liu 0002, Jie Yang 0003, Yan Wang 0003, Yingying Chen 0001 |
INFOCOM | 1 |
| 2012 | Error minimizing jammer localization through smart estimation of ambient noiseabstractJammer can jeopardize the dependability of wireless networks, and jammer's position information allows the network to cope with jamming leveraging varieties of defense strategies. Thus, in this paper, we address the problem of localizing jammer. Prior work relies on indirect measurements derived from jamming effects, which makes it difficult to accurately localize jammer. We localize jammer by directly using the strength of jamming signals (JSS). Estimating JSS is challenging as they may be embedded in other signals. As such, we devise an estimation scheme based on ambient noise floor and validate it with real world experiments. To improve localization accuracy, we define an evaluation feedback metric to quantify the estimation errors and formulate jammer localization as a nonlinear optimization problem, whose optimal solution approaches jammer's true position. We exploit a heuristic search based algorithm for approximating the global optimal solution, and our extensive simulation shows that our error-minimizing-based algorithm outperforms existing algorithms. Zhenhua Liu 0005, Hongbo Liu 0002, Wenyuan Xu 0001, Yingying Chen 0001 |
MASS | 2 |
| 2012 | Push the limit of WiFi based localization for smartphonesabstractHighly accurate indoor localization of smartphones is critical to enable novel location based features for users and businesses. In this paper, we first conduct an empirical investigation of the suitability of WiFi localization for this purpose. We find that although reasonable accuracy can be achieved, significant errors (e.g., $6\sim8m$) always exist. The root cause is the existence of distinct locations with similar signatures, which is a fundamental limit of pure WiFi-based methods. Inspired by high densities of smartphones in public spaces, we propose a peer assisted localization approach to eliminate such large errors. It obtains accurate acoustic ranging estimates among peer phones, then maps their locations jointly against WiFi signature map subjecting to ranging constraints. We devise techniques for fast acoustic ranging among multiple phones and build a prototype. Experiments show that it can reduce the maximum and 80-percentile errors to as small as $2m$ and $1m$, in time no longer than the original WiFi scanning, with negligible impact on battery lifetime. Hongbo Liu 0002, Yu Gan 0003, Jie Yang 0003, Simon Sidhom, Yan Wang 0003, Yingying Chen 0001, Fan Ye 0003 |
MobiCom | 1 |
| 2012 | Extracting jamming signals to locate radio interferers and jammersabstractNo abstract available. Zhenhua Liu 0005, Hongbo Liu 0002, Wenyuan Xu 0005, Yingying Chen 0001 |
MobiHoc | 2 |
| 2012 | Sensing Driver Phone Use with Acoustic Ranging through Car SpeakersabstractThis work addresses the fundamental problem of distinguishing between a driver and passenger using a mobile phone, which is the critical input to enable numerous safety and interface enhancements. Our detection system leverages the existing car stereo infrastructure, in particular, the speakers and Bluetooth network. Our acoustic approach has the phone send a series of customized high frequency beeps via the car stereo. The beeps are spaced in time across the left, right, and if available, front and rear speakers. After sampling the beeps, we use a sequential change-point detection scheme to time their arrival, and then use a differential approach to estimate the phone's distance from the car's center. From these differences a passenger or driver classification can be made. To validate our approach, we experimented with two kinds of phones and in two different cars. We found that our customized beeps were imperceptible to most users, yet still playable and recordable in both cars. Our customized beeps were also robust to background sounds such as music and wind, and we found the signal processing did not require excessive computational resources. In spite of the cars' heavy multipath environment, our approach had a classification accuracy of over 90 percent, and around 95 percent with some calibrations. We also found, we have a low false positive rate, on the order of a few percent. Jie Yang 0003, Simon Sidhom, Gayathri Chandrasekaran, Tam Vu 0001, Hongbo Liu 0002, Nicolae Cecan, Yingying Chen 0001, Marco Gruteser, Richard P. Martin |
IEEE Trans. Mob. Comput. | 5 |
| 2012 | Exploiting Jamming-Caused Neighbor Changes for Jammer LocalizationabstractJamming attacks are especially harmful when ensuring the dependability of wireless communication. Finding the position of a jammer will enable the network to actively exploit a wide range of defense strategies. In this paper, we focus on developing mechanisms to localize a jammer by exploiting neighbor changes. We first conduct jamming effect analysis to examine how the communication range alters with the jammer's location and transmission power using free-space model. Then, we show that a node's affected communication range can be estimated purely by examining its neighbor changes caused by jamming attacks and thus, we can perform the jammer location estimation by solving a least-squares (LSQ) problem that exploits the changes of communication range. Compared with our previous iterative-search-based virtual force algorithm, our LSQ-based algorithm exhibits lower computational cost (i.e., one step instead of iterative searches) and higher localization accuracy. Furthermore, we analyze the localization challenges in real systems by building the log-normal shadowing model empirically and devising an adaptive LSQ-based algorithm to address those challenges. The extensive evaluation shows that the adaptive LSQ-based algorithm can effectively estimate the location of the jammer even in a highly complex propagation environment. Zhenhua Liu 0005, Hongbo Liu 0002, Wenyuan Xu 0001, Yingying Chen 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2011 | Distributed Cooperative Spectrum Sensing Based on Weighted Average ConsensusabstractIn this paper, we study the distributed spectrum sensing in cognitive radio networks. Using weighted average consensus algorithm, we develop a weighted soft measurement combining scheme without the centralized fusion center. After the measurement by the energy detector, each secondary user (SU) exchanges their own measurement statistics with its local neighbors, and chooses the information exchanging rate according to the estimated average signal-to-noise ratio (SNR). We prove the convergence of the consensus iteration, and each SU will hold the global decision statistics from the weighted soft measurement combining throughout the network. The proposed scheme is robust with respect to temporary communication link failures. Simulation results show our method has a better performance than the existing average consensus-based approach. Zheng Wang 0009, Yi Guo 0004, Hongbo Liu 0002, Yingying Chen 0001, Joseph Mitola III |
GLOBECOM | 4 |
| 2011 | Localizing Multiple Jamming Attackers in Wireless NetworksabstractJamming attacks and unintentional radio interference are one of the most urgent threats harming the dependability of wireless communication and endangering the successful deployment of pervasive applications built on top of wireless networks. Unlike the traditional approaches focusing on developing jamming defense techniques without considering the location of jammers, we take a different viewpoint that the jammers' position should be identified and exploited for building a wide range of defense strategies to alleviate jamming. In this paper, we address the problem of localizing multiple jamming attackers coexisting in wireless networks by leveraging the network topology changes caused by jamming. We systematically analyze the jamming effects and develop a framework that can partition network topology into clusters and can successfully estimate the positions of multiple jammers even when their jamming areas are overlapping. Our experiments on a multi-hop network setup using MicaZ sensor nodes validate the feasibility of real-time collection of network topology changes under jamming and our extensive simulation results demonstrate that our approach is highly effective in localizing multiple attackers with or without the prior knowledge of the order that the jammers are turned on. Hongbo Liu 0002, Zhenhua Liu 0005, Yingying Chen 0001, Wenyuan Xu 0001 |
ICDCS | 1 |
| 2011 | Detecting driver phone use leveraging car speakersabstractThis work addresses the fundamental problem of distinguishing between a driver and passenger using a mobile phone, which is the critical input to enable numerous safety and interface enhancements. Our detection system leverages the existing car stereo infrastructure, in particular the speakers and Bluetooth network. Our acoustic approach has the phone send a series of customized high frequency beeps via the car stereo. The beeps are spaced in time across the left, right, and if available, front and rear speakers. After sampling the beeps, we use a sequential change-point detection scheme to time their arrival, and then use a differential approach to estimate the phone's distance from the car's center. From these differences a passenger or driver classification can be made. To validate our approach, we experimented with two kinds of phones and in two different cars. We found that our customized beeps were imperceptible to most users, yet still playable and recordable in both cars. Our customized beeps were also robust to background sounds such as music and wind, and we found the signal processing did not require excessive computational resources. In spite of the cars' heavy multi-path environment, our approach had a classification accuracy of over 90%, and around 95% with some calibrations. We also found we have a low false positive rate, on the order of a few percent. Jie Yang 0003, Simon Sidhom, Gayathri Chandrasekaran, Tam Vu 0001, Hongbo Liu 0002, Nicolae Cecan, Yingying Chen 0001, Marco Gruteser, Richard P. Martin |
MobiCom | 5 |
| 2011 | Determining the position of a jammer using a virtual-force iterative approach
Hongbo Liu 0002, Zhenhua Liu 0005, Yingying Chen 0001, Wenyuan Xu 0001 |
Wirel. Networks | 1 |
| 2011 | Metadata-guided evaluation of resource-constrained queries in content caching based wireless networks
Xiuyuan Zheng, Hongbo Liu 0002, Wendy Hui Wang, Yingying Chen 0001 |
Wirel. Networks | 3 |
| 2010 | Wireless Jamming Localization by Exploiting Nodes' Hearing Ranges
Zhenhua Liu 0005, Hongbo Liu 0002, Wenyuan Xu 0001, Yingying Chen 0001 |
DCOSS | 2 |
| 2010 | Ensuring Data Storage Security against Frequency-Based Attacks in Wireless Networks
Hongbo Liu 0002, Wendy Hui Wang, Yingying Chen 0001 |
DCOSS | 1 |
| 2010 | Accuracy characterization of cell tower localizationabstractCell tower triangulation is a popular technique for determining the location of a mobile device. However, cell tower triangulation methods require the knowledge of the actual locations of cell towers. Because the locations of cell towers are not publicly available, these methods often need to use estimated tower locations obtained through wardriving. This paper provides the first large scale study of the accuracy of two existing methods for cell tower localization using wardriving data. The results show that naively applying these methods results in very large localization errors. We analyze the causes for these errors and conclude that one can localize a cell accurately only if it falls within the area covered by the wardriving trace. We further propose a bounding technique to select the cells that fall within the area covered by the wardriving trace and identify a cell combining optimization that can further reduce the localization error by half. Jie Yang 0003, Alexander Varshavsky, Hongbo Liu 0002, Yingying Chen 0001, Marco Gruteser |
UbiComp | 3 |
| 2010 | Performing Joint Learning for Passive Intrusion Detection in Pervasive Wireless EnvironmentsabstractRecent years have witnessed increasing interests in passive intrusion detection for wireless environments, e.g., asset protection in industrial facilities and emergency rescue of trapped people. Most previous studies have focused primarily on exploiting a single intrusion indicator, such as moving variance, for capturing an intrusion pattern at a time. However, in real-world, there are many intrusion patterns which may be only detectable by combining different intrusion indicators and performing detection jointly. To this end, we propose a joint intrusion learning approach, which has the ability in combining the detection power of several complementary intrusion indicators and detects different intrusion patterns at the same time. We developed the GREEK algorithm, which utilizes grid-based clustering over K-neighborhood to effectively diagnose the presence of intrusions. Further, we show that the performance of intrusion detection can be enhanced by utilizing the collaborative detecting efforts among multiple transmitter-receiver pairs. To validate the effectiveness of the joint intrusion learning method, we conducted experiments in a real-office environment using an IEEE 802.15.4 (Zigbee) network. Our experimental results provide strong evidence of the effectiveness of our joint learning approach in performing passive intrusion detection with a minimized false positive rate. Jie Yang 0003, Yong Ge 0001, Hui Xiong 0001, Yingying Chen 0001, Hongbo Liu 0002 |
INFOCOM | 5 |
| 2010 | Characterizing the impact of multi-frequency and multi-power on localization accuracyabstractWireless localization using the received signal strength (RSS) can have tremendous savings over using specialized positioning infrastructures. In this work, we explore improving RSS localization performance in multipath environments by varying the transmitter's signal power and frequency. Using a theoretical analysis, we first show how selection of different signal powers and frequencies can improve localization accuracy for the least squares algorithm. We next develop a set of selection methods that attempt to select the combinations of power and frequencies which minimize the localization error. Our selection methods are based on the observed standard deviations of RSS as well as algorithm specific residuals. Using active RFID tags, we experimentally characterize the effect of using multiple signal powers and frequencies on a wide spectrum of RSS-based algorithms. We found that the performance of all the algorithms improves when leveraging on multiple power levels and frequencies, although different algorithms present different sensitivity in terms of localization accuracy under different selection methods. Xiuyuan Zheng, Hongbo Liu 0002, Jie Yang 0003, Yingying Chen 0001, John-Austen Francisco, Richard P. Martin |
MASS | 2 |
| 2010 | A decentralized key management scheme via neighborhood prediction in mobile wireless networksabstractThe wireless data collected in mobile environments provides tremendous opportunities to build new applications in various domains such as Vehicular Ad Hoc Networks and mobile social networks. One of the biggest challenges is how to store these data. Storing the data decentralized in wireless devices is an attractive approach because of its major advantages over centralized ones. In this work, to facilitate effective access control of the wireless data in distributed data storage, we propose a fully decentralized key management scheme by utilizing a cryptography-based secret sharing method. The secret sharing method splits the keys into multiple shares and distributes them to multiple nodes, which brings the challenge that due to node mobility, these key shares may not be available in the neighborhood when they are needed for key reconstruction. To address this challenge arising from mobile environments, we propose the Transitive Prediction(TRAP) protocol that distributes key shares among devices that are traveling together. We derive a theoretical analysis of the robustness of our approach. Furthermore, inside TRAP, we develop three key distribution schemes that utilize the correlation relationship embedded among devices that are traveling together. Our key distribution schemes maximize the chance of successful key reconstruction and minimize the communication overhead. Our extensive simulation results demonstrate that our key distribution schemes are highly effective, and thus provide strong evidence of the feasibility of applying our approach to support distributed data storage in wireless networks. Xiuyuan Zheng, Wendy Hui Wang, Yingying Chen 0001, Hongbo Liu 0002 |
MASS | 4 |
| 2008 | Self-localization based on improved subspace approach in wireless sensor networkabstractIn this paper, an improved subspace approach based on range measurement is proposed and analyzed. Through the factorization of multidimensional similarity (MDS) matrix, we derive a novel kernel subspace to estimate the coordinate of unknown mobile node in wireless sensor networks (WSN). Simulation results are included to contrast the estimator performance with general subspace method, and the performance analysis is provided. Hongbo Liu 0002 |
AICCSA | 1 |