If you are interested in our research, you can also find the following links with more detailed information!
- Wenyuan Xu: Personal Page
- Xiaoyu Ji: Personal Page
- Yanjiao Chen: Personal Page
- Kaikai Pan: Personal Page
- Chen Yan: Personal Page
- Yushi Cheng: Personal Page
Easier Said Than Done: Unpacking Intent–Behavior Gap in Jailbreaking LLM-based Robots Accept by Network and Distributed System Security Symposium (NDSS) 2027 Code Homepage Arxiv
Phantom Menace: Exploring and Enhancing the Robustness of VLA Models Against Physical Sensor Attacks Accept by AAAI Conference on Artificial Intelligence (AAAI) 2026 Code Arxiv Paper
CamPI: Physical Adversarial Examples through Camera Power Signal Injection Accept by IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 2026 Paper
Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs Accept by Network and Distributed System Security Symposium (NDSS) 2026 Code
SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities Accept by Network and Distributed System Security Symposium (NDSS) 2026 Arxiv Paper
PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal Fuzzing Accept by Network and Distributed System Security Symposium (NDSS) 2026 Paper
TRAP: Hijacking VLA CoT-Reasoning via Adversarial Patches Accept by International Conference on Machine Learning (ICML) 2026 Code Homepage Arxiv
GhostTac: Manipulating Tactile Sensors without Physical Contact Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2026 Homepage
Myopia: protecting face privacy from malicious personalized text-to-image synthesis via unlearnable examples Accept by AAAI Conference on Artificial Intelligence (AAAI) 2025 Code
AdvPainting: Clean-text Jailbreaking Against Inpainting Models Accept by ACM International Conference on Multimedia (MM) 2025 Paper
BARBIE: Robust Backdoor Detection Based on Latent Separability Accept by Network and Distributed System Security Symposium (NDSS) 2025 Code
LightAntenna: Characterizing the Limits of Fluorescent Lamp-Induced Electromagnetic Interference Accept by Network and Distributed System Security Symposium (NDSS) 2025
PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR Accept by Network and Distributed System Security Symposium (NDSS) 2025 Arxiv Paper
PowerRadio: Manipulate Sensor Measurement via Power GND Radiation Accept by Network and Distributed System Security Symposium (NDSS) 2025 Homepage Arxiv Paper
Retriever: A Distributed Intrusion Detection System for NOS-Enabled Networks Accept by IEEE Transactions on Dependable and Secure Computing (TDSC) 2025 Code Paper
Neural Invisibility Cloak: Concealing Adversary in Images via Compromised AI-driven Image Signal Processing Accept by USENIX Security Symposium (USENIX Security) 2025 Homepage
GhostShot: Manipulating the Image of CCD Cameras with Electromagnetic Interference Accept by Network and Distributed System Security Symposium (NDSS) 2025 Paper
Sensor-based IoT data privacy protection Accept by Nature Reviews Electrical Engineering (Nat. Rev. Electr. Eng.) 2024 Paper
SafeEar: Content Privacy-Preserving Audio Deepfake Detection Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2024 Code Homepage Arxiv Paper
Legilimens: Practical and Unified Content Moderation for Large Language Model Services Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2024 Arxiv Paper
CamPro: Camera-based Anti-Facial Recognition Accept by Network and Distributed System Security Symposium (NDSS) 2024 Code Arxiv Paper
UniID: Spoofing Face Authentication System by Universal Identity Accept by Network and Distributed System Security Symposium (NDSS) 2024 Paper
GhostType: The Limits of Using Contactless Electromagnetic Interference to Inject Phantom Keys into Analog Circuits of Keyboards Accept by Network and Distributed System Security Symposium (NDSS) 2024 Paper
Understanding and Benchmarking the Commonality of Adversarial Examples Accept by IEEE Symposium on Security and Privacy (SP) 2024 Paper
SafeGen: Mitigating Unsafe Content Generation in Text-to-Image Models Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2024 Code Arxiv Paper
Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack Accept by ACM Web Conference (WWW) 2024 Code Homepage Paper
Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time Accept by Network and Distributed System Security Symposium (NDSS) 2024 Code Homepage Arxiv Paper
MicPro: Microphone-based Voice Privacy Protection Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2023 Code Homepage Paper
VILLAIN: Backdoor Attacks Against Vertical Split Learning Accept by USENIX Security Symposium (USENIX Security) 2023 Paper
TPatch: A Triggered Physical Adversarial Patch Accept by USENIX Security Symposium (USENIX Security) 2023 Code Arxiv Paper
Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice Attacks Accept by USENIX Security Symposium (USENIX Security) 2023 Paper
CAPatch: Physical Adversarial Patch against Image Captioning Systems Accept by USENIX Security Symposium (USENIX Security) 2023 Code Paper
GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMI Accept by USENIX Security Symposium (USENIX Security) 2023 Paper
V-Cloak: Intelligibility-, Naturalness- & Timbre-Preserving Real-Time Voice Anonymization Accept by USENIX Security Symposium (USENIX Security) 2023 Arxiv Paper
Catch You and I Can: Revealing Source Voiceprint Against Voice Conversion Accept by USENIX Security Symposium (USENIX Security) 2023 Arxiv Paper
Volttack: Control IoT Devices by Manipulating Power Supply Voltage Accept by IEEE Symposium on Security and Privacy (SP) 2023 Code Paper
DepthFake: Spoofing 3D Face Authentication with a 2D Photo Accept by IEEE Symposium on Security and Privacy (SP) 2023 Paper
PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous Vehicle Accept by IEEE Symposium on Security and Privacy (SP) 2023 Paper
DeHiREC: Detecting Hidden Voice Recorders via ADC Electromagnetic Radiation Accept by IEEE Symposium on Security and Privacy (SP) 2023 Paper
MagView++: Data Exfiltration via CPU Magnetic Signals Under Video Decoding Accept by IEEE Transactions on Mobile Computing (TMC) 2023 Paper
PDGes: An Interpretable Detection Model for Parkinson's Disease Using Smartphones Accept by ACM Transactions on Sensor Networks (ToSN) 2023 Paper
Toward Pitch-Insensitive Speaker Verification via Soundfield Accept by IEEE Internet of Things Journal (IoTJ) 2023 Paper
Critical cyber parameters in hybrid power systems with VSP-based virtual inertia emulation: Theoretical approach and mitigation strategy Accept by International Journal of Electrical Power & Energy Systems (Int. J. Electr. Power Energy Syst.) 2023 Paper
OBLIVION: Poisoning Federated Learning by Inducing Catastrophic Forgetting Accept by IEEE International Conference on Computer Communications (INFOCOM) 2023 Paper
FenceSitter: Black-box, Content-Agnostic, and Synchronization-Free Enrollment-Phase Attacks on Speaker Recognition Systems Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2022 Paper
WIGHT: Wired Ghost Touch Attack on Capacitive Touchscreens Accept by IEEE Symposium on Security and Privacy (SP) 2022 Code Paper
"OK, Siri" or "Hey, Google": Evaluating Voiceprint Distinctiveness via Content-based PROLE Score Accept by USENIX Security Symposium (USENIX Security) 2022 Code Paper
GhostTouch: Targeted Attacks on Touchscreens without Physical Touch Accept by USENIX Security Symposium (USENIX Security) 2022 Code Paper
Rolling Colors: Adversarial Laser Exploits against Traffic Light Recognition Accept by USENIX Security Symposium (USENIX Security) 2022 Arxiv Paper
FakeWake: Understanding and Mitigating Fake Wake-up Words of Voice Assistants Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2021 Arxiv Paper
mID: Tracing Screen Photos via Moiré Patterns Accept by USENIX Security Symposium (USENIX Security) 2021 Code Paper
Poltergeist: Acoustic Manipulation of Image Stabilization towards Object Mis-Labeling Accept by IEEE Symposium on Security and Privacy (SP) 2021 Code Paper
EarArray: Defending against DolphinAttack via Acoustic Attenuation Accept by Network and Distributed System Security Symposium (NDSS) 2021 Code Paper
CapSpeaker: Injecting Voices to Microphones via Capacitors Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2021 Code Paper
No Seeing is Also Believing: Electromagnetic-emission-based Application Guessing Attacks via Smartphones Accept by IEEE Transactions on Mobile Computing (TMC) 2021 Paper
OutletSpy: cross-outlet application inference via power factor correction signal Accept by ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2021 Paper
SMS Goes Nuclear: Fortifying SMS-Based MFA in Online Account Ecosystem Accept by IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W) 2021 Paper
SenCS: Enabling Real-time Indoor Proximity Verification via Contextual Similarity Authors Accept by ACM Transactions on Sensor Networks (ToSN) 2021 Paper
MagView: A Distributed Magnetic Covert Channel via Video Encoding and Decoding Accept by IEEE International Conference on Computer Communications (INFOCOM) 2020 Paper
SoK: A Minimalist Approach to Formalizing Analog Sensor Security Accept by IEEE Symposium on Security and Privacy (SP) 2020 Paper
Authenticating Smart Home Devices via Home Limited Channels Accept by ACM Transactions on Internet of Things (TIOT) 2020 Paper
Identifying child users via touchscreen interactions Accept by ACM Transactions on Sensor Networks (TOSN) 2020 Paper
OPCIO: Optimizing Power Consumption for Embedded Devices via GPIO Configuration Accept by ACM Transactions on Sensor Networks (TOSN) 2020 Paper
DeMiCPU: Device Fingerprinting with Magnetic Signals Radiated by CPU Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2019 Code Paper
NAuth: Secure Face-to-Face Device Authentication via Nonlinearity Accept by IEEE International Conference on Computer Communications (INFOCOM) 2019 Paper
The Catcher in the Field: A Fieldprint based Spoofing Detection for Text-Independent Speaker Verification Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2019 Code Paper
On Cuba, Diplomats, Ultrasound, and Intermodulation Distortion Accept by Computers in Biology and Medicine (Comput. Biol. Med.) 2019 Paper
The Feasibility of Injecting Inaudible Voice Commands to Voice Assistants Accept by IEEE Transactions on Dependable and Secure Computing (TDSC) 2019 Paper
HlcAuth: Key-free and Secure Communications via Home-Limited Channel Accept by ACM Asia Conference on Computer and Communications Security (AsiaCCS) 2018 Homepage Paper
FBSleuth: Fake Base Station Forensics via Radio Frequency Fingerprinting Accept by ACM Asia Conference on Computer and Communications Security (AsiaCCS) 2018 Homepage Paper
DeWiCam: Detecting Hidden Wireless Cameras via Smartphones Accept by ACM Asia Conference on Computer and Communications Security (AsiaCCS) 2018 Homepage Paper
On Cuba, Diplomats, Ultrasound, and Intermodulation Distortion Accept by Technical Report (TR) 2018 Paper
HomeSpy: Inferring User Presence via Encrypted Traffic of Home Surveillance Camera Accept by ICPADS Workshop on Wireless Sensing Technology (WST) 2017 Paper
DolphinAttack: Inaudible Voice Commands Accept by ACM SIGSAC Conference on Computer and Communications Security (CCS) 2017 Code Homepage Paper
SADO: State-Associated and Delay-Oriented Data Collection for Intertidal WSNs Accept by International Conference on Wireless Communications and Signal Processing (WCSP) 2017 Paper
A Robust Backup Routing Protocol for Neighbor Area Network in the Smart Grid Accept by International Conference on Wireless Communications and Signal Processing (WCSP) 2017 Paper
NIPAD: a non-invasive power-based anomaly detection scheme for programmable logic controllers Accept by Frontiers of Information Technology & Electronic Engineering (FITEE) 2017 Paper
Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicles Accept by DEF CON Hacking Conference (DEF CON 24) 2016 Paper
Research of anti-eavesdropping technology based on electromagnetic interference against analog sensors Accept by Electronic Technology (ET) 2016 Homepage Paper
On Modeling of Electrical Cyber Physical Systems Considering Cyber Security Accept by Frontiers of Information Technology & Electronic Engineering (FITEE) 2016 Paper
A New Framework of Electrical Cyber Physical Systems Accept by IEEE Conference on Industrial Electronics and Applications (ICIEA) 2016 Paper
Assessing Electric Cyber-Physical System using Integrated Co-simulation Platform Accept by Chinese Control Conference (CCC) 2016 Paper
On identifying vulnerable nodes for power system in the presence of undetectable cyber attacks Accept by IEEE Conference on Industrial Electronics and Applications (ICIEA) 2016 Paper
Ghost Talk: Mitigating EMI Signal Injection Attacks against Analog Sensors Accept by IEEE Symposium on Security and Privacy (SP) 2013 Homepage Paper
Taco: Temperature-aware compensation for time synchronization in wireless sensor networks Accept by IEEE International Conference on Mobile Ad Hoc and Sensor Systems (MASS) 2013 Paper
Security and privacy vulnerabilities of in-car wireless networks: A tire pressure monitoring system case study Accept by USENIX Security Symposium (USENIX Security) 2010 Paper