EDBT 2026 Demo / reviewers in the wild / expert
Kai Zeng 0001
dblp:80/1651-1
· DBLP profile ↗
114ranked-venue papers
12as first author
35since 2021 · last 2026
0000-0003-3279-0695ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 79 · 10 first-author · 19 since 2021Security and privacy · 22 · 11 since 2021Artificial intelligence and machine learning · 6 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fine-Grained Privacy Control for OFDM-based Integrated Sensing and Communication
Farshad Soleiman, Long Jiao, Kai Zeng 0001 |
INFOCOM | 5 |
| 2026 | WirelessSenseLLM: Zero-Shot Human Activity Understanding by Bridging Wireless Signals and Human Language
MahmudaAkter Keya, Sneh Pillai, Kai Zeng 0001, Long Jiao |
SECON | 4 |
| 2025 | StealthInk: A Multi-bit and Stealthy Watermark for Large Language ModelsabstractWatermarking for large language models (LLMs) offers a promising approach to identifying AI-generated text. Existing approaches, however, either compromise the distribution of original generated text by LLMs or are limited to embedding zero-bit information that only allows for watermark detection but ignores identification. We present StealthInk, a stealthy multi-bit watermarking scheme that preserves the original text distribution while enabling the embedding of provenance data, such as userID, TimeStamp, and modelID, within LLM-generated text. This enhances fast traceability without requiring access to the language model’s API or prompts. We derive a lower bound on the number of tokens necessary for watermark detection at a fixed equal error rate, which provides insights on how to enhance the capacity. Comprehensive empirical evaluations across diverse tasks highlight the stealthiness, detectability, and resilience of StealthInk, establishing it as an effective solution for LLM watermarking applications. Ya Jiang, Chuxiong Wu, Massieh Kordi Boroujeny, Brian L. Mark, Kai Zeng 0001 |
ICML | 5 |
| 2025 | DroneMA: Drone Mobility Alignment Countering AI-Based Spoofing Attacks
Weiyang Li, Ning Wang 0003, Chuan Ma 0001, Tao Xiang 0001, Kai Zeng 0001 |
INFOCOM | 5 |
| 2025 | NeuroGenPoisoning: Neuron-Guided Attacks on Retrieval-Augmented Generation of LLM via Genetic Optimization of External KnowledgeabstractRetrieval-Augmented Generation (RAG) empowers Large Language Models (LLMs) to dynamically integrate external knowledge during inference, improving their factual accuracy and adaptability. However, adversaries can inject poisoned external knowledge to override the model’s internal memory. While existing attacks iteratively manipulate retrieval content or prompt structure of RAG, they largely ignore the model’s internal representation dynamics and neuron-level sensitivities. The underlying mechanism of RAG poisoning has not been fully studied and the effect of knowledge conflict with strong parametric knowledge in RAG is not considered. In this work, we propose NeuroGenPoisoning, a novel attack framework that generates adversarial external knowledge in RAG guided by LLM internal neuron attribution and genetic optimization. Our method first identifies a set of **Poison-Responsive Neurons** whose activation strongly correlates with contextual poisoning knowledge. We then employ a genetic algorithm to evolve adversarial passages that maximally activate these neurons. Crucially, our framework enables massive-scale generation of effective poisoned RAG knowledge by identifying and reusing promising but initially unsuccessful external knowledge variants via observed attribution signals. At the same time, Poison-Responsive Neurons guided poisoning can effectively resolves knowledge conflict. Experimental results across models and datasets demonstrate consistently achieving high Population Overwrite Success Rate (POSR) of over 90\% while preserving fluency. Empirical evidence shows that our method effectively resolves knowledge conflict. Hanyu Zhu 0001, Lance Fiondella, Kai Zeng 0001, Long Jiao |
NeurIPS | 4 |
| 2025 | Key Generation and Secrecy Analysis Using OTFS for TDD SystemsabstractPhysical layer key generation techniques aim to extract secret keys from the information contained in wireless channels. However, existing key generation schemes often rely on time-frequency domain waveforms for channel estimation, which not only makes secret extraction less reliable but may also compromise the confidentiality of the extracted secret information. This paper presents physical layer key generation methods relying on the Orthogonal Time Frequency and Space (OTFS) waveform. We present analysis showing that the delay-Doppler domain channel estimates obtained using OTFS are conducive to more secure and reliable secret extraction than time-frequency domain channel estimates obtained using the prevalent Orthogonal Frequency Division Multiplexing (OFDM). This analysis provides theoretical guarantees under certain simple assumptions. We then relax those assumptions in extensive time-division duplex (TDD) simulations and show that under realistic settings, OTFS offers the expected benefits to reliability and security. Our simulations show that the introduced OTFS schemes can reliably extract secret keys from channel estimates in scenarios where time-frequency domain methods deteriorate. Usama Saeed, A. Robert Calderbank, Kai Zeng 0001, Elizabeth S. Bentley, Lauren Huie-Seversky, Karim A. Said, Lingjia Liu 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2024 | Swipe2Pair: Secure and Fast In-Band Wireless Device PairingabstractWireless device pairing is a critical security mechanism to bootstrap the secure communication between two devices without a pre-shared secret. It has been widely used in many Internet of Things (IoT) applications, such as smarthome and smarthealth. Most existing device pairing mechanisms are based on out-of-band channels, e.g., extra sensors or hardware, to validate the location proximity of pairing devices. However, out-of-band channels are not universal on all wireless devices, thus this type of scheme is limited to certain application scenarios or conditions. On the other hand, in-band channel-based device pairing aims at universal applicability by only relying on wireless interfaces. Existing in-band channel-based pairing schemes either require multiple antennas separated in a good distance on one pairing devices which is not applicable in certain scenarios, or require users to repeat multiple sweeps which is not optimal in terms of usability. Therefore, an in-band wireless device pairing scheme providing high security while maintaining good usability (simple pairing process and user interaction) is highly desired. In this work, we propose an easy-to-use mutual authentication device pairing scheme, named Swipe2Pair, based on location proximity of pairing devices and wireless transmission power randomization. We conduct extensive security analysis and collect considerable experimental data under various settings in different environments. Experimental results show that Swipe2Pair achieves high security and usability. It only takes less than one second to complete the pairing process with a simple swipe of one device in front of the other. Yaqi He, Kai Zeng 0001, Long Jiao, Brian L. Mark, Khaled N. Khasawneh |
WISEC | 2 |
| 2024 | BGKey: Group Key Generation for Backscatter Communications Among Multiple DevicesabstractBackscatter communication (BC) is an emerging radio technology for achieving sustainable wireless communications. However, the literature still lacks an effective secret group key generation scheme for safeguarding communications among multiple resource-constrained backscatter devices (BDs). In this paper, we propose a novel physical layer group key generation framework, BGKey, for securing backscatter communications among multiple BDs. BGKey contains three schemes: Centralized Group Key Generation (CGKG), Decentralized Group Key Generation (DGKG), and Decentralized Hierarchical Group Key Generation (DHGKG). Each scheme has its own advantages, applicable in different scenarios. We analyze the performance of BGKey schemes regarding computation and communication complexity and security under eavesdropping and three active attacks. We conduct extensive simulations with different system parameters to evaluate their performance. CGKG is the most efficient and accurate for generating a group key, but it depends on a trusted radio frequency source (RFS) and is the least secure under eavesdropping and three active attacks among three schemes. DGKG exhibits better security and higher key generation rate (KGR) against eavesdropping and three active attacks compared with CGKG. However, the bit disagreement ratio (BDR) of group key increases when the size of BD group increases. DHGKG dramatically enhances the performance of group key generation compared with DGKG and retains its excellent security against eavesdropping and three active attacks. Pu Wang 0003, Zheng Yan 0002, Yishan Yang, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Efficient Group Key Generation Based on Satellite Cluster State Information for Drone SwarmabstractIn the context of drone swarms, achieving efficient group secure communication is a challenging problem, due to the inherent limitations imposed by the drones’ limited energy and constrained resources. Physical layer group key generation (PLGK) is a promising technology to enable efficient group security communication. However, most existing PLGK schemes struggle to adapt to the dynamic nature of drone swarms. To address this gap, this paper proposes a novel satellite cluster state information (SCSI)-based PLGK, which leverages signal status information from all visible navigation satellites to establish the group key. The presented method utilizes the regional similarity of SCSI as a random information source to generate group keys between different drones, and employs a novel updating framework based on a fuzzy generator and a hash chain to enhance key update and alignment robustness. The proposed scheme not only significantly reduces the overhead of group key generation also mitigates the issues of key loss and reconstruction. The security of the proposed scheme is validated through formal protocol security proof and security analysis against possible attacks. Finally, experiments with real-world drones demonstrate the efficiency and effectiveness of the SCSI-based PLGK. Ning Wang 0003, Jixuan Duan, Biwen Chen, Shangwei Guo, Tao Xiang 0001, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | BatchAuth: A Physical Layer Batch Authentication Scheme for Multiple Backscatter DevicesabstractBackscatter communication (BC) offers a promising power-efficient communication paradigm for wireless devices with constrained energy resources. However, the innate openness and broadcast characteristics of BC raise considerable security concerns. To address this, physical layer authentication has emerged as a primary solution to enable secure BC. To facilitate efficient authentication on multiple backscatter devices (BDs), batch authentication becomes essential. Nevertheless, existing schemes have not yet bridged the research gap regarding effective batch authentication on mobile BDs with high scalability support. This paper proposes BatchAuth, a physical layer batch authentication scheme designed to authenticate multiple BDs simultaneously by leveraging orthogonal frequency-division multiple access (OFDMA) technology. BatchAuth utilizes two factors, received signal strength (RSS) and multiple channel impulse responses (CIRs), to authenticate a group of BDs and leverages a channel correlation coefficient to offset performance loss and support BD dynamicity. What’s more, a backscatter waveform design facilitates an access point (AP) in estimating the CIRs from backscattered signals. Additionally, BatchAuth possesses the capability to detect and trace potential attackers by analyzing the specific characteristics of orthogonal subcarriers to facilitate countermeasure. In particular, BatchAuth demonstrates significant potential on scalability in large-scale BC systems and multiple-input multiple-output (MIMO) systems. Theoretical analysis on BatchAuth security and extensive simulations under various settings by comparing with cutting-edge schemes further validate its commendable performance with regard to accuracy, robustness, efficiency, and scalability. Yishan Yang, Niya Luo, Zheng Yan 0002, Yifan Zhang 0042, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | BatAu: A Batch Authentication Scheme for Backscatter Devices in a Smart Home NetworkabstractWith the maturity of the Internet of Things (IoT), many IoT applications have been popularized and promoted. As one of the IoT technology, backscatter communication (BC) has aroused research interest due to its low-cost and ultra-low power consumption characteristics. Due to their simple design and battery-less functionalities, backscatter devices (BDs) have been introduced as the main candidates for deploying in smart home networks (SHN). Although batch authentication in BC systems is crucial and efficient for SHN security, existing schemes have only focused on radio frequency identification (RFID) devices and no literature has given a general solution for BD batch authentication. In this paper, we propose a scheme named BatAu for authenticating batch BDs applied in SHN by extracting physical layer features in multiplexing signals. We conduct numerical simulations with various settings to show its desirable performance. Yishan Yang, Masoud Kaveh, Yifan Zhang 0042, Zheng Yan 0002, Kai Zeng 0001 |
ICC | 6 |
| 2023 | Realizing Uplink MU-MIMO Communication in mmWave WLANs: Bayesian Optimization and Asynchronous Transmission
Shichen Zhang 0001, Bo Ji 0001, Kai Zeng 0001, Huacheng Zeng |
INFOCOM | 3 |
| 2023 | Privacy-Preserving Federated Learning With Malicious Clients and Honest-but-Curious ServersabstractFederated learning (FL) enables multiple clients to jointly train a global learning model while keeping their training data locally, thereby protecting clients’ privacy. However, there still exist some security issues in FL, e.g., the honest-but-curious servers may mine privacy from clients’ model updates, and the malicious clients may launch poisoning attacks to disturb or break global model training. Moreover, most previous works focus on the security issues of FL in the presence of only honest-but-curious servers or only malicious clients. In this paper, we consider a stronger and more practical threat model in FL, where the honest-but-curious servers and malicious clients coexist, named as the non-fully trusted model. In the non-fully trusted FL, privacy protection schemes for honest-but-curious servers are executed to ensure that all model updates are indistinguishable, which makes malicious model updates difficult to detect. Toward this end, we present an Adaptive Privacy-Preserving FL (Ada-PPFL) scheme with Differential Privacy (DP) as the underlying technology, to simultaneously protect clients’ privacy and eliminate the adverse effects of malicious clients on model training. Specifically, we propose an adaptive DP strategy to achieve strong client-level privacy protection while minimizing the impact on the prediction accuracy of the global model. In addition, we introduce DPAD, an algorithm specifically designed to precisely detect malicious model updates, even in cases where the updates are protected by DP measures. Finally, the theoretical analysis and experimental results further illustrate that the proposed Ada-PPFL enables client-level privacy protection with 35% DP-noise savings, and maintains similar prediction accuracy to models without malicious attacks. Junqing Le, Di Zhang 0011, Long Jiao, Kai Zeng 0001, Xiaofeng Liao 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Security Analysis of Triangle Channel-Based Physical Layer Key Generation in Wireless Backscatter CommunicationsabstractAmbient backscatter communication (AmBC) enables ultra-low-power communications by backscattering ambient radio frequency (RF) signals and harvesting energy simultaneously. It has emerged as a cutting-edge technology for supporting a variety of Internet of Things (IoT) applications. However, existing research lacks effective secret key sharing schemes for safeguarding communications between resource-constrained backscatter devices (BDs) in AmBC systems. In this paper, we present, Tri-Channel, a novel physical layer key generation scheme between two BDs by multiplying downlink signals and backscatter signals to obtain the information of a triangle channel as a shared random secret source for key generation. In particular, we analyze the security of our scheme under both passive and active attacks, concretely Eavesdropping Attack (EA), Control Channel Attack (CCA), Signal Manipulative Attack (SMA), and Untrusted RF-Source Attack (URSA). Through theoretical analysis and simulations by comparing with a traditional scheme (named Tradi-Channel), we found that our scheme consistently outperforms the Tradi-Channel under the EA and two active attacks (CCA and SMA). In addition, it shows better security performance under URSA, which is proposed based on the unauthenticated characteristic of BDs in Tri-Channel, even though URSA is more vital than SMA. Concretely, Tri-Channel’s secret key rate (SKR) outperforms Tradi-Channel’s under the above four passive and active attacks. This implies that our scheme is advanced in terms of both security and efficiency of key generation. Numerous extensive simulations further prove our theoretical analysis results. Pu Wang 0003, Long Jiao, Zheng Yan 0002, Kai Zeng 0001, Yishan Yang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Federated Graph Neural Network for Fast Anomaly Detection in Controller Area NetworksabstractDue to the lack of CAN frame encryption and authentication, CAN bus is vulnerable to various attacks, which can in general be divided into message injection, suspension, and falsification. Existing CAN bus anomaly detection mechanisms either can only detect one or two of these attacks, or require numerous CAN messages during predictions, which can hardly realize real-time performance. In this paper, we propose a CAN bus anomaly detection system that can detect all these attacks simultaneously in as short as 3 milliseconds (ms) based on Graph Neural Network (GNN). This work generates directed attributed graphs based on CAN message streams in given message intervals. Node attributes denote data contents in CAN messages while each edge attribute represents the frequency of a typical CAN ID pair in the given interval. Afterwards, a GNN is trained based on generated CAN message graphs. Considering highly imbalanced training data, a two-stage classifier cascade is developed in this paper, which is composed of a one-class classifier for anomaly detection and a multi-class classifier for attack classification. An openmax layer is further introduced to the multi-class classifier to tackle new anomalies from unknown classes. To take advantage of crowdsourcing while protecting user data privacy, we adopt federated learning to train a universal model that covers different driving scenarios and vehicle states. Extensive experiment results show the effectiveness and efficiency of our methodology. Hengrun Zhang 0001, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Self-Unaware Adversarial Multi-Armed Bandits With Switching CostsabstractWe study a family of adversarial (a.k.a. nonstochastic) multi-armed bandit (MAB) problems, wherein not only the player cannot observe the reward on the played arm (self-unaware player) but also it incurs switching costs when shifting to another arm. We study two cases: In Case 1, at each round, the player is able to either play or observe the chosen arm, but not both. In Case 2, the player can choose an arm to play and, at the same round, choose another arm to observe. In both cases, the player incurs a cost for consecutive arm switching due to playing or observing the arms. We propose two novel online learning-based algorithms each addressing one of the aforementioned MAB problems. We theoretically prove that the proposed algorithms for Case 1 and Case 2 achieve sublinear regret of O(√[4]KT3lnK) and O(√[3](K-1)T2lnK) , respectively, where the latter regret bound is order-optimal in time, K is the number of arms, and T is the total number of rounds. In Case 2, we extend the player's capability to multiple observations and show that more observations do not necessarily improve the regret bound due to incurring switching costs. However, we derive an upper bound for switching cost as c ≤ 1/√[3]m2 for which the regret bound is improved as the number of observations increases. Finally, through this study, we found that a generalized version of our approach gives an interesting sublinear regret upper bound result of [Formula: see text] for any self-unaware bandit player with s number of binary decision dilemma before taking the action. To further validate and complement the theoretical findings, we conduct extensive performance evaluations over synthetic data constructed by nonstochastic MAB environment simulations and wireless spectrum measurement data collected in a real-world experiment. Amir Alipour-Fanid, Monireh Dabaghchian, Kai Zeng 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2022 | Characterization of AES Implementations on Microprocessor-based IoT DevicesabstractThe increased proliferation of IoT devices and the emergence of 5G networks have necessitated increased security of data storage and communication in such connected devices. Thus, cryptography is used in IoT environments to provide secrecy and integrity to the data as well as both authentication and anonymity to the communications across the IoT network. However, IoT devices are resource-constrained devices; have limited memory, network bandwidth, power, and compute units. Since most of the existing cryptographic algorithms were designed to run on resource powerful devices (e.g., desktops or servers), many of these algorithms may not fit into resource-constrained devices. Therefore, in this work, we present a practical performance analysis of different implementations of the Advanced Encryption Standard (AES), which is the most widely used symmetric-key cryptosystem in the IoT environment. Specifically, we explore execution times, energy consumption, and memory usage of the different AES implementations across 4 different public libraries. Furthermore, our analysis is done using various modes, key sizes, plaintext sizes, and microprocessor-based IoT devices. Our results show that for the same combination of inputs and a given algorithm, different crypto library implementations give results with widely varying relative differences. As per the obtained results, the PyCryptodome library seems to be the most suitable one in terms of both execution time and energy on a resource-constrained IoT device and has the most efficient memory usage. Sunanda Roy, Angelos Stavrou, Brian L. Mark, Kai Zeng 0001, Sai Manoj Pudukotai Dinakarrao, Khaled N. Khasawneh |
WCNC | 4 |
| 2022 | Sharing Secrets via Wireless Broadcasting: A New Efficient Physical Layer Group Secret Key Generation for Multiple IoT DevicesabstractWith the increasing demands for sharing confidential information among massive Internet of Things (IoT) devices in 5G and beyond wireless networks, many applications require the common secret key generation for a group of IoT devices. However, most of the existing works on physical layer secret key generation (PLKG) only focus on the pairwise key generation between two users, which is a low efficient and high cost to be extended to the scenarios of group key generation. In this work, we propose a new efficient multiple-input–multiple-output (MIMO) physical layer group secret key generation scheme to reduce the consumption of channel probing and improve the efficiency for group key generation. Different from current schemes, in the proposed scheme, the transmitter randomly generates the group secret key and directly broadcasts the downlink data symbols to the group users. At the receiver end, each group user can efficiently “observe” the common group key through the downlink broadcasting data symbols, while keeping perfect secrecy of the shared group key against eavesdroppers. The performance of reliability, security, and the group key generation rate is fully investigated, which shows the advantages of high efficiency, low consumption, and strong robustness of the proposed scheme. Extensive simulations are conducted to validate the effectiveness of the proposed scheme. Jie Tang 0005, Hong Wen 0001, Huanhuan Song 0001, Long Jiao, Kai Zeng 0001 |
IEEE Internet Things J. | 5 |
| 2022 | Orientation and Channel-Independent RF Fingerprinting for 5G IEEE 802.11ad DevicesabstractPhysical-layer fingerprinting is a promising technique to identify Internet of Things (IoT) devices. In this article, we investigate a new radio-frequency (RF) fingerprinting based on the distinctive signal-to-noise-ratio (SNR) trace in the sector-level sweep (SLS) procedure of 5G IEEE 802.11ad devices. This SLS SNR trace-based fingerprinting can directly apply to off-the-shelf devices without any extra hardware requirements and be independent of the wireless channel and environment. To tackle the impact of orientation on the RF fingerprinting, we propose a novel fingerprinting framework, involving correlation analysis, surface fitting, curve pursuing, and binary classification, named the CSCB framework. Using this framework, the proposed SLS SNR trace-based fingerprinting can achieve device authentication at any orientation with one receiver under line-of-sight (LOS) or non-LOS (NLOS) scenarios. We conduct proof-of-concept experiments using off-the-shelf IEEE 802.11ad devices (Talon AD7200 and MG360 WiGig) to evaluate the performance of the proposed fingerprinting schemes. Experimental results show the effectiveness of the proposed fingerprinting schemes where the verification accuracy of the proposed scheme can reach 99% with only 200 training samples. Ning Wang 0003, Weiwei Li 0002, Long Jiao, Amir Alipour-Fanid, Tao Xiang 0001, Kai Zeng 0001 |
IEEE Internet Things J. | 6 |
| 2022 | AuthIoT: A Transferable Wireless Authentication Scheme for IoT Devices Without Input InterfaceabstractWireless Internet of Things (IoT) applications have penetrated every aspect of our society and become increasingly important in smart homes, smart cities, and smart hospitals. However, many WiFi-based IoT devices (e.g., light switches, door/window open alert sensors, and Google Home) do not have input interfaces such as keypad or touchscreen due to their limits in physical size, power consumption, and/or manufacturing cost, making it inconvenient and onerous for end users to authenticate those IoT devices for wireless Internet access. In this article, we present AuthIoT, a learning-based authentication scheme for wireless IoT devices without input interfaces. The key component of AuthIoT is a channel state information (CSI)-based character classification algorithm for a WiFi access point (AP), which recognizes the passcode from an IoT device when an end user holds it in hand and writes the passcode over the air. AuthIoT has two salient features: 1) it is transferable for cross-environment applications and 2) it works in more realistic scenarios where AP is equipped with nonlinear antenna array. We have built a prototype of AuthIoT and evaluated its performance on two testbeds: 1) Intel 5300 WiFi card with three linear antennas and 2) USRP N310 with four nonlinear (square-shaped) antennas. The experimental results show that AuthIoT achieves 84% and 83% recognition accuracy on the two testbeds. Shichen Zhang 0001, Pedram Kheirkhah Sangdeh, Hossein Pirayesh, Huacheng Zeng, Qiben Yan 0001, Kai Zeng 0001 |
IEEE Internet Things J. | 6 |
| 2022 | Communication-Aware Secret Share Placement in Hierarchical Edge ComputingabstractSecret sharing (SS) and secure multiparty computation (MPC) are now widely considered for privacy-preserving data processing. However, related applications can suffer from large transmission overhead. In this article, we propose a communication-aware secret share placement strategy to optimize communication overhead by minimizing transmission hop counts in a hierarchical edge computing architecture. Meanwhile, relevant privacy constraints in SS can still be guaranteed. We show that the constructed optimization problem is NP-hard, and efficient heuristic algorithms can be applied to find suboptimal solutions. With this consideration, we first evaluate two traditional heuristics, i.e., the genetic algorithm (GA) and particle swarm optimization (PSO). Besides, we introduce two basic heuristics, i.e., top-down and bottom-up heuristic, which can outperform GA and PSO in certain cases. Finally, we propose an algorithm, called bottom-up top-down (BUTD) heuristic, which can outperform all of the above four heuristics when communication among different shares of the same secret is comparable to that among different secrets. Comprehensive experimental results demonstrate the advantage of the proposed algorithms. Hengrun Zhang 0001, Kai Zeng 0001 |
IEEE Internet Things J. | 2 |
| 2022 | BCAuth: Physical Layer Enhanced Authentication and Attack Tracing for Backscatter CommunicationsabstractBackscatter communication (BC) enables ultra-low-power communications and allows devices to harvest energy simultaneously. But its practical deployment faces severe security threats caused by its nature of openness and broadcast. Authenticating backscatter devices (BDs) is treated as the first line of defense. However, complex cryptographic approaches are not desirable due to the limited computation capability of BDs. Existing physical layer authentication schemes cannot effectively support BD mobility, multiple attacker identification and attacker location tracing in an integrated way. To tackle these problems, this paper proposes BCAuth, a multi-stage authentication and attack tracing scheme based on the physical spatial information of BDs to realize enhanced BD authentication security for both static and mobile BDs. After initial authentication based on BD identity with its position information registration, preemptive authentication and re-authentication are performed according to spatial correlation of backscattered signal source locations associated with the BD. By exploiting clustering-based analysis on spacial information, BCAuth is capable of determining the number of attackers and localizing their positions. In addition, we propose a reciprocal channel-based method for BD re-authentication with better authentication performance than the clustering-based method for mobile BDs when the BDs is able to measure received signal strength (RSS), which also enables mutual authentication. We theoretically analyze BCAuth security and conduct extensive numerical simulations with various settings to show its desirable performance. Pu Wang 0003, Zheng Yan 0002, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Identity-Based Attack Detection and Classification Utilizing Reciprocal RSS Variations in Mobile Wireless NetworksabstractIdentity-based attacks (IBAs) are one of the most serious threats to wireless networks. Recently, there is an increasing interest in using the received signal strength (RSS) to detect IBAs in wireless networks. However, current schemes tend to generate excessive false alarms in the mobile scenario. In this paper, we propose a stronger Reciprocal Channel Variation-based Identification and classification (RCVIC) scheme for the mobile wireless networks, which exploits the reciprocity of the wireless fading channel and RSS variations naturally incurred by mobility to improve the detection performance. Different from current schemes only detect IBAs, RCVIC scheme conducts a multi-stage detection processes. If the IBAs are detected, RCVIC scheme partitions the received frames into two classes. The frames in the same class should be sent from the same senders, which could benefit the further analysis, such as network forensics, attacker localizing and trajectory analysis, etc. The feasibility of RCVIC are numerically evaluated through theoretical analysis and simulations. It is further validated through experiments using off-the-shelf 802.11 devices under different attacking patterns in real indoor and outdoor mobile scenarios. Jie Tang 0005, Long Jiao, Kai Zeng 0001, Hong Wen 0001, Kannan Govindan 0001, Daniel Wu, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | Enabling Efficient Blockage-Aware Handover in RIS-Assisted mmWave Cellular NetworksabstractRecently, networks operate at frequencies over 28 GHz (mmWave) have emerged as a viable solution for 5G mobile networks to provide Gbps data rate. Due to the high directivity and attenuation of mmWave signals, mmWave communication links are highly vulnerable to the frequent mmWave channel blockages, which can trigger excessive handovers. Thanks to its ability to enrich the scattering environment and create reflective signal multipaths, Reconfigurable Intelligent Surface (RIS) has great potential to counter the blockage effect and thus greatly reduce the number of unnecessary handovers. However, this potential has not been well explored. In this paper, we propose a RIS-assisted handover scheme by leveraging deep reinforcement learning (DRL). Under various channel blockage conditions, the DRL agent manages to reduce the cumulative handover overhead by jointly adjusting beamformers and RIS phase shifts. Compared with the existing schemes without considering RIS, the RIS-assisted handover scheme significantly reduces the number of handovers and achieves higher spectrum efficiency. Besides, to alleviate the impact from the limited observations of the fast fading channels, we propose a lightweight algorithm to sense the blockage status and such sensing results can be utilized to improve the performance of model training. Numerical results show that DRL agent is able to further improve the performance when integrated with the blockage status sensing algorithm. Long Jiao, Pu Wang 0003, Amir Alipour-Fanid, Huacheng Zeng, Kai Zeng 0001 |
IEEE Trans. Wirel. Commun. | 5 |
| 2022 | Resource Allocation Optimization for Secure Multidevice Wirelessly Powered Backscatter Communication With Artificial NoiseabstractWirelessly powered backscatter communications (WPBC) is an emerging technology for providing continuous energy and ultra-low power communications. Despite some progress in WPBC systems, resource allocation for multiple devices towards secure backscatter communications (BC) and efficient-energy harvesting (EH) requests a deep-insight investigation. In this paper, we consider a WPBC system in which a full-duplex access point (AP) transmits multi-sinewave signals to power backscatter devices (BDs) and injects artificial noise (AN) to secure their backscatter transmissions. To maximize the minimum harvested energy and ensure fairness and security of all BDs, we formulate an optimization problem by jointly considering the backscatter time, power splitting ratio between multi-sinewave and AN, and signal power allocation. For a single-BD system, we characterize the achievable secrecy rate-energy region with a non-linear energy harvester and propose two algorithms to solve an energy maximization problem. We then analyze the effect of multi-sinewave and AN signals on BD’s secrecy rate and harvested energy through simulations and proof-of-concept experiments. For a multi-BD system, we propose an iterative algorithm by leveraging block successive upper-bound minimization (BSUM) techniques to solve the non-convex problem of fair resource allocation and show its convergence and complexity. Numerical results show the proposed algorithm achieves optimal and equitable harvested energy for all BDs with satisfying the security constraint. Pu Wang 0003, Zheng Yan 0002, Ning Wang 0003, Kai Zeng 0001 |
IEEE Trans. Wirel. Commun. | 4 |
| 2022 | Friendly spectrum jamming against MIMO eavesdropping
Rong Jin 0002, Kai Zeng 0001 |
Wirel. Networks | 2 |
| 2021 | Physical Layer Key Generation between Backscatter Devices over Ambient RF SignalsabstractAmbient backscatter communication (AmBC), which enables energy harvesting and ultra-low-power communication by utilizing ambient radio frequency (RF) signals, has emerged as a cutting-edge technology to realize numerous Internet of Things (IoT) applications. However, the current literature lacks efficient secret key sharing solutions for resource-limited devices in AmBC systems to protect the backscatter communications, especially for private data transmission. Thus, we propose a novel physical layer key generation scheme between backscatter devices (BDs) by exploiting received superposed ambient signals. Based on the repeated patterns (i.e., cyclic prefix in OFDM symbols) in ambient RF signals, we present a joint transceiver design of BD backscatter waveform and BD receiver to extract the downlink signal and the backscatter signal from the superposed signals. By multiplying the downlink signal and the backscatter signal, we can actually obtain the triangle channel information as a shared random secret source for key generation. Besides, we study the trade-off between the rate of secret key generation and harvested energy by modeling it as a joint optimization problem. Finally, extensive numerical simulations are provided to evaluate the key generation performance, energy harvesting performance, and their trade-offs under various system settings. Pu Wang 0003, Long Jiao, Kai Zeng 0001, Zheng Yan 0002 |
INFOCOM | 3 |
| 2021 | Online-Learning-Based Defense Against Jamming Attacks in Multichannel Wireless CPSabstractWe study security of remote state estimation in wireless cyber-physical systems (CPS) where a sensor sends its measurements to the remote state estimator over a multichannel wireless link in presence of a jamming attacker. Most of the existing works study the sensor's defense scheme by adopting optimization-based methods and rely on the prior knowledge of the attacker's attack policy. To relax this constraint, we propose a novel online-learning-based policy called joint channel and power selection (J-CAP) for the sensor to dynamically choose transmission channel and power. The proposed method assumes no prior knowledge of the attacker's attack policy, nor of the channel state information. J-CAP jointly optimizes sensor's channel selection and power consumption, and guarantees the estimator's asymptotic stability. We theoretically prove that J-CAP achieves a sublinear learning regret bound. We also show J-CAP's optimality by deriving and matching its regret lower and upper bound orders. Compared with the solution that directly applies the baseline solution, J-CAP improves the regret upper bound by a factor of √{K+L}, where K and L denote the number of channels and number of power levels, respectively. Numerical evaluations validate the analytical results under various CPS parameters, and compare the J-CAP's performance with the state-of-the-art solutions. Amir Alipour-Fanid, Monireh Dabaghchian, Ning Wang 0003, Long Jiao, Kai Zeng 0001 |
IEEE Internet Things J. | 5 |
| 2021 | Federated Continuous Learning With Broad Network ArchitectureabstractFederated learning (FL) is a machine-learning setting, where multiple clients collaboratively train a model under the coordination of a central server. The clients' raw data are locally stored, and each client only uploads the trained weight to the server, which can mitigate the privacy risks from the centralized machine learning. However, most of the existing FL models focus on one-time learning without consideration for continuous learning. Continuous learning supports learning from streaming data continuously, so it can adapt to environmental changes and provide better real-time performance. In this article, we present a federated continuous learning scheme based on broad learning (FCL-BL) to support efficient and accurate federated continuous learning (FCL). In FCL-BL, we propose a weighted processing strategy to solve the catastrophic forgetting problem, so FCL-BL can handle continuous learning. Then, we develop a local-independent training solution to support fast and accurate training in FCL-BL. The proposed solution enables us to avoid using a time-consuming synchronous approach while addressing the inaccurate-training issue rooted in the previous asynchronous approach. Moreover, we introduce a batch-asynchronous approach and broad learning (BL) technique to guarantee the high efficiency of FCL-BL. Specifically, the batch-asynchronous approach reduces the number of client-server interaction rounds, and the BL technique supports incremental learning without retraining when learning newly produced data. Finally, theoretical analysis and experimental results further illustrate that FCL-BL is superior to the existing FL schemes in terms of efficiency and accuracy in FCL. Junqing Le, Nankun Mu, Hengrun Zhang 0001, Kai Zeng 0001, Xiaofeng Liao 0001 |
IEEE Trans. Cybern. | 5 |
| 2021 | Manipulative Attack Against Physical Layer Key Agreement and CountermeasureabstractPhysical layer key agreement techniques derive a symmetric cryptographic key from the wireless fading channel between two wireless devices by exploiting channel randomness and reciprocity. Current efforts have focused mainly on the security issue and protocol design of the techniques under passive attack and jamming attack. In this paper, we raise the subject of manipulative attack. The attacker wants the keying devices to actually agree on some valid, but manipulated bits. We discuss the feasibility and different means to launch manipulative attack. Aiming at a practical countermeasure, we further propose PHY-UIR (PHYsical layer key agreement with User Introduced Randomness). Both keying devices generate and use random voltage levels X = {x[1], x[2] ... x[N]} and Y = {y[1], y[2] ... y[N]} to exchange probing frames over reciprocal random fading channels H = {h[1], h[2] ... h[N]}. At receiving end, they multiply the received channel measurements XH and YH with the random sequences Y and X to compose a common keying sequence XYH. With this solution, the attacker can no longer manipulate the keying sequences established at legitimate sides and infer the subsequent key. We analyze the security strength of PHY-UIR and conduct extensive simulations to evaluate it. We also perform proof-of-concept experiments by using software defined radios in a real-world environment. Both simulations and experiments demonstrate the effectiveness of PHY-UIR. Rong Jin 0002, Kai Zeng 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Physical Layer Secure MIMO Communications Against Eavesdroppers With Arbitrary Number of AntennasabstractRecently, MIMO (multiple-input-multiple-output) physical layer secure transmission has attracted great attentions. However, current schemes cannot defend against the passive eavesdroppers with arbitrary number of antennas. To address this problem, in this work, we propose a practical physical layer MIMO secure communication scheme (PLSC) to defend against such an eavesdropper with arbitrary number of antennas. In the proposed scheme, the transmitter first independently generates a random binary sequence as the “key bits (KB)” to “encrypt” (XOR) the confidential information. After that, the transmitter sends the “encrypted information” over the wireless channel, along with mapping key bits to the legitimate receiver simultaneously. The key principle lies in that the KB information is coded in the indexes of the activated/non-activated antennas combination of the legitimate user. Then, the legitimate receiver first observes his/her activated antenna indexes to obtain the corresponding key bits. After that, he/she demodulates the “encrypted information” at the activated antennas, and finally “decrypts” (XOR) the confidential information by using the observed key bits. However, due to the uniqueness and independence of MIMO wireless channel, for any other eavesdroppers who suffer an independent channel from legitimate users, we prove that it cannot observe any information about KB from the received signals, regardless of how many antennas it has used. Consequently, without knowledge of KB, it cannot decrypt any information about the confidential information, too. The reliability and security of PLSC are theoretically demonstrated. The simulation and numerical results fully verified the validity and effectiveness of the proposed scheme. Jie Tang 0005, Long Jiao, Kai Zeng 0001, Hong Wen 0001, Kaiyu Qin |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Pilot Contamination Attack Detection for 5G MmWave Grant-Free IoT NetworksabstractGrant-free random access is an emerging technology for providing massive connectivity for 5G massive machine-type communications (mMTC), where non-orthogonal pilot sequences are used to simultaneously detect active users and estimate channels. However, grant-free 5G IoT networks are vulnerable to pilot contamination attacks (PCA), where the attacker can send the same pilots as legitimate IoT users to harm the active user detection and channel estimation. To defend against this attack, in this article, we propose a physical-layer countermeasure based on the channel virtual representation (CVR). CVR can emphasize the unique characteristics of mmWave channels that are sensitive to the location of the sender. This can be utilized to counter PCA no matter if the attacker's pilots are superimposed to that of the victim or not. Based on this observation, to achieve an efficient PCA detection, a single-hidden-layer multiple measurement (SHMM) Siamese network is employed. This solution tackles the challenges of channel randomness and massive connectivity in mMTC IoT networks, and supports small sample learning. Simulation results evaluate and confirm the effectiveness of the proposed detection scheme under various scenarios. The detection accuracy can approach 99% with 128 antennas at the receiver and reach above 95% even with only 50 training samples. Ning Wang 0003, Weiwei Li 0002, Amir Alipour-Fanid, Long Jiao, Monireh Dabaghchian, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2021 | Large-scale Cost-Aware Classification Using Feature Computational Dependency GraphabstractWith the rapid growth of real-time machine learning applications, the process of feature selection and model optimization requires to integrate with the constraints on computational budgets. A specific computational resource in this regard is the time needed for evaluating predictions on test instances. The joint optimization problem of prediction accuracy and prediction-time efficiency draws more and more attention in the data mining and machine learning communities. The runtime cost is dominated by the feature generation process that contains significantly redundant computations across different features that sharing the same computational component in practice. Eliminating such redundancies would obviously reduce the time costs in the feature generation process. Our previous Cost-aware classification using Feature computational dependencies heterogeneous Hypergraph (CAFH) model has achieved excellent performance on the effectiveness. In the big data era, the high dimensionality caused by the heterogeneous data sources leads to the difficulty in fitting the entire hypergraph into the main memory and the high computational cost during the optimization process. Simply partitioning the features into batches cannot give the optimal solution since it will lose some feature dependencies across the batches. To improve the high memory and computational costs in the CAFH model, we propose an equivalent Accelerated CAFH (ACAFH) model based on the lossless heterogeneous hypergraph decomposition. An efficient and effective nonconvex optimization algorithm based on the alternating direction method of multipliers (ADMM) is developed to optimize the ACAFH model. The time and space complexities of the optimization algorithm for the ACAFH model are three and one polynomial degrees less than our previous algorithm for the CAFH model, respectively. Extensive experiments demonstrate the proposed ACAFH model achieves competitive performance on the effectiveness and much better performance on the efficiency. Qingzhe Li, Amir Alipour-Fanid, Martin Slawski, Yanfang Ye 0001, Lingfei Wu 0001, Kai Zeng 0001, Liang Zhao 0002 |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2021 | A Reassessment on Friendly Jamming EfficiencyabstractWith the rapid and continuous growth of various types of wireless devices in IoT, securing the communications among heterogeneous devices becomes an emerging issue. A physical layer security scheme, called “friendly jamming”, has drawn great attention recently owing to its ability to protect the confidentiality of the communication as well as to enable message authentication and access control for those already employed, unencrypted, weakly encrypted, or resource constrained devices. We notice that in a large number of cases in which friendly jamming are preferable, the transmitting signals to be protected have varying spectrum utilization at symbol level. In this paper, we rebuild secrecy capacity models and re-evaluate the jamming efficiency by taking this micro time scale non-stationary characteristic into consideration. Our reassessments reveal that jamming efficiency is greatly overestimated in the existing literature. The second part of our work further proposes a waveform design on jamming signal as a means to enhance the jamming efficiency. The basic idea is to consider both time and frequency domain structure of the transmitting signal when designing the jamming signal, making both time and frequency bandwidth largely match to each other. We discuss the implementation details for jamming common QAM and PSK modulated signals. Both simulations and proof-of-concept experiments validate the theoretical correctness of our reassessment and practical effectiveness of our method. Rong Jin 0002, Kai Zeng 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2021 | Exploiting Beam Features for Spoofing Attack Detection in mmWave 60-GHz IEEE 802.11ad NetworksabstractSpoofing attacks pose a serious threat to wireless communications. Exploiting physical-layer features to counter spoofing attacks is a promising solution. Although various physical-layer spoofing attack detection (PL-SAD) techniques have been proposed for conventional 802.11 networks in the sub-6GHz band, the study of PL-SAD for 802.11ad networks in 5G millimeter wave (mmWave) 60GHz band is largely open. In this paper, to achieve efficient PL-SAD in 5G networks, we propose a unique physical layer feature in IEEE 802.11ad networks, i.e., the signal-to-noise-ratio (SNR) trace obtained at the receiver in the sector level sweep (SLS) process. The SNR trace is readily extractable from the off-the-shelf device, and it is dependent on both transmitter location and intrinsic hardware impairment. Therefore, it can be used to achieve an efficient detection no matter the attacker is co-located with the legitimate transmitter or not. To achieve spoofing attack detection, we provide two methods based on different machine learning models. For the first method, the detection problem is formulated as a machine learning classification problem. To tackle the small sample learning and fast model construction challenges, we propose a novel neural network framework consisting of a backpropation network, a forward propagation network, and generative adversarial networks (GANs). Another method involves a Siamese network, in which the similarity between sample pairs from one device is used to achieve PL-SAD. It can tackle the training problem that the historical data cannot support the identification of the same device in a new communication session. We conduct experiments using off-the-shelf 802.11ad devices, Talon AD7200s and MG360, to evaluate the performance of the proposed PL-SAD schemes. Experimental results confirm the effectiveness of the proposed PL-SAD schemes, and the detection accuracy can reach 99% using small sample sizes under different scenarios. Ning Wang 0003, Long Jiao, Pu Wang 0003, Weiwei Li 0002, Kai Zeng 0001 |
IEEE Trans. Wirel. Commun. | 5 |
| 2020 | Machine Learning-based Spoofing Attack Detection in MmWave 60GHz IEEE 802.11ad NetworksabstractSpoofing attacks pose a serious threat to wireless communications. Exploiting physical-layer features to counter spoofing attacks is a promising solution. Although various physical-layer spoofing attack detection (PL-SAD) techniques have been proposed for conventional 802.11 networks in the sub-6GHz band, the study of PL-SAD for 802.11ad networks in 5G millimeter wave (mmWave) 60GHz band is largely open. In this paper, we propose a unique physical layer feature in IEEE 802.11ad networks, i.e., the signal-to-noise-ratio (SNR) trace obtained at the receiver in the sector level sweep (SLS) process, to achieve efficient PL-SAD. The SNR trace is readily extractable from the off-the-shelf device, and it is dependent on both transmitter location and intrinsic hardware impairment. Therefore, it can be used to achieve an efficient detection no matter the attacker is co-located with the legitimate transmitter or not. The detection problem is formulated as a machine learning classification problem. To tackle the small sample learning and fast model construction challenges, we propose a novel neural network framework consisting of a backpropation network, a forward propagation network, and generative adversarial networks (GANs). It can tackle small sample learning and allow for quick model construction. We conduct experiments using off-the-shelf 802.11ad devices, Talon AD7200s and MG360, to evaluate the performance of the proposed PL-SAD scheme. Experimental results confirm the effectiveness of the proposed PL-SAD scheme, and the detection accuracy can reach 98% using small sample sizes under different scenarios. Ning Wang 0003, Long Jiao, Pu Wang 0003, Weiwei Li 0002, Kai Zeng 0001 |
INFOCOM | 5 |
| 2020 | Compressed-Sensing-Based Pilot Contamination Attack Detection for NOMA-IoT CommunicationsabstractNonorthogonal multiple access (NOMA) technology can significantly promote Internet-of-Things (IoT) networks on spectral efficiency and massive connectivity. However, NOMA-IoT communications are vulnerable to pilot contamination attacks, where the attacker can send the same pilot signals as legitimate IoT users. Most existing countermeasures to this physical-layer threat struggle to adapt to NOMA-IoT networks, in which superimposed signals appear and low-cost IoT devices exist. In this article, we propose a compressed-sensing-based detection scheme to defend against pilot contamination attacks in NOMA-IoT networks. In particular, we present a multiple measurement vector (MMV) compressed sensing model and a security spreading code generation (SSCG) framework to prevent pilot contamination attacks from spoofing base station (BS) in NOMA-IoT networks. Furthermore, to efficiently reconstruct the superimposed signals based on the SSCG framework, a matching pursuit (MP) multiple response sparse Bayesian learning (MSBL) algorithm (MP-MSBL) is proposed. The security analysis and algorithm complexity of the proposed algorithms are provided. The simulation results evaluate and confirm the effectiveness of the proposed detection schemes. The reconstruction and detection accuracy of pilots can be higher than 99% under different scenarios. Ning Wang 0003, Weiwei Li 0002, Amir Alipour-Fanid, Monireh Dabaghchian, Kai Zeng 0001 |
IEEE Internet Things J. | 5 |
| 2020 | A Practical Downlink NOMA Scheme for Wireless LANsabstractNon-orthogonal multiple access (NOMA) has emerged as a new multiple access paradigm for wireless networks. Although many results have been produced for NOMA, most of them are limited to theoretical exploration and performance analysis in cellular networks. Very limited progress has been made so far in the design of practical NOMA schemes for wireless local area networks (WLANs). In this paper, we propose a practical downlink NOMA scheme for WLANs and evaluate its performance in real-world wireless environments. Our NOMA scheme has three key components: precoder design, user grouping, and successive interference cancellation (SIC). On the transmitter side, we first formulate the precoding design problem as an optimization problem and then devise an efficient algorithm to construct precoders for downlink NOMA transmissions. We further propose a lightweight user grouping algorithm to ensure the success of SIC at the receivers. On the receiver side, we propose a new SIC method to decode the desired signal in the presence of strong interference. In contrast to existing SIC methods, our SIC method does not require channel estimation to decode the signals, thereby improving its resilience to interference. We have built a prototype of the proposed NOMA scheme on a wireless testbed. Experimental results show that, compared to orthogonal multiple access (OMA), the proposed NOMA scheme can significantly improve the weak user's date rate (93% on average) and considerably improve WLAN's weighted sum rate (36% on average). Pedram Kheirkhah Sangdeh, Hossein Pirayesh, Qiben Yan 0001, Kai Zeng 0001, Wenjing Lou, Huacheng Zeng |
IEEE Trans. Commun. | 4 |
| 2020 | Message Integrity Protection Over Wireless Channel: Countering Signal Cancellation via Channel RandomizationabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel signal cancellation attack framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments as well as the online nature of the attack. Based on theoretical results, we propose a practical channel randomization approach to defend against signal cancellation attack, which exploits state diversity and swift reconfigurability of reconfigurable antenna to increase randomness and meanwhile reduce correlation of channel state information. We show that by proactively mimicking the attacker and placing restrictions on the attacker's location, we can bound the attacker's knowledge of channel state information, thereby achieve a guaranteed level of message integrity protection in practice. Besides, we conduct extensive experiments and simulations to show the security and performance of the proposed approach. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yanjun Pan 0001, Yantian Hou, Ming Li 0003, Ryan M. Gerdes, Kai Zeng 0001, Md. Asaduzzaman Towfiq, Bedri A. Cetiner |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2020 | Machine Learning-Based Delay-Aware UAV Detection and Operation Mode Identification Over Encrypted Wi-Fi TrafficabstractThe consumer unmanned aerial vehicle (UAV) market has grown significantly over the past few years. Despite its huge potential in spurring economic growth by supporting various applications, the increase of consumer UAVs poses potential risks to public security and personal privacy. To minimize the risks, efficiently detecting and identifying invading UAVs is in urgent need for both invasion detection and forensics purposes. Aiming to complement the existing physical detection mechanisms, we propose a machine learning-based framework for fast UAV identification over encrypted Wi-Fi traffic. It is motivated by the observation that many consumer UAVs use Wi-Fi links for control and video streaming. The proposed framework extracts features derived only from packet size and inter-arrival time of encrypted Wi-Fi traffic, and can efficiently detect UAVs and identify their operation modes. In order to reduce the online identification time, our framework adopts a re-weighted ℓ1-norm regularization, which considers the number of samples and computation cost of different features. This framework jointly optimizes feature selection and prediction performance in a unified objective function. To tackle the packet inter-arrival time uncertainty when optimizing the trade-off between the detection accuracy and delay, we utilize maximum likelihood estimation (MLE) method to estimate the packet inter-arrival time. We collect a large number of real-world Wi-Fi data traffic of eight types of consumer UAVs and conduct extensive evaluation on the performance of our proposed method. Evaluation results show that our proposed method can detect and identify tested UAVs within 0.15-0.35s with high accuracy of 85.7-95.2%. The UAV detection range is within the physical sensing range of 70m and 40m in the line-of-sight (LoS) and non-line-of-sight (NLoS) scenarios, respectively. The operation mode of UAVs can be identified with high accuracy of 88.5-98.2%. Amir Alipour-Fanid, Monireh Dabaghchian, Ning Wang 0003, Pu Wang 0003, Liang Zhao 0002, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | Pilot Contamination Attack Detection for NOMA in 5G mm-Wave Massive MIMO NetworksabstractPower non-orthogonal multiple access (NOMA) has been considered as a new enabling technology in 5G communication. In this paper, we introduce the problem of pilot contamination attack (PCA) on NOMA in millimeter wave (mmWave) and massive MIMO 5G communication. Due to the new characteristics of NOMA such as superposed signals with multi-users, PCA detection faces new challenges. By harnessing the sparseness and statistics of mmWave and massive MIMO virtual channel, we propose two effective PCA detection schemes for NOMA tackling static and dynamic environments, respectively. For the static environment, the problem of PCA detection is formulated as a binary hypothesis test of the virtual channel sparsity. For the dynamic environment, the statistic of the peaks in the virtual channel is leveraged to distinguish the contamination state from the normal state. A peak estimation algorithm and a machine learning based detection framework are proposed to achieve high detection performance. To further optimize the proposed scheme, a feature selection algorithm and an optimization model considering the detection accuracy and detection delay are presented. Simulation results evaluate and confirm the effectiveness of the proposed detection schemes. The detection rate can approach 100% with 10-3false alarm rate in the static environment and above 95% in the dynamic environment under various system parameters. Ning Wang 0003, Long Jiao, Amir Alipour-Fanid, Monireh Dabaghchian, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Multi-stage Deep Classifier Cascades for Open World RecognitionabstractAt present, object recognition studies are mostly conducted in a closed lab setting with classes in test phase typically in training phase. However, real-world problem are far more challenging because: i)~new classes unseen in the training phase can appear when predicting; ii)~discriminative features need to evolve when new classes emerge in real time; and iii)~instances in new classes may not follow the "independent and identically distributed" (iid) assumption. Most existing work only aims to detect the unknown classes and is incapable of continuing to learn newer classes. Although a few methods consider both detecting and including new classes, all are based on the predefined handcrafted features that cannot evolve and are out-of-date for characterizing emerging classes. Thus, to address the above challenges, we propose a novel generic end-to-end framework consisting of a dynamic cascade of classifiers that incrementally learn their dynamic and inherent features. The proposed method injects dynamic elements into the system by detecting instances from unknown classes, while at the same time incrementally updating the model to include the new classes. The resulting cascade tree grows by adding a new leaf node classifier once a new class is detected, and the discriminative features are updated via an end-to-end learning strategy. Experiments on two real-world datasets demonstrate that our proposed method outperforms existing state-of-the-art methods. Xiaojie Guo 0002, Amir Alipour-Fanid, Lingfei Wu 0001, Hemant Purohit, Xiang Chen 0010, Kai Zeng 0001, Liang Zhao 0002 |
CIKM | 6 |
| 2019 | Optimal Resource Allocation for Secure Multi-User Wireless Powered Backscatter Communication with Artificial NoiseabstractIn this paper, we consider a wireless powered backscatter communication (WPBC) network in which a full-duplex access point (AP) simultaneously transmits information and energy signals by injecting artificial noise (AN) to secure the backscatter transmission from multiple backscatter devices (BDs). To maximize the minimum throughput and ensure fairness and security, we formulate an optimization problem by jointly considering the power splitting ratio between dedicated information signals and AN, backscatter time and signal power allocation among multiple BDs. For a single BD network, we obtain a closed-form solution and evaluate its validity through proof-of-concept experiments. For the general case with multiple BDs, we present an iterative algorithm by leveraging block coordinate descent (BCD) and successive convex approximation optimization to solve a non-convex problem incurred in WPBC. We further show the convergence of the proposed algorithm and analyze its complexity. Finally, extensive simulation results show that the proposed algorithm achieves an optimal and equitable throughput for all BDs, and our work provides a good perspective of resource allocation to improve the performance of WPBC networks. Pu Wang 0003, Ning Wang 0003, Monireh Dabaghchian, Kai Zeng 0001, Zheng Yan 0002 |
INFOCOM | 4 |
| 2019 | Pairwise Markov Chain: A Task Scheduling Strategy for Privacy-Preserving SIFT on EdgeabstractIn this paper, we propose a task scheduling strategy, which can achieve image feature extraction on edge while ensuring privacy. Our task scheduling strategy applies to a fairly popular privacy-preserving Scale-Invariant Feature Transform SIFT scheme, where images to be processed are firstly randomly split into two portions for encryption and transmitted to two different edge nodes for feature extraction. Then, in the edge, our task scheduling strategy will re-assign these two portions to proper edge nodes for processing. During the whole process, two portions of the same image should not be assigned to the same edge node in order to preserve privacy. We show that this privacy constraint can be enforced through constructing a pairwise Markov chain, and carefully designing system states and transition probabilities. We further formulate the whole task scheduling problem as a stochastic latency minimization problem and solve it by converting it into a linear programming problem. Simulation results show that our proposed task scheduling strategy can achieve lower latency than baseline strategies while satisfying the privacy constraint. Hengrun Zhang 0001, Kai Zeng 0001 |
INFOCOM | 2 |
| 2019 | Physical-Layer Security of 5G Wireless Networks for IoT: Challenges and OpportunitiesabstractThe fifth generation (5G) wireless technologies serve as a key propellent to meet the increasing demands of the future Internet of Things (IoT) networks. For wireless communication security in 5G IoT networks, physical-layer security (PLS) has recently received growing interest. This paper aims to provide a comprehensive survey of the PLS techniques in 5G IoT communication systems. The investigation consists of four hierarchical parts. In the first part, we review the characteristics of 5G IoT under typical application scenarios. We then introduce the security threats from the 5G IoT physical-layer and categorize them according to the different purposes of the attacker. In the third part, we examine the 5G communication technologies in 5G IoT systems and discuss their challenges and opportunities when coping with physical-layer threats, including massive multiple-input-multiple-output (MIMO), millimeter wave (mmWave) communications, nonorthogonal multiple access (NOMA), full-duplex technology, energy harvesting (EH), visible light communication (VLC), and unmanned aerial vehicle (UAV) communications. Finally, we discuss open research problems and future works about PLS in the IoT system with technologies of 5G and beyond. Ning Wang 0003, Pu Wang 0003, Amir Alipour-Fanid, Long Jiao, Kai Zeng 0001 |
IEEE Internet Things J. | 5 |
| 2018 | Secret Beam: Robust Secret Key Agreement for mmWave Massive MIMO 5G CommunicationabstractIn this work, we present a scheme of physical layer secret key generation for Millimeter wave (mmWave) Massive MIMO system. Our scheme is compatible with current hardware structure and protocols including Analog Beamforming, Massive MIMO, and Beam Sweep. We add a small perturbation angle into the Angle of Arrival (AoA) of the transmitter as the common randomness, which significantly improved the secret key rate without being constrained by the complexity of link initialization protocols and low dynamic of the channel. Therefore, the secret key rate can be enhanced by increasing the number of perturbations. In addition, our scheme can combat co-located eavesdropper (Eve) by utilizing the high directionality of Massive MIMO antenna. Numerical results show that our scheme has a high bit agreement ratio (BAR) between legitimate users while the co-located Eve only gets the BAR around 50%, which indicates that the secrecy of the generated key is well achieved. Long Jiao, Ning Wang 0003, Kai Zeng 0001 |
GLOBECOM | 3 |
| 2018 | Mobility Improves NOMA Physical Layer SecurityabstractPhysical layer security of non-orthogonal multiple access (NOMA) systems has attracted great attentions. However, the impact of mobility on physical layer security of NOMA systems has not been well studied. In this paper, to fill this gap, we investigate the impact of random mobility on physical layer security of NOMA systems. Considering scenarios where a base station (BS) or access point (AP) communicates to two random mobile users with a passive eavesdropper in two concentric circles, we study the secrecy performance with combinations of two typical random mobility models: random waypoint (RWP) and random direction (RD). A general analytical framework to numerically calculate the average secrecy rates of NOMA mobile users under steady state is provided. By comparing secrecy performance of mobile users with static users, we find that RWP mobile users can achieve higher average secrecy rates than the users with other mobility combinations. Meanwhile, two types of secrecy fairness for mobile users are fully considered and we propose a novel sum average secrecy rate maximization problem, subject to average power limits and users' QoS (quality of service) requirements. Considering eavesdropper's channel state information (CSI) is unknown to BS, we propose a threshold power allocation strategy to improve the sum average secrecy rate of NOMA mobile users. Extensive numerical simulations are conducted to validate our model and theoretical analysis. Jie Tang 0005, Long Jiao, Ning Wang 0003, Pu Wang 0003, Kai Zeng 0001, Hong Wen 0001 |
GLOBECOM | 5 |
| 2018 | Efficient Identity Spoofing Attack Detection for IoT in mm-Wave and Massive MIMO 5G CommunicationabstractIn many IoT (Internet-of-Things) applications, a large number of low-cost IoT devices are connected to the Internet through an access point (AP) or gateway via wireless communication. Due to the resource constraints on IoT devices and broadcast nature of wireless medium, identity spoofing attacks are easy to launch but hard to defend in an IoT wireless access network. In this paper, under the context of 5G communication, we propose an efficient physical layer identity spoofing attack detection scheme for IoT. By harnessing the sparsity of the virtual channel in mmWave and Massive MIMO 5G communication, we propose a two- step detection scheme. In the first step, our scheme detects anomalies by examining the virtual angles of arrival (AoA) and path gains of all the IoT devices simultaneously in a virtual channel space (VCS). In the second step, we introduce a machine learning based detection scheme to detect the actual attack. Simulation results evaluate and confirm the effectiveness of the proposed detection scheme. The minimum Bayes risk of the proposed scheme can be less than 0.5\% even in the presence of 100 IoT devices. Ning Wang 0003, Long Jiao, Pu Wang 0003, Monireh Dabaghchian, Kai Zeng 0001 |
GLOBECOM | 5 |
| 2018 | Prediction-time Efficient Classification Using Feature Computational DependenciesabstractAs machine learning methods are utilized in more and more real-world applications involving constraints on computational budgets, the systematic integration of such constraints into the process of model selection and model optimization is required to an increasing extent. A specific computational resource in this regard is the time needed for evaluating predictions on test instances. There is meanwhile a substantial body of work concerned with the joint optimization of accuracy and test-time efficiency by considering the time costs of feature generation and model prediction. During the feature generation process, significant redundant computations across different features occur in many applications. Although the elimination of such redundancies would reduce the time cost substantially, there has been little research in this area due to substantial technical challenges involved, especially: 1) the lack of an effective formulation for feature computation dependency; and 2) the nonconvex and discrete nature of the optimization over feature computation dependency. In order to address these problems, this paper first proposes a heterogeneous hypergraph to represent the feature computation dependency, after which a framework is proposed that jointly optimizes the accuracy and the exact test-time cost based on a given feature computational dependency. A continuous tight approximation to this original problem is proposed based on a non-monotone nonconvex regularization term. Finally, an effective nonconvex optimization algorithm is proposed to solve the problem, along with a theoretical analysis of the convergence conditions. Extensive experiments on eight synthetic datasets and six real-world datasets demonstrate the proposed models' outstanding performance in terms of both accuracy and prediction-time cost. Liang Zhao 0002, Amir Alipour-Fanid, Martin Slawski, Kai Zeng 0001 |
KDD | 4 |
| 2018 | An Adaptive Primary User Emulation Attack Detection Mechanism for Cognitive Radio Networks
Yu Chen 0002, Xiaohua Li 0003, Kai Zeng 0001, Roger Zimmermann |
SecureComm (1) | 4 |
| 2018 | A Survey on Security, Privacy, and Trust in Mobile CrowdsourcingabstractWith the popularity of sensor-rich mobile devices (e.g., smart phones and wearable devices), mobile crowdsourcing (MCS) has emerged as an effective method for data collection and processing. Compared with traditional wireless sensor networking, MCS holds many advantages such as mobility, scalability, cost-efficiency, and human intelligence. However, MCS still faces many challenges with regard to security, privacy, and trust. This paper provides a survey of these challenges and discusses potential solutions. We analyze the characteristics of MCS, identify its security threats, and outline essential requirements on a secure, privacy-preserving, and trustworthy MCS system. Further, we review existing solutions based on these requirements and compare their pros and cons. Finally, we point out open issues and propose some future research directions. Wei Feng 0010, Zheng Yan 0002, Hengrun Zhang 0001, Kai Zeng 0001, Yu Xiao 0001, Y. Thomas Hou 0001 |
IEEE Internet Things J. | 4 |
| 2018 | Guest Editorial Special Issue on Trust, Security, and Privacy in CrowdsourcingabstractThe recent proliferation of mobile devices such as smartphones and wearable devices has given rise to crowdsourcing Internet of Things (IoT) applications, such as urban mobility monitoring, virtual/augmented reality, smart city management, and indoor floor plan reconstruction and mapping. Various data collected by mobile devices with small or big volumes can be further processed, analyzed, and mined in order to support multifarious promising services with intelligence. Zheng Yan 0002, Kai Zeng 0001, Yu Xiao 0001, Y. Thomas Hou 0001, Pierangela Samarati |
IEEE Internet Things J. | 2 |
| 2018 | Secure Inductive-Coupled Near Field Communication at Physical LayerabstractNear field communication (NFC) is widely used today in many useful applications, such as contactless payment, identification, and file exchange. Due to the limitations on computation, power, and cost of NFC devices, NFC systems often lack encryption or are weakly encrypted, leaving them exposed to security attacks. One solution for this problem is to install strong cryptographic protocols on NFC devices. However, it involves upgrading and revoking deployed NFC devices, which is costly and impractical. Moreover, encryption algorithms are usually considered expensive for resource constrained NFC devices in terms of computation overhead and energy consumption. Aiming at a solution to tackle the security threat without revoking or changing the insecure NFC devices, this paper investigates whether the recent advance of physical layer security can be applied as a means to secure NFC. A detailed analysis is performed to reveal two unique challenges brought by NFC's data transmission mechanism. A practical solution, SecNFC, through special waveform design at the initiator is proposed. Extensive simulations and concept-proof experiments are conducted to evaluate the performance of our solution. Both simulation and experimental results show that SecNFC can efficiently prevent NFC from eavesdropping with a slight and tolerable decoding performance degradation at the initiator. Rong Jin 0002, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Online Learning With Randomized Feedback Graphs for Optimal PUE Attacks in Cognitive Radio Networks
Monireh Dabaghchian, Amir Alipour-Fanid, Kai Zeng 0001, Qingsi Wang, Peter Auer |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | Impact of Mobility on Physical Layer Security Over Wireless Fading ChannelsabstractWireless physical layer security has attracted great attention in recent years. Although mobility is an intrinsic property of wireless networks, most of the existing works only consider static scenarios and the impact of mobility on wireless physical layer security is not well understood. To fill this gap, in this paper, we investigate physical layer security in the scenario with a random mobile receiver under Rayleigh fading channel. We consider a common scenario where a base station or access point communicates to a random mobile receiver with a passive eavesdropper in a circular region. The secrecy performances under three typical random mobility models are studied: random waypoint model (RWP); random direction model (RD); and border move model. We investigate the secrecy characteristics of the mobile user under steady-state running and provide a general analytical framework for computing the ergodic secrecy capacity. We derive tractable closed-form expressions of positive secrecy capacity probability and secrecy outage probability for RWP and RD mobility users, respectively. By comparing the secrecy performance of mobility with static case, we find that the RWP mobile user can achieve much better secrecy performance than the others. We then investigate the secrecy performance of RWP mobile user with pause time. Furthermore, the two types of secrecy improvement strategies for random mobile users are proposed. In the first strategy, a transmit subcell for RWP users is bounded. We allow the transmitter to communicate with the mobile user only when he is moving within the subcell. In the other strategy, the transmitter is turned on only when the evaluated secrecy performance reaches to a required level. We strike a good trade-off between the secrecy improvements and transmit outage probability. Extensive simulation results validate our theoretical analysis. Finally, we extend our framework to other realistic scenarios, including nodes moving in other shapes of areas, and multiple non-cooperative and cooperative eavesdroppers. Jie Tang 0005, Monireh Dabaghchian, Kai Zeng 0001, Hong Wen 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2018 | Physical layer multi-user key generation in wireless networks
Rong Jin 0002, Kai Zeng 0001 |
Wirel. Networks | 2 |
| 2017 | Achieving Unconditional Security for MIMO-BAN under Short Blocklength Wiretap CodeabstractFor current MIMO physical layer security, most of the existing works study how to increase the secrecy capacity. However, the unconditional secure transmission fully achieving the secrecy capacity is difficult to realize, because the theoretical capacity can be achieved only by a wiretap code with infinite blocklength [1]. In most cases, the long codelength secure code is needed to approach the secrecy capacity [14]. Even though the short blocklengh code is prospective for timely and lower burden communication networks, not much exploration has been done to fulfil the unconditional security by a short length wiretap code. In this work, we investigate a lightweight strategy to achieve unconditional secrecy for the practical MIMO Beamforming artifacial noise (MIMO-BAN) physical layer security system under short blocklength wiretap code. Firstly, we analyse the modulated impact on MIMO-BAN secrecy capacity. Then we investigate the achievable secrecy performance for MIMO-BAN physical layer secure system under practical short blocklengh secure code. Based on this, we propose a light wight secrecy strategy, which could guarantee required quality of the main channel while keeping eavesdropper's BER approaching to 0.5. The simulation results verify our analytical performance predictions and demonstrate its feasibility. Jie Tang 0005, Hong Wen 0001, Kai Zeng 0001, Lin Hu 0002 |
VTC Fall | 3 |
| 2016 | A smartphone-based driver fatigue detection using fusion of multiple real-time facial featuresabstractIn this paper, a fatigue monitoring system focuses on information fusion is designed and implemented in smartphone. Eye blinking, head nod and yawning are detected as indicators of driver fatigue. We developed a mathematical model to extract the characteristic in time and frequency domain using mean-variance of key fatigue parameters. The system perform real time detection of face and eye blink using Harr-like technique and mouth detection for yawning with Canny Active Contour Method. The testing result of the system demonstrates the practical use of multiple features, particularly with our mean-variance methods, and their fusion enables a more accurate and authentic fatigue detection. Yantao Qiao, Kai Zeng 0001, Xiaoyu Yin |
CCNC | 2 |
| 2016 | Intelligence Measure of Cognitive Radios with Learning CapabilitiesabstractCognitive radio (CR) is considered as a key enabling technology for dynamic spectrum access to improve spectrum efficiency. Although the CR concept was invented with the core idea of realizing "cognition", the research on measuring CR cognition capabilities and intelligence is largely open. Deriving the intelligence capabilities of CR not only can lead to the development of new CR technologies, but also makes it possible to better configure the networks by integrating CRs with different intelligence capabilities in a more cost- efficient way. In this paper, for the first time, we propose a data-driven methodology to quantitatively analyze the intelligence factors of the CR with learning capabilities. The basic idea of our methodology is to run various tests on the CR in different spectrum environments under different settings and obtain various performance results on different metrics. Then we apply factor analysis on the performance results to identify and quantize the intelligence capabilities of the CR. More specifically, we present a case study consisting of sixty three different types of CRs. CRs are different in terms of learning-based dynamic spectrum access strategies, number of sensors, sensing accuracy, and processing speed. Based on our methodology, we analyze the intelligence capabilities of the CRs through extensive simulations. Four intelligence capabilities are identified for the CRs through our analysis, which comply with the nature of the tested algorithms. Monireh Dabaghchian, Amir Alipour-Fanid, Kai Zeng 0001, Xiaohua Li 0003, Yu Chen 0002 |
GLOBECOM | 4 |
| 2016 | Integration of machine learning and human learning for training optimization in robust linear regressionabstractIn this paper machine learning and human learning are applied jointly to optimize the training of linear regression. Human learning is exploited to label extra training data so as to resolve problems such as insufficient training and over-fitting. Considering the inevitable human errors in labeling, two machine learning algorithms are developed which optimize the selection of the extra training data and detect human errors during linear regression. The first algorithm assumes sparse human errors and implements a sparse optimization within a sequential active learning procedure. The second algorithm deals with non-sparse human errors. By exploiting the IRT (item response theory) to model the distribution of human errors, it reconstructs the training data set so that the human labeling errors become sparse. Simulations are conducted to show that the two algorithms are effective in resolving the insufficient training and human labeling error problems. Xiaohua Li 0003, Yu Chen 0002, Kai Zeng 0001 |
ICASSP | 3 |
| 2016 | Monitoring Multi-Hop Multi-Channel Wireless Networks: Online Sniffer Channel AssignmentabstractData capture is important for some critical network applications, such as network diagnosis and criminal investigation. In multi-channel wireless networks, the fundamental challenge for data capture is how to assign operation channels to wireless sniffers. The existing approaches make some impractical assumptions, such as the prior knowledge on network traffic and the perfect conditions of data capture. In this paper, we relax these assumptions and investigate the sniffer-channel assignment problem in multi-hop scenarios. Especially, sniffer redundancy deployment is discussed, which enables multiple sniffers to monitor one traffic. This problem is formulated as a combinatorial multi-arm bandit (MAB) problem, and a cooperative distribute learning policy is proposed. We analyze the regret of our policy in theory, and validate its effectiveness through numerical simulations. Jing Xu 0005, Wei Liu 0004, Kai Zeng 0001 |
LCN | 3 |
| 2016 | MagPairing: Pairing Smartphones in Close Proximity Using MagnetometersabstractWith the prevalence of mobile computing, lots of wireless devices need to establish secure communication on the fly without pre-shared secrets. Device pairing is critical for bootstrapping secure communication between two previously unassociated devices over the wireless channel. Using auxiliary out-of-band channels involving visual, acoustic, tactile, or vibrational sensors has been proposed as a feasible option to facilitate device pairing. However, these methods usually require users to perform additional tasks, such as copying, comparing, and shaking. It is preferable to have a natural and intuitive pairing method with minimal user tasks. In this paper, we introduce a new method, called MagPairing, for pairing smartphones in close proximity by exploiting correlated magnetometer readings. In MagPairing, users only need to naturally tap the smartphones together for a few seconds without performing any additional operations in authentication and key establishment. Our method exploits the fact that smartphones are equipped with tiny magnets. Highly correlated magnetic field patterns are produced when two smartphones are close to each other. We design MagPairing protocol and implement it on Android smartphones. We conduct extensive simulations and real-world experiments to evaluate MagPairing. Experiments verify that the captured sensor data on which MagPairing is based has high entropy and sufficient length, and is nondisclosure to attackers more than few centimeters away. Usability tests on various kinds of smartphones by totally untrained users show that the whole pairing process needs only 4.5 s on average with more than 90% success rate. Rong Jin 0002, Liu Shi, Kai Zeng 0001, Amit Pande, Prasant Mohapatra |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Practical Secret Key Agreement for Full-Duplex Near Field CommunicationsabstractNear Field Communication (NFC) is a promising short distance radio communication technology for many useful applications. Although its communication range is short, NFC alone does not guarantee secure communication and is subject to security attacks, such as an eavesdropping attack. Generating a shared key and using symmetric key cryptography to secure the communication between NFC devices is a feasible solution to prevent various attacks. However, conventional Diffie-Hellman key agreement protocol is not preferable for resource constrained NFC devices due to its extensive computational overhead and energy consumption. In this paper, we propose a practical, fast and energy-efficient key agreement scheme, which uses random bits transmission with waveform shaking, for NFC devices by exploiting its off-the-shelf full-duplex capability. In the proposed method, two devices send random bits to each other simultaneously without strict synchronization or perfect match of amplitude and phase. On the contrary, the method randomly introduces synchronization offset and mismatch of amplitude and phase for each bit transmission in order to prevent a passive attacker from determining the generated key. A shared bit can be established when two devices send different bits. We conduct theoretical analysis on the correctness and security strength of the method, and extensive simulations to evaluate its effectiveness. We build a testbed based on USRP software defined radio and conduct proof-of-concept experiments to evaluate the method in a real-world environment. It shows that the proposed method achieves a high key generation rate of about 26 kbps and is immune to eavesdropping attack even when the attacker is within several centimeters from the legitimate devices. The proposed method is a practical, fast, energy-efficient, and secure key agreement scheme for resource-constrained NFC devices. Rong Jin 0002, Xianru Du, Zi Deng, Kai Zeng 0001, Jing Xu 0005 |
IEEE Trans. Mob. Comput. | 4 |
| 2016 | Sniffer Channel Assignment With Imperfect Monitoring for Cognitive Radio NetworksabstractSniffer channel assignment (SCA) is a fundamental building block for wireless data capture, which is essential for traffic monitoring and network forensics. Most of the existing SCA approaches for cognitive radio networks (CRNs) adopt optimization-based methods and rely on the prior knowledge of the secondary user (SU) activities. To relax this constraint, learning-based methods have been recently developed; however, there is still insufficient theoretical understanding within the learning framework for SCA. In this paper, we aim to maximize the total amount of the captured SU traffic, and we formulate the SCA problem as a nonstochastic/adversarial multiarmed bandit problem. Moreover, the inherent error in wireless capturing, i.e., imperfect monitoring, is considered in our model. We propose two online learning algorithms for the SCA scenarios with and without channel switching costs, respectively, and their regret performances are proved uniformly sublinear in time and polynomial in the number of channels. The numerical evaluation shows, in addition to their robust regret performances, the proposed algorithms greatly outperform the existing SCA approaches in the amount of effectively captured SU traffic. Jing Xu 0005, Qingsi Wang, Kai Zeng 0001, Mingyan Liu, Wei Liu 0004 |
IEEE Trans. Wirel. Commun. | 3 |
| 2015 | Message Integrity Protection over Wireless Channel by Countering Signal Cancellation: Theory and PracticeabstractPhysical layer message integrity protection and authentication by countering signal-cancellation has been shown as a promising alternative to traditional pure cryptographic message authentication protocols, due to the non-necessity of neither pre-shared secrets nor secure channels. However, the security of such an approach remained an open problem due to the lack of systematic security modeling and quantitative analysis. In this paper, we first establish a novel correlated jamming framework to study the optimal signal-cancellation attacker's behavior and utility using game-theory, which precisely captures the attacker's knowledge using its correlated channel estimates in various channel environments. Besides, we design a practical physical layer message integrity protection protocol based on ON/OFF keying and Manchester coding, which provides quantitative security guarantees in the real-world. Such a guarantee is achieved by bounding the attacker's knowledge about the future channel via proactively measuring channel statistics (mimic the attacker), so as to derive a lower-bound to the defender's signal-detection probability under optimal correlated jamming attacks. We conduct extensive experiments and simulations to show the security and performance of the proposed scheme. We believe our novel threat modeling and quantitative security analysis methodology can benefit a wide range of physical layer security problems. Yantian Hou, Ming Li 0003, Ruchir Chauhan, Ryan M. Gerdes, Kai Zeng 0001 |
AsiaCCS | 5 |
| 2015 | Online learning for unreliable passive monitoring in multi-channel wireless networksabstractPassive network monitoring is important for the critical applications of network diagnosis and criminal investigation. As in multi-channel wireless networks, the sniffer-channel assignment problem faces a tradeoff between exploitation and exploration. In this paper, we investigate this problem in a practical scenario. Different from the existing literature, we assume that the knowledge of the users' activities is not known a priori, and there exists capture uncertainty due to unreliable monitoring conditions. Furthermore, we consider the case of sniffer redundancy deployment, which enables multiple sniffers to monitor one channel to enhance capture reliability. Our problem is then formulated as a combinatorial multi-arm bandit problem. We propose an online learning policy, in which sniffer-channel assignment is dynamically decided based on the learning results of the users' activities. We further develop a greedy algorithm to achieve the channel assignment decision in polynomial time. Our solution is evaluated by both theoretical analysis and numerical simulations. Simulation results show that our policy achieves logarithmic regret in time and outperforms the learning policy without consideration of sniffer redundancy deployment. Jing Xu 0005, Kai Zeng 0001, Wei Liu 0004 |
ICC | 2 |
| 2015 | Live Video Forensics: Source Identification in Lossy Wireless NetworksabstractVideo source identification is very important in validating video evidence, tracking down video piracy crimes, and regulating individual video sources. With the prevalence of wireless communication, wireless video cameras continue to replace their wired counterparts in security/surveillance systems and tactical networks. However, wirelessly streamed videos usually suffer from blocking and blurring due to inevitable packet loss in wireless transmissions. The existing source identification methods experience significant performance degradation or even fail to work when identifying videos with blocking and blurring. In this paper, we propose a method that is effective and efficient in identifying such wirelessly streamed videos. In addition, we also propose to incorporate wireless channel signatures and selective frame processing into source identification, which significantly improve the identification speed. We conduct extensive real-world experiments to validate our method. The results show that the source identification accuracy of the proposed scheme largely outperforms the existing methods in the presence of video blocking and blurring. Moreover, our method is able to identify the video source in a near-real-time fashion, which can be used to detect the wireless camera spoofing attack. Shaxun Chen, Amit Pande, Kai Zeng 0001, Prasant Mohapatra |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Practical secret key agreement for full-duplex near field communicationsabstractNear Field Communication (NFC) is a promising short distance radio communication technology for many useful applications. Although its communication range is short, NFC alone does not guarantee secure communication and is subject to security attacks, such as eavesdropping attack. Generating a shared key and using symmetric key cryptography to secure the communication between NFC devices is a feasible solution to prevent various attacks. However, conventional Diffie-Hellman key agreement protocol is not preferable for resource constrained NFC devices due to its extensive computational overhead and energy consumption. In this paper, we propose a practical, fast and energy-efficient key agreement scheme, called RIWA (Random bIts transmission with Waveform shAking), for NFC devices by exploiting its full-duplex capability. In RIWA, two devices send random bits to each other simultaneously without strict synchronization or perfect match of amplitude and phase. On the contrary, RIWA randomly introduces synchronization offset and mismatch of amplitude and phase for each bit transmission in order to prevent a passive attacker from determining the generated key. A shared bit can be established when two devices send different bits. We conduct theoretical analysis on the correctness and security strength of RIWA, and extensive simulations to evaluate its effectiveness. We build a testbed based on USRP software defined radio and conduct proof-of-concept experiments to evaluate RIWA in a real-world environment. It shows that RIWA achieves a high key generation rate about 26kbps and is immune to eavesdropping attack even when the attacker is within several centimeters away from the legitimate devices. RIWA is a practical, fast, energy-efficient, and secure key agreement scheme for resource-constrained NFC devices. Rong Jin 0002, Xianru Du, Zi Deng, Kai Zeng 0001, Jing Xu 0005 |
AsiaCCS | 4 |
| 2014 | Delay analysis of physical layer key generation in multi-user dynamic wireless networksabstractSecret key generation by extracting the shared randomness in wireless fading channel is a promising way to ensure wireless communication security. Previous works only consider key generation in static networks, but real-world key establishments are usually dynamic. In this work, for the first time we investigate the pairwise key generation in dynamic wireless networks with a center node (eg. access point (AP)) and random arrival users. We establish the key generation model for this kind of networks. We propose a method based on discrete Markov chain to calculate the average time a user will spend on waiting and completing the key generation (average key generation delay, AKGD). Our method can tackle both serial and parallel key generation scheduling under various conditions. We conduct extensive simulations to show the effectiveness of our model and method. The analytical and simulation results match to each other. Rong Jin 0002, Xianru Du, Kai Zeng 0001, Laiyuan Xiao, Jing Xu 0005 |
ICC | 3 |
| 2014 | Physical layer challenge-response authentication in wireless networks with relayabstractExploiting physical layer characteristics to enhance or complement authentication strength in wireless networks has been attracting research attention recently. Existing physical layer authentication mechanisms mainly tackle single-hop communications. In this paper, we propose two physical layer challenge-response authentication mechanisms for wireless networks with relay. One mechanism, named PHY-CRAMR, is an extension of the existing PHY-CRAM protocol. It fully utilizes the randomness, reciprocity, and location decorrelation features of the wireless fading channel to hide/encrypt the challenge response messages at the physical layer, and is immune to outside attacks with a trusted relay. The other novel mechanism, named PHY-AUR, exploits randomness, coherence, and location decorrelation properties of wireless fading channel to securely convey the product of the channel state information on consecutive links and uses the fading channel to encrypt challenge and response messages. PHY-AUR is immune to both outside and inside attacks with an untrusted relay. Both PHY-CRAMR and PHY-AUR adopt OFDM technique to modulate the authentication key and challenge-response messages on subcarriers. Physical layer pilots and preambles are eliminated to prevent an attacker from gaining knowledge about the channel state information, and as a result prevent the authentication key from being revealed to untrusted attackers. We analyze the security strength of both mechanisms and conduct extensive simulations to evaluate them. It shows that both PHY-CRAMR and PHY-AUR can achieve both a high successful authentication rate and low false acceptance rate, and the performance improves as the signal to noise ratio (SNR) increases. Xianru Du, Dan Shan, Kai Zeng 0001, Lauren M. Huie |
INFOCOM | 3 |
| 2014 | Efficient Data Capturing for Network Forensics in Cognitive Radio NetworksabstractNetwork forensics is an emerging interdiscipline used to track down cyber crimes and detect network anomalies for a multitude of applications. Efficient capture of data is the basis of network forensics. Compared to traditional networks, data capture faces significant challenges in cognitive radio networks. In traditional wireless networks, usually one monitor is assigned to one channel for traffic capture. This approach will incur very high cost in cognitive radio networks because it typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's behavior, cognitive radio devices change their operating channels dynamically, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. We also propose a protocol that schedules multiple monitors to perform channel scanning and packet capturing in an efficient manner. Monitors are reused in the time domain, and geographic coverage is taken into account. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%. Shaxun Chen, Kai Zeng 0001, Prasant Mohapatra |
IEEE/ACM Trans. Netw. | 2 |
| 2013 | iSens: Detecting hidden busy channels in WM systems with interactive sensing for CRNabstractCognitive radio (CR) implements dynamic spectrum access (DSA) mainly through performing spectrum sensing. In some circumstances, spectrum sensing is regarded as not sufficient for CR systems without generating unacceptable impact on primary users. For example, for wireless microphone (WM) systems when the transmitters either are turned off or stay idle while receivers are actively listening, CR systems decide to transmit message over the idle channel after spectrum sensing. At this moment, active WM receivers still can detect narrow-band BPSK/QPSK signals transmitted by customer premise equipments (CPEs) leading to unexpected audio signals. In this paper, we first address and study such a hidden busy channel (HBC) situation. The degree of audio interferences generated by narrow-band BPSK/QPSK signals on HBCs is evaluated through field testing. To detect HBCs, we propose a novel technique named iSens. Experiments show that detection the rate of iSens is higher than 90% while the false alarm rate is lower than 10%. Dan Shan, Kai Zeng 0001, Paul C. Richardson, Weidong Xiang |
GLOBECOM | 2 |
| 2013 | Video source identification in lossy wireless networksabstractVideo source identification is very important in validating video evidence, tracking down video piracy crimes and regulating individual video sources. With the prevalence of wireless communication, wireless video cameras continue to replace their wired counterparts in security/surveillance systems and tactical networks. However, wirelessly streamed videos usually suffer from blocking and blurring due to inevitable packet loss in wireless transmissions. The existing source identification methods experience significant performance degradation or even fail to work when identifying videos with blocking and blurring. In this paper, we propose a method which is effective and efficient in identifying such wirelessly streamed videos. In addition, we also propose to incorporate wireless channel signatures and selective frame processing into source identification, which significantly improve the identification speed. Shaxun Chen, Amit Pande, Kai Zeng 0001, Prasant Mohapatra |
INFOCOM | 3 |
| 2013 | PHY-CRAM: Physical Layer Challenge-Response Authentication Mechanism for Wireless NetworksabstractExploiting the unique properties of the physical layer to enhance or complement authentication strength in wireless networks has attracted a lot of research attention recently. In this paper, we propose a novel PHYsical layer Challenge-Response Authentication Mechanism (PHY-CRAM) for wireless networks. PHY-CRAM is suitable for both one-way and mutual authentication. It fully utilizes the randomness, reciprocal, and location decorrelation features of the wireless fading channel, and is immune to various passive and active attacks. In the authentication procedure, challenge-response signals are exchanged at the physical layer, which allow two devices to verify their shared secrets while not revealing these secrets to attackers. PHY-CRAM adopts orthogonal frequency-division multiplexing (OFDM) technique which separately modulates the higher layer information and shared keys on subcarriers' phases and amplitudes respectively, in order to prevent channel probing from traffic-related information. We conduct extensive simulation study and develop a prototype using field-programmable gate array (FPGA) and discrete radio frequency (RF) components to evaluate PHY-CRAM in real-world environments. It shows that PHY-CRAM achieves both high successful authentication rate and low false acceptance rate in various channel conditions and under various attacks. Dan Shan, Kai Zeng 0001, Weidong Xiang, Paul C. Richardson, Yan Dong 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2013 | Trusted Collaborative Spectrum Sensing for Mobile Cognitive Radio NetworksabstractCollaborative spectrum sensing is a key technology in cognitive radio networks (CRNs). Although mobility is an inherent property of wireless networks, there has been no prior work studying the performance of collaborative spectrum sensing under attacks in mobile CRNs. Existing solutions based on user trust for secure collaborative spectrum sensing cannot be applied to mobile scenarios, since they do not consider the location diversity of the network, thus over penalize honest users who are at bad locations with severe path-loss. In this paper, we propose to use two trust parameters, location reliability and malicious intention (LRMI), to improve both malicious user detection and primary user detection in mobile CRNs under attack. Location reliability reflects path-loss characteristics of the wireless channel and malicious intention captures the true intention of secondary users, respectively. We propose a primary user detection method based on location reliability (LR) and a malicious user detection method based on LR and Dempster-Shafer (D-S) theory. Simulations show that mobility helps train location reliability and detect malicious users based on our methods. Our proposed detection mechanisms based on LRMI significantly outperforms existing solutions. In comparison to the existing solutions, we show an improvement of malicious user detection rate by 3 times and primary user detection rate by 20% at false alarm rate of 5%, respectively. Shraboni Jana, Kai Zeng 0001, Wei Cheng 0001, Prasant Mohapatra |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Hearing Is Believing: Detecting Wireless Microphone Emulation Attacks in White SpaceabstractIn cognitive radio networks, an attacker transmits signals mimicking the characteristics of primary signals, in order to prevent secondary users from transmitting. Such an attack is called primary user emulation (PUE) attack. TV towers and wireless microphones are two main types of primary users in white space. Existing work on PUE attack detection only focused on the first category. For the latter category, primary users are mobile and their transmission power is low. These properties introduce great challenges on PUE detection and existing methods are not applicable. In this paper, we propose a novel method to detect the emulation attack of wireless microphones. We exploit the relationship between RF signals and acoustic information to verify the existence of wireless microphones. The effectiveness of our approach is validated through real-world implementation. Extensive experiments show that our method achieves both false positive rate and false negative rate lower than 0.1 even in a noisy environment. Shaxun Chen, Kai Zeng 0001, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Adaptive Wireless Channel Probing for Shared Key Generation Based on PID ControllerabstractGenerating a shared key between two parties from the wireless channel is an increasingly interesting topic. The process of obtaining information from the wireless channel is called channel probing. Previous key generation schemes probe the channel at a preset and constant rate without any consideration of channel variation or probing efficiency. To satisfy the usersâ requirements for key generation rate (KGR) and to use the wireless channel efficiently, we propose an adaptive channel probing scheme based on the proportional-integral-derivative controller, which is used to tune the probing rate. Moreover, we use the Lempel-Ziv complexity to estimate the entropy rate of channel statistics (received signal strength), which is considered as an indicator of probing efficiency. The experimental results show that the controller can dynamically tune the probing rate and, meanwhile, to achieve a user desired KGR. It stabilizes the KGR at the desired value with error below 1 bit/s. Besides, channel probing process is efficient under different user velocities, motion types, and sites. Yunchuan Wei, Kai Zeng 0001, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 2 |
| 2012 | Trusted collaborative spectrum sensing for mobile cognitive radio networksabstractCollaborative spectrum sensing is a key technology in cognitive radio networks (CRNs). It is inaccurate if spectrum sensing nodes are malicious. Although mobility is an inherent property of wireless networks, there has been no prior work studying the detection of malicious users for collaborative spectrum sensing in mobile CRNs. Existing solutions based on user trust for secure collaborative spectrum sensing cannot be applied to mobile scenarios, since they do not consider the location diversity of the network, thus over penalize honest users who are at locations with severe pathloss. In this paper, we propose to use two trust parameters, Location Reliability and Malicious Intention (LRMI), to improve malicious and primary user detection in mobile CRNs under attacks. Location Reliability reflects pathloss characteristics of the wireless channel and Malicious Intention captures the true intention of secondary users, respectively. Simulations of our proposed detection mechanisms, LRMI, show that mobility helps train location reliability and detect malicious users. We show an improvement of malicious user detection rate by 3 times and primary user detection rate by 20% at false alarm rate of 5%, respectively. Shraboni Jana, Kai Zeng 0001, Prasant Mohapatra |
INFOCOM | 2 |
| 2012 | Detecting spectrum misuse in wireless networksabstractIn contrast to conventional static fixed-width channel allocation, on-demand dynamic variable-width channel allocation has shown that it can effectively improve the fairness, throughput, and spectrum efficiency of wireless networks. Air-time utilization (the percentage of time spent on transmissions) is often used to characterize the spectrum demand of networks. The higher the airtime utilization of a network is, the more spectrum the network should be allocated to. Normally, if all wireless devices in a network utilize spectrum effectively, the airtime utilization can faithfully reflect the spectrum usage. In practice, however, spectrum can be ineffectively used due to the misconfiguration of wireless devices, such as inappropriate bit rate configuration, conservative transmit power setting, or mismatch between channel-width and bit rate. The misconfiguration not only degrades the performance of its local network, but also causes the inflation of local network's airtime utilization and thus results in an unfair spectrum allocation. To address the problem, we present Pinokio, a system that monitors spectrum usage at access points, detects spectrum misuse and improves spectrum efficiency. Our extensive evaluations suggest that Pinokio can accurately detect spectrum misuse, and limit the inflation of airtime utilization from more than 730% to less than 20%. Kefeng Tan, Kai Zeng 0001, Daniel Wu, Prasant Mohapatra |
MASS | 2 |
| 2012 | Fast rendezvous for cognitive radios by exploiting power leakage at adjacent channelsabstractCognitive radio is considered as a promising technology that enables dynamic spectrum access and improves spectrum utilization. To bootstrap the communication, rendezvous process is crucial for cognitive radio users to establish communication links among each other. Blind rendezvous is a representative technology for rendezvous purpose without relying on a common control channel. Existing works mainly focus on channel hopping (CH) sequence design to speed up or guarantee users meeting on the same channel, while largely ignored the MAC overhead and PHY layer characteristics. This paper proposes new blind rendezvous protocols that take into account the handshaking overhead and power leakage at adjacent channels. Our basic idea is that a cognitive radio user can infer the transmission at adjacent channels by exploiting adjacent channel power leakage, then it can launch a local channel search to find the other user even when they are not on the same channel initially, thus speeding up the rendezvous process. We analyze the time to rendezvous (TTR) of our protocols with two-user and multi-user settings, and identify the conditions under which our protocols outperform the existing ones. We have conducted extensive simulations to evaluate our protocols. Both analytical and simulation results show that our protocols can significantly decrease the time to rendezvous (TTR) by by 53.5% over the packets decoding based rendezvous. Li Zhang 0129, Kefeng Tan, Kai Zeng 0001, Prasant Mohapatra |
PIMRC | 3 |
| 2012 | Transmit power estimation with a single monitor in multi-band networksabstractTransmit power estimation is widely used in network monitoring, power-aware design of MANETs, primary user detection in cognitive radio networks and many other areas. Traditional methods for transmit power estimation are trilateration-based, which require an underlying infrastructure with at least three monitors. In this paper, we propose a novel transmit power estimation method which utilizes the nuance of the received signal strength at different frequencies. Our method only needs one monitor, thus has less hardware requirement and is much easier to carry around. We use a support vector machine to facilitate the estimation, and conduct real-world experiments to validate our method. The experimental results demonstrate that our method is able to achieve the accuracy as high as 90%, which in practice outperforms the trilateration method using multiple monitors. Shaxun Chen, Kai Zeng 0001, Ningning Cheng, Prasant Mohapatra |
SECON | 2 |
| 2012 | Improving crowd-sourced Wi-Fi localization systems using Bluetooth beaconsabstractCrowd-sourced Wi-Fi-based localization systems utilize user input for RF scene analysis and map construction. Such systems reduce the deployment cost and privacy concerns that expert-based site survey systems can create. However, the main bottleneck of such crowd-sourcing localization systems is a bootstrapping stage, where lack of contributions by users results in no accuracy guarantee and frequent unnecessary prompting for users' input, even for explored areas. In this paper, we propose a crowd-sourcing localization system that uses both Wi-Fi scene analysis and Bluetooth beacons to address the insufficient contribution challenge. After prompting for user input, the mobile device not only submits Wi-Fi fingerprint to a map server, but also enables Bluetooth beacons to disseminate/share its location and fingerprint information to quickly populate the signal map. Then, subsequent user devices entering the area can discover the Bluetooth beacons and are able to instantly obtain room-level location information without causing unnecessary prompting to users. We implement our proposed system in the Linux OS and evaluate the prototype extensively through both experiments and simulation. Our evaluation results show that using Bluetooth beacons help to improve signal map growth, while maintaining reasonable localization accuracy. Jindan Zhu, Kai Zeng 0001, Kyu-Han Kim, Prasant Mohapatra |
SECON | 2 |
| 2012 | Secondary User Monitoring in Unslotted Cognitive Radio Networks with Unknown Models
Shanhe Yi, Kai Zeng 0001, Jing Xu 0005 |
WASA | 2 |
| 2012 | Edge-prioritized channel- and traffic-aware uplink Carrier Aggregation in LTE-advanced systemsabstractLTE-Advanced (LTE-A) systems support wider transmission bandwidths and hence, higher data rates for bulk traffic, as a result of Carrier Aggregation (CA). However, existing literature lacks efforts on channel-aware CA, especially in the uplink. The cell-edge users particularly suffer from exhaustion of resources, higher fading losses, lower SINR values (hence, requiring a higher power consumption) due to lossy channels that their traffic requirements are least-satisfied by channel-blind CA. This paper addresses the above concern by proposing an edge-prioritized channel- and traffic-aware uplink CA comprising Component Carrier (CC) assignment and resource scheduling. The LTE-A UEs are spatially-grouped and the under-represented edge UE groups, having the least assignable resources (good CCs), are prioritized for CA. This results in assigning the best channels to the edge groups. The frequency resources are scheduled to the groups based on inter-group and intra-group Proportional Fair Packet Scheduling (PFPS) in the time and frequency domains respectively, to resolve resource contention. The proposed approach outperforms the existing channel-blind Round-Robin and channel-aware Opportunistic CA, in terms of overall uplink throughput, by 33% in CC assignment and 21% in PFPS, in addition to significant throughput improvements for the edge UEs. Rajarajan Sivaraj, Amit Pande, Kai Zeng 0001, Kannan Govindan 0001, Prasant Mohapatra |
WOWMOM | 3 |
| 2012 | On energy efficiency of geographic opportunistic routing in lossy multihop wireless networks
Kai Zeng 0001, Wenjing Lou |
Wirel. Networks | 1 |
| 2011 | Measurement-Based Short-Term Performance Prediction in Wireless Mesh NetworksabstractTraditionally, the performance of wireless mesh networks (WMNs) is measured by long-term averaged metrics, such as long-term averaged packet delivery ratio or throughput. However, due to the dynamic nature of the wireless networks, long-term averaged metrics cannot reflect the short-term behaviors of the network. In the meanwhile, the users may require a sustained performance for a certain period of time in many realtime applications. Prediction of network performance of WMNs at the level of individual flows in a small time granularity becomes very important, but is missing in the literature. In this paper, we propose a measurement-based model to predict the short-term performance of both goodput and packet loss for individual flows in WMNs. This model captures the complex dependencies among the different queues in the system, traffic demand, and wireless interference in the network. We developed two tools Rater and CalMedium to calculate the probabilities of packet loss along all the layers in the protocol stack at each node. Real-world experiments on an indoor mesh network testbed demonstrate that our prediction method can achieve accurate performance prediction under both single-flow and multiple-flow scenarios. We also discuss two application examples of utilizing our prediction model: finding the bottleneck rate of a flow and admission control. Kai Zeng 0001, Prasant Mohapatra |
ICCCN | 2 |
| 2011 | Efficient data capturing for network forensics in cognitive radio networksabstractNetwork forensics is widely used in tracking down criminals and detecting network anomalies, and data capture is the basis of network forensics. Compared to traditional networks, data capture faces significant challenges in cognitive radio networks. In traditional wireless networks, one monitor is usually assigned to one channel to capture traffic, which incurs very high cost in a cognitive radio network because the latter typically has a large number of channels. Furthermore, due to the uncertainty of the primary user's activity, cognitive radio devices change their operating channels randomly, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. In addition, a protocol is proposed to schedule multiple monitors to perform channel scan and packet capturing in an efficient manner. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%. Shaxun Chen, Kai Zeng 0001, Prasant Mohapatra |
ICNP | 2 |
| 2011 | Hearing is believing: Detecting mobile primary user emulation attack in white spaceabstractIn cognitive radio networks, an adversary transmits signals whose characteristics emulate those of primary users, in order to prevent secondary users from transmitting. Such an attack is called primary user emulation (PUE) attack. There are two main types of primary users in white space: TV towers and wireless microphones. Existing work on PUE attack detection focused on the first category. However, for the latter category, primary users are mobile and their transmission power is low. These unique properties of wireless microphones introduce great challenges and existing methods are not applicable. In this paper, we propose a novel method to detect the PUE attack of mobile primary users. We exploit the correlations between RF signals and acoustic information to verify the existence of wireless microphones. The effectiveness of our approach is validated through extensive real-world experiments. It shows that our method achieves both false positive rate and false negative rate lower than 0.1. Shaxun Chen, Kai Zeng 0001, Prasant Mohapatra |
INFOCOM | 2 |
| 2011 | Adaptive wireless channel probing for shared key generationabstractGenerating a shared key between two parties from the wireless channel is of increasing interest. The procedure for obtaining information from wireless channel is called channel probing. Previous works used a constant channel probing rate to generate a key, but they neither consider the tradeoff between the bit generation rate (BGR) and channel resource consumption, nor adjust the probing rate according to different scenarios. In order to satisfy users' requirement for BGR and to use the wireless channel efficiently, we first build a mathematical model of channel probing and derive the relationship between BGR and probing rate. Second, we introduce an adaptive channel probing system based on Lempel-Ziv complexity (LZ76) and Proportional-Integral-Derivative (PID) controller. Our scheme uses LZ76 to estimate the entropy rate of the channel statistics, e.g. the Received Signal Strength (RSS), and uses the PID controller to control the channel probing rate. Our experiments show that this system is able to dynamically adjust its probing rate to achieve a desired BGR under different moving speeds, different mobile types, and different sites. Our results also show that the standard deviation of the LZ76 calculator is less than 0.15 bits/s. The PID controller is able to stabilize the bit generation rate at a desired value with mean error of less than 0.9 bits/s. Yunchuan Wei, Kai Zeng 0001, Prasant Mohapatra |
INFOCOM | 2 |
| 2011 | Identity-based attack detection in mobile wireless networksabstractIdentity-based attacks (IBAs) are one of the most serious threats to wireless networks. Recently, received signal strength (RSS) based detection mechanisms were proposed to detect IBAs in static networks. Although mobility is an inherent property of wireless networks, limited work has addressed IBA detection in mobile scenarios. In this paper, we propose a novel RSS based technique, Reciprocal Channel Variation-based Identification (RCVI), to detect IBAs in mobile wireless networks. RCVI takes advantage of the location decorrelation, randomness, and reciprocity of the wireless fading channel to decide if all packets come from a single sender or more. If the packets are only coming from the genuine sender, the RSS variations reported by the sender should be correlated with the receiver's observations. Otherwise, the correlation should be degraded, then an attack can be flagged. We evaluate RCVI through theoretical analysis, and validate it through experiments using off-the-shelf 802.11 devices under different attacking patterns in real indoor and outdoor mobile scenarios. We show that RCVI can detect IBAs with a high probability even when the attacker is half a meter away from the genuine user. Kai Zeng 0001, Kannan Govindan 0001, Daniel Wu, Prasant Mohapatra |
INFOCOM | 1 |
| 2011 | Good Neighbor: Ad hoc Pairing of Nearby Wireless Devices by Multiple Antennas
Kai Zeng 0001, Hao Chen 0003, Prasant Mohapatra |
NDSS | 2 |
| 2011 | Opportunistic spectrum scheduling for mobile cognitive radio networks in white spaceabstractRecent works have shown that the white-space spectrum opened to cognitive radio devices is far less than what the lobbyists claimed. With fast growing number of secondary users, carefully scheduling the spectrum allocation in cognitive radio networks operating on white space becomes vital. However, the frequent ON/OFF activity of primary users (PU) and the mobility of the cognitive users make the problem of spectrum scheduling extremely hard. By modeling the PUs activity in an opportunistic manner, this paper studies how to schedule the spectrum assignment for mobile cognitive radio devices. With the mobility information, we formally define the related problem as the Maximum Throughput Channel Scheduling problem (MTCS) which seeks a channel assignment schedule for each cognitive radio device such that the maximum expected throughput can be achieved. We present a general scheduling framework for solving the MTCS. Based on the proposed framework, we then present two polynomial time optimal algorithms to solve the MTCS in the homogeneous and the heterogeneous traffic load cases, respectively. Our algorithms are evaluated by simulations using the mobility trace obtained from a real world public transportation system. On average, the proposed algorithms outperform a greedy algorithm by 21.6%. Li Zhang 0129, Kai Zeng 0001, Prasant Mohapatra |
WCNC | 2 |
| 2011 | Opportunistic broadcast of event-driven warning messages in Vehicular Ad Hoc Networks with lossy links
Ming Li 0003, Kai Zeng 0001, Wenjing Lou |
Comput. Networks | 2 |
| 2011 | Probability Density of the Received Power in Mobile NetworksabstractProbability density of the received power is well analyzed for wireless networks with static nodes. However, most of the present days networks are mobile and not much exploration has been done on statistical analysis of the received power for mobile networks in particular, for the network with random moving patterns. In this paper, we derive probability density of the received power for mobile networks with random mobility models. We consider the power received at an access point from a particular mobile node. Two mobility models are considered: Random Direction (RD) model and Random way-point (RWP) model. Wireless channel is assumed to have a small scale fading of Rayleigh distribution and path loss exponent of 4. 3D, 2D and 1D deployment of nodes are considered. Our findings show that the probability density of the received power for RD mobility models for all the three deployment topologies are weighted confluent hypergeometric functions. In case of RWP mobility models, the received power probability density for all the three deployment topologies are linear combinations of confluent hypergeometric functions. The analytical results are validated through NS2 simulations and a reasonably good match is found between analytical and simulation results. Kannan Govindan 0001, Kai Zeng 0001, Prasant Mohapatra |
IEEE Trans. Wirel. Commun. | 2 |
| 2010 | Jamming-Resistant Communication: Channel Surfing without NegotiationabstractChannel surfing is an effective method to prevent jamming attacks in wireless communications. In traditional channel surfing schemes, two parties have to negotiate beforehand, in order to agree on the channel switching sequence. However, the negotiation process itself is vulnerable to jamming attacks. In this paper, we propose a novel channel surfing method without relying on such negotiation. Taking advantage of the reciprocity of the wireless fading channel, our method switches channels according to the random channel states observed by the two parties during their communication. Therefore, it does not introduce any extra communication overhead and can achieve strong security. To evaluate our method, we carry out extensive experiments using off-the-shelf 802.11 devices in a real indoor environment. Experimental results validate the efficiency and security of our method. Shaxun Chen, Kai Zeng 0001, Prasant Mohapatra |
ICC | 2 |
| 2010 | Metrics for Evaluating Video Streaming Quality in Lossy IEEE 802.11 Wireless NetworksabstractPeak Signal-to-Noise Ratio (PSNR) is the simplest and the most widely used video quality evaluation methodology. However, traditional PSNR calculations do not take the packet loss into account. This shortcoming, which is amplified in wireless networks, contributes to the inaccuracy in evaluating video streaming quality in wireless communications. Such inaccuracy in PSNR calculations adversely affects the development of video communications in wireless networks. This paper proposes a novel video quality evaluation methodology. As it not only considers the PSNR of a video, but also with modifications to handle the packet loss issue, we name this evaluation method MPSNR. MPSNR rectifies the inaccuracies in traditional PSNR computation, and helps us to approximate subjective video quality, Mean Opinion Score (MOS), more accurately. Using PSNR values calculated from MPSNR and simple network measurements, we apply linear regression techniques to derive two specific objective video quality metrics, PSNR-based Objective MOS (POMOS) and Rates-based Objective MOS (ROMOS). Through extensive experiments and human subjective tests, we show that the two metrics demonstrate high correlation with MOS. POMOS takes the averaged PSNR value of a video calculated from MPSNR as the only input. Despite its simplicity, it has a Pearson correlation of 0.8664 with the MOS. By adding a few other simple network measurements, such as the proportion of distorted frames in a video, ROMOS achieves an even higher Pearson correlation (0.9350) with the MOS. Compared with the PSNR metric from the traditional PSNR calculations, our metrics evaluate video streaming quality in wireless networks with a much higher accuracy while retaining the simplicity of PSNR calculation. An (Jack) Chan, Kai Zeng 0001, Prasant Mohapatra, Sung-Ju Lee 0001, Sujata Banerjee |
INFOCOM | 2 |
| 2010 | Exploiting Multiple-Antenna Diversity for Shared Secret Key Generation in Wireless NetworksabstractGenerating a secret key between two parties by extracting the shared randomness in the wireless fading channel is an emerging area of research. Previous works focus mainly on single-antenna systems. Multiple-antenna devices have the potential to provide more randomness for key generation than single-antenna ones. However, the performance of key generation using multiple-antenna devices in a real environment remains unknown. Different from the previous theoretical work on multiple-antenna key generation, we propose and implement a shared secret key generation protocol, Multiple-Antenna KEy generator (MAKE) using off-the-shelf 802.11n multiple-antenna devices. We also conduct extensive experiments and analysis in real indoor and outdoor mobile environments. Using the shared randomness extracted from measured Received Signal Strength Indicator (RSSI) to generate keys, our experimental results show that using laptops with three antennas, MAKE can increase the bit generation rate by more than four times over single-antenna systems. Our experiments validate the effectiveness of using multi-level quantization when there is enough mutual information in the channel. Our results also show the trade-off between bit generation rate and bit agreement ratio when using multi-level quantization. We further find that even if an eavesdropper has multiple antennas, she cannot gain much more information about the legitimate channel. Kai Zeng 0001, Daniel Wu, An (Jack) Chan, Prasant Mohapatra |
INFOCOM | 1 |
| 2010 | Opportunistic Routing in Multi-radio Multi-channel Multi-hop Wireless NetworksabstractTwo major factors that limit the throughput in multi-hop wireless networks are the unreliability of wireless transmissions and co-channel interference. One promising technique that combats lossy wireless transmissions is opportunistic routing (OR). OR involves multiple forwarding candidates to relay packets by taking advantage of the broadcast nature and spacial diversity of the wireless medium. Furthermore, recent advances in multi-radio multi-channel transmission technology allows more concurrent transmissions in the network, and shows the potential of substantially improving the system capacity. However, the performance of OR in multi-radio multi-channel systems is still unknown, and the methodology of studying the performance of traditional routing (TR) can not be directly applied to OR. In this paper, we present our research on computing an end-to-end throughput bound of OR in multi-radio multi-channel systems. We formulate the capacity of OR as a linear programming (LP) problem which jointly solves the radio-channel assignment and transmission scheduling. Leveraging our analytical model, we gain the following insights into OR: 1) OR can achieve better performance than TR under different radio/channel configurations, however, in particular scenarios, TR is more preferable than OR; 2) OR can achieve comparable or even better performance than TR by using less radio resource; 3) for OR, the throughput gained from increasing the number of potential forwarding candidates becomes marginal. Kai Zeng 0001, Zhenyu Yang 0007, Wenjing Lou |
INFOCOM | 1 |
| 2010 | Opportunistic Routing in Multi-Radio Multi-Channel Multi-Hop Wireless NetworksabstractTwo major factors that limit the throughput in multi-hop wireless networks are the co-channel interference and unreliability of wireless transmissions. Multi-radio multi-channel technology and opportunistic routing (OR) have shown their promise to significantly improve the network capacity by combating these two limits. It raises an interesting problem on the tradeoff between multiplexing and spatial diversity when integrating these two techniques for throughput optimization. It is unknown what the capacity of the network could be when nodes have multiple radios and OR capability. In this paper, we present our study on optimizing an end-to-end throughput of the multi-radio multi-channel network when OR is available. First, we formulate the end-to-end throughput bound as a linear programming (LP) problem which jointly solves the radio-channel assignment, transmission scheduling, and forwarding candidate selection. Second, we propose an LP approach and a heuristic algorithm to find a feasible scheduling of opportunistic forwarding priorities to achieve the capacity. Simulations show that the heuristic algorithm achieves desirable performance under various number of forwarding candidates. Leveraging our analytical model, we find that 1) OR can achieve better performance than traditional routing (TR) under different radio/channel configurations, however, in particular scenario (e.g. bottleneck links exist between the sender and relays), TR is preferable; 2) OR can achieve comparable or better performance than TR by using less radio resource. Kai Zeng 0001, Zhenyu Yang 0007, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 1 |
| 2009 | FSA: A Fast Coordination Scheme for Opportunistic RoutingabstractAbstract—Opportunistic Routing (OR) has been considered as one promising technique to overcome the unreliability of the wireless medium by collaborating multiple neighboring re-ceivers/candidates for packet forwarding. A key challenge in OR is how to efficiently coordinate the multiple candidates and ensure only one of them to forward the packet. In this paper, we investigate the existing candidate coordination schemes and propose a“fast slotted acknowledgment ” (FSA) to further improve the performance of OR by using single ACK with the help of channel sensing technique. The simulation results show that FSA can reduce the average end-to-end time delay of OR protocols by up to 50 % compared with state-of-the-art coordination schemes in light traffic scenarios and can increase the average end-to-end throughput by up to 20 % in heavy traffic scenarios. I. Zhenyu Yang 0007, Kai Zeng 0001, Wenjing Lou |
ICC | 2 |
| 2009 | OppCast: Opportunistic Broadcast of Warning Messages in VANETs with Unreliable LinksabstractMulti-hop broadcast is a key technique to disseminate important information such as time-sensitive safety warning messages (WMs) in Vehicular Ad hoc Networks (VANETs). Due to the fact that the implementation of broadcast at the link layer uses unreliable transmissions (i.e., lack of positive ACKs), highly reliable, scalable, and fast multi-hop broadcast protocol is particularly difficult to design in VANETs with unreliable links. Schemes that use redundant network layer broadcasts have been proposed. However, the balance between receiving reliability and transmission count in such schemes needs to be carefully considered. In this paper, we propose the opportunistic broadcast protocol (OppCast) that aims at minimizing the number of transmissions while achieving high network packet reception ratio (PRR) and fast multi-hop message propagation simultaneously. A double-phase broadcast strategy is proposed to achieve fast message propagation in one phase and to ensure high PRR in the other. The idea of opportunistic forwarding is exploited at each hop to minimize the propagation latency. An opportunistic forwarding protocol is designed accordingly as a MAC-layer broadcast coordination function, that allows multiple nodes to agree on the actual relay nodes in a distributed fashion. The proposed function also alleviates the hidden terminal problem. Theoretical analysis is carried out to optimize and design both broadcast phases. Extensive simulation results show that, compared with existing competing protocols, OppCast achieves close to 100% PRR and fast dissemination rate under a wide range of vehicle densities, while using significantly smaller number of transmissions. Ming Li 0003, Wenjing Lou, Kai Zeng 0001 |
MASS | 3 |
| 2009 | Energy aware efficient geographic routing in lossy wireless sensor networks with environmental energy supply
Kai Zeng 0001, Kui Ren 0001, Wenjing Lou, Patrick J. Moran |
Wirel. Networks | 1 |
| 2008 | Towards Secure Link Quality Measurement in Multihop Wireless NetworksabstractLink quality measurement (LQM), i.e. packet reception ratio (PRR) measurement, is becoming an indispensable component in multihop wireless networks. However, in all the existing LQM mechanisms, a common fact is that a node's knowledge about the forward PRR from itself to its neighbor is informed by the neighbor. On the one hand, this receiver- dependent measurement provides accurate and timely updates on the link quality. On the other hand, it opens up a door for a malicious node to easily report a false measurement result to mislead the routing decision and degrade the system performance. In this paper, we analyze the security vulnerabilities in the existing LQM mechanisms and propose an efficient broadcast- based secure LQM (SLQM) mechanism, which prevents the malicious receiver from reporting a higher PRR than the actual one. We analyze the security strength and the cost of the proposed mechanism. Simulation results show that even when there are only 10% malicious nodes in the network, the average end-to-end throughput can be degraded by 50% compared with the normally operated network, which demonstrates the importance of employing SLQM mechanisms. To the best of our knowledge, this is the first work addressing the SLQM problem in multihop wireless networks. Kai Zeng 0001, Shucheng Yu, Kui Ren 0001, Wenjing Lou |
GLOBECOM | 1 |
| 2008 | On End-to-End Throughput of Opportunistic Routing in Multirate and Multihop Wireless NetworksabstractRouting in multi-hop wireless networks presents a great challenge mainly due to unreliable wireless links and interference among concurrent transmissions. Recently, a new routing paradigm, opportunistic routing (OR), is proposed to cope with the unreliable transmissions by exploiting the broadcast nature and spatial diversity of the wireless medium. Previous studies on OR focused on networks with a single channel rate. The performance of OR in a multi-rate scenario is not carefully studied. In addition, although simulation and practical implementation have shown that OR achieves better throughput performance than that of traditional routing, there is no theoretical results on capacity enhancement provided by OR or network capacity bounds of OR. In this paper, we bridge these gaps by carrying out a comprehensive study on the impacts of multiple rates, interference, candidate selection and prioritization on the maximum end-to-end throughput or capacity of OR. Taking into consideration of wireless interference, we propose a new method of constructing transmission conflict graphs - we propose transmitter based conflict graph in contrast to link conflict graph. Then, we introduce the concept of concurrent transmitter sets to represent the constraints imposed by the transmission conflicts of OR, and formulate the maximum end-to-end throughput problem as a maximum-flow linear programming problem subject to the transmission conflict constraints. We also propose a rate selection scheme, and compare the throughput capacity of multi- rate OR with single-rate ones. We validate the analysis results by simulation, and show that OR has great potential to improve end- to-end throughput and system operating at multi-rates achieves higher throughput than that operating at any single rate. Kai Zeng 0001, Wenjing Lou, Hongqiang Zhai |
INFOCOM | 1 |
| 2008 | Secure and Fault-Tolerant Event Boundary Detection in Wireless Sensor NetworksabstractEvent boundary detection is in and of itself a useful application in wireless sensor networks (WSNs). Typically, it includes the detection of a large-scale spatial phenomenon such as the transportation front line of a contamination or the diagnosis of network health. In this paper, we present SEBD, a fully distributed and light-weight secure event boundary detection scheme, which implements secure and fault-tolerant detection of event boundaries in an adversarial environment. An efficient key establishment protocol is first proposed which establishes location based keys at each sensor node to secure the communications. The idea of location-based keys also effectively minimizes the impact of node compromise such that a compromised node cannot impersonate other nodes at locations other than where it is. Then a collaborative endorsement scheme is designed to allow multiple nodes collectively endorsing a valid boundary claim for increased resilience against node compromise. SEBD further develops an enhanced (nonparametric) statistical model that supports localized detection and shows a much better accuracy and fault tolerance property as compared to previous models. The security strength and performance of SEBD are evaluated by both analysis and simulations. Kui Ren 0001, Kai Zeng 0001, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 2 |
| 2008 | Capacity of opportunistic routing in multi-rate and multi-hop wireless networksabstractOpportunistic routing (OR) copes with the unreliable transmissions by exploiting the broadcast nature of the wireless medium and spatial diversity of the multi-hop wireless networks. In this paper, we carry out a comprehensive study on the impacts of multiple rates, interference, candidate selection and prioritization on the maximum end-to-end throughput or capacity of OR. Taking into account the wireless interference and unique properties of OR, we introduce the concept of concurrent transmitter sets to represent the constraints imposed by the transmission conflicts of OR, and formulate the maximum end-to-end throughput problem as a maximum-flow linear programming subject to the transmission conflict constraints. We also propose two multi-rate OR metrics: expected medium time (EMT) and expected advancement rate (EAR), and the corresponding distributed and local rate and candidate set selection schemes, one of which is least medium time OR (LMTOR) and the other is multi-rate geographic OR (MGOR). We compare the capacity of multi-rate OR with single-rate ones under different settings. We show that our proposed multi-rate OR schemes achieve higher throughput bound than any single-rate GOR. We observe some insights of OR: 1) although involving more forwarding candidates increases the end-to-end capacity, the capacity gained from involving more forwarding candidates decreases; 2) there exists a node density threshold, higher than which 24 Mbps GOR performs better than 12 Mbps GOR, and vice versa. Kai Zeng 0001, Wenjing Lou, Hongqiang Zhai |
IEEE Trans. Wirel. Commun. | 1 |
| 2007 | On throughput efficiency of geographic opportunistic routing in multihop wireless networksabstractGeographic opportunistic routing (GOR) is a new routing concept in multihop wireless networks. In stead of picking one node to forward a packet to, GOR forwards a packet to a set of candidate nodes and one node is selected dynamically as the actual forwarder based on the instantaneous wireless channel condition and node position and availability at the time of transmission. GOR takes advantages of the spatial diversity and broadcast nature of wireless communications and is an efficient mechanism to combat the unreliable links. The existing GOR schemes typically involve as many as available next-hop neighbors into the local opportunistic forwarding, and give the nodes closer to the destination higher relay priorities. In this paper, we focus on realizing GOR's potential in maximizing throughput. We start with an insightful analysis of various factors and their impact on the throughput of GOR, and propose a local metric named expected one-hop throughput (EOT) to balance the tradeoff between the benefit (i.e., packet advancement and transmission reliability) and the cost (i.e., medium time delay). We identify an upper bound of EOT and proof its concavity. Based on the EOT, we also propose a local candidate selection and prioritization algorithm. Simulation results validate our analysis and show that the metric EOT leads to both higher one-hop and path throughput than the corresponding pure GOR and geographic routing. Kai Zeng 0001, Wenjing Lou, D. Richard Brown III |
QSHINE | 1 |
| 2007 | On Throughput Efficiency of Geographic Opportunistic Routing in Multihop Wireless Networks
Kai Zeng 0001, Wenjing Lou, D. Richard Brown III |
Mob. Networks Appl. | 1 |
| 2007 | On Broadcast Authentication in Wireless Sensor NetworksabstractBroadcast authentication is a critical security service in wireless sensor networks (WSNs), since it enables users to broadcast the WSN in an authenticated way. Symmetric key based schemes such as muTESLA and multilevel muTESLA have been proposed to provide such services for WSNs; however, these schemes all suffer from serious DoS attacks due to the delay in message authentication. This paper presents several effective public key based schemes to achieve immediate broadcast authentication and thus overcome the vulnerability presented in the muTESLA-like schemes. Several cryptographic techniques, including Merkle hash tree and identity-based signature scheme, are adopted to minimize the scheme overhead regarding the costs on both computation and communication. A quantitative energy consumption analysis of the proposed schemes is given in detail. We believe that this paper can serve as the start point towards fully solving the important multisender broadcast authentication problem in WSNs. Kui Ren 0001, Wenjing Lou, Kai Zeng 0001, Patrick J. Moran |
IEEE Trans. Wirel. Commun. | 3 |
| 2006 | Fault-tolerant Event Boundary Detection in Wireless Sensor NetworksabstractEvent boundary detection is in and of itself a useful application in wireless sensor networks (WSNs). Typically, it includes the detection of a large-scale spatial phenomenon such as the transportation front line of a contamination or the diagnosis of network health. In this paper, we present FEBD, a fully distributed and light-weight fault-tolerant event boundary detection scheme. FEBD features an enhanced (nonparametric) statistical model that supports localized detection among neighboring nodes. To enhance detection accuracy, FEBD also introduces an error suppression technique prior to the determination of boundary nodes. The proposed scheme shows a much better detection accuracy and fault tolerance properties as compared to the previous models. The proposed FEBD is evaluated by extensive simulations, and presents very good detection accuracy, even when sensor fault probability is as high as 20%. Kui Ren 0001, Kai Zeng 0001, Wenjing Lou |
GLOBECOM | 2 |
| 2006 | Energy-aware geographic routing in lossy wireless sensor networks with environmental energy supplyabstractWireless sensor networks are characterized by multihop wireless lossy links and resource constrained nodes. Energy efficiency is a major concern in such networks. In this paper, we study Geographic Routing with Environmental Energy Supply (GREES) and propose two protocols, GREES-L and GREES-M, which combine geographic routing and energy-aware routing techniques and take into account the realistic lossy wireless channel condition and the renewal capability of environmental energy supply when making routing decisions. Simulation results show that GREESs are more energy efficient than the corresponding residual energy based protocols and geographic routing protocols without energy awareness. GREESs can maintain higher mean residual energy on nodes, and achieve better load balancing in terms of having smaller standard deviation of residual energy on nodes. Both GREES-L and GREES-M exhibit graceful degradation on end-to-end delay, but do not compromise the end-to-end throughput performance. Kai Zeng 0001, Kui Ren 0001, Wenjing Lou, Patrick J. Moran |
QSHINE | 1 |
| 2006 | On Broadcast Authentication in Wireless Sensor Networks
Kui Ren 0001, Kai Zeng 0001, Wenjing Lou, Patrick J. Moran |
WASA | 2 |
| 2006 | Routing optimization security in mobile IPv6
Kui Ren 0001, Wenjing Lou, Kai Zeng 0001, Feng Bao 0001, Jianying Zhou 0001, Robert H. Deng |
Comput. Networks | 3 |
| 2006 | A new approach for random key pre-distribution in large-scale wireless sensor networksabstractAbstract In a wireless sensor network (WSN), pre‐distribution of secret keys is possibly the most practical approach to protect network communications. To meet the stringent resource constraints of the sensor nodes, key pre‐distribution schemes should be highly efficient, require as little storage space as possible, and at the same time, maintain a strong security strength, that is, high resilience against node capture. In this paper, a new approach for random key pre‐distribution is proposed to achieve both efficiency and security goals. The novelty of this approach lies in that, instead of using a key pool consisting of random keys, a key generation technique is carefully designed such that a large number of random keys can be represented by a small number of key‐generation keys. Then, instead of storing a big number of random keys, each sensor node stores a small number of key‐generation keys while computing the shared secret keys during the bootstrapping phase on the fly using the computationally efficient hash function. The proposed scheme outperforms the previous random key pre‐distribution schemes in that it reduces the storage requirement significantly while holding the comparable security strength, as shown by our thorough analysis and simulation. Copyright © 2006 John Wiley & Sons, Ltd. Kui Ren 0001, Kai Zeng 0001, Wenjing Lou |
Wirel. Commun. Mob. Comput. | 2 |