Person re-identification (ReID) has recently achieved remarkable progress, driving its widespread deployment in real-world applications. This, in turn, raises growing concerns about its vulnerability to adversarial attacks, particularly in black-box settings. Existing methods often rely on gradient-based optimization to improve the generalization of adversarial perturbations, but their effectiveness is constrained by the limited diversity of surrogate models. In this work, we propose LoRA-Attack, a novel adversarial attack framework that enhances the structural and parametric dynamics of surrogate models. Specifically, LoRA-Attack integrates Low-Rank Adaptation (LoRA)-based fine-tuning with the generation of universal adversarial perturbations. By embedding LoRA layers into surrogate models, our method enlarges the effective space and implicitly simulates diverse feature-space scenarios, thereby improving cross-model generalization and boosting black-box transferability. Furthermore, we introduce a Lipschitz-based gradient regularization to stabilize optimization, smoothing gradient fluctuations and enforcing perturbation consistency. Extensive experiments show that LoRA-Attack significantly outperforms most of state-of-the-art methods, achieving superior transferability for ReID.
With the explosive increase in wireless devices, enabling sensing between incompatible radios has become critically beneficial. Integrating diverse IoT devices enhances sensing accuracy by providing richer data, while utilizing the diverse characteristics of heterogeneous signals meets sensing needs in complex environments. However, most existing wireless sensing methods primarily focus on homogeneous signals, while research on sensing with heterogeneous signals is still in its infancy. In this paper, we propose CrossSense, a novel Cross-Technology Sensing (CTS) framework that enables sensing between incompatible WiFi and LoRa device. CrossSense recovers the fine-grained trajectory of a WiFi transmitter based on its emulated LoRa signals. To decompose the motion feature components of WiFi transmitter, we develop a chirp difference vector model that utilizes the energy peak within each chirp window for sensing. We model the relationship between sampling frequency offsets and oscillation frequency offsets among heterogeneous devices to guide the extraction of motion features from the emulated signal. We also propose a greedy-based peak enhancement method to calculate the optimized LoRa phases, minimizing the impact of phase discontinuity caused by cyclic prefix (CP) errors. We implement a prototype of CrossSense on the USRP platform. The extensive experiments demonstrate that CrossSense can achieve an efficient Cross-Technology Sensing with $2.92cm$ distance accuracy and $0.26cm/s$ speed accuracy over a $120m$ sensing range.
In LoRaWAN, users are allowed to customize the center frequency of channel. This mechanism provides more flexibility but also introduces non-negligible interference for packet reception. This paper focuses on Overlapping Channel Interference (OCI), which arises when multiple users simultaneously transmit on partially overlapping channels. Existing methods proposed for interference in a single channel concurrently demodulate collided packets by inferring the chirp’s onset and offset times. However, the collided chirps in OCI exhibit different center frequencies, leading to unpredictable chirp’s onset and offset times which makes OCI particularly challenging to resolve. To resolve it, we propose Hole, a novel method to reliably receive target packet by exploiting the difference in chirp’s onset and offset times instead of inferring them. Hole adopts signal elimination to construct identifiable energy losses for different chirps. Since the onset and offset times of target chirp are stable, its energy loss is deterministic while that of the interfering chirp is random. By comparing energy loss, we identify target chirp under OCI. However, in practice, the channel noise reduces the stability of energy loss. Therefore, we first theoretically analyze the optimal position of signal elimination and then propose noiseaware elimination setting. Furthermore, we also propose target packet recognition method by leveraging difference in packet’s center frequency offset. The experiments in real LoRa network present that Hole improves the Packet Reception Rate (PRR) by up to $7.5 \times$ compared with existing methods.
Deploying Tiny Deep Learning (TinyDL) on Internet of Things (IoT) devices is gaining popularity. To accommodate the limited memory, recent methods split tensors into fine-grained parts and plan memory offline to minimize its footprint. However, they fail to adapt to dynamic memory, missing the opportunity to utilize temporarily available memory for faster inference. Additionally, existing approaches focus solely on minimizing memory size while neglecting cache usage characteristics, resulting in frequent cache misses and increased latency. In this paper, we propose RAMS, an efficient framework supporting runtime adaptive memory scaling to fully utilize the dynamic memory. We design a size-controllable tensor generation method, thereby enabling memory scaling at runtime. We also propose a cache-friendly memory management approach that minimizes cache miss times. RAMS includes an offline planner to minimize the memory footprint essential for inference and an online manager to determine memory sizes and generate layouts for size-controllable tensors based on available memory. RAMS significantly reduces inference latency while maintaining a compact memory footprint. Extensive experiments on commercial devices running RTOS and Android systems demonstrate that, compared to the state-of-the-art methods, RAMS can efficiently reduce latency by up to 1.57 & times; and 1.48 & times; compared to TFLM and TinyTS, respectively using a comparable memory footprint, while reducing power consumption by 67.74% and 15.97%.
Wi-Fi computational imaging has emerged as a promising paradigm for non-intrusive sensing; however, its practical deployment is severely hindered by dense physical multipath clutter, hardware phase quantization errors, and the limited bandwidth of commercial Wi-Fi. Traditional beamforming-based algorithms often completely lose target focus in complex environments, resulting in severe ghosting artifacts. To overcome these fundamental limitations, we propose RISimg, a novel robust Wi-Fi imaging framework empowered by the spatiotemporal coding of Reconfigurable Intelligent Surface. We design a differential coding strategy to guarantee a well-conditioned and noise-robust sensing matrix, and propose a multi-frequency sparse reconstruction algorithm based on the Least Absolute Shrinkage and Selection Operator. By constructing a large-scale overdetermined system, this physics-driven approach effectively suppresses multipath interference and hardware errors, successfully recovering the basic morphological outlines of complex targets. To further enhance the imaging performance, we propose leveraging a Conditional Diffusion Model to refine the imaging results. By utilizing the reconstruction as a structural prior, a carefully designed Conditional U-Net progressively refines the image through a generative reverse sampling process, restoring high-fidelity continuous boundaries. Extensive evaluations using a hardware prototype built with commercial Wi-Fi devices and a low-cost metasurface demonstrate that the final cascaded CDM achieves an unprecedented Structural Similarity Index Measure of 0.9192 and a Spatial Correlation Coefficient of 0.7336, paving a robust new avenue for Wi-Fi imaging.
Unmanned Aerial Vehicle (UAV) equipped with a gateway shows great potential for data collection in many scenarios, especially for the areas lacking of public network infrastructures. However, our in-field experiments on UAV-assisted LoRa networks show that a large throughput gap exists between the ground-to-air and ground-to-ground transmissions. We find that the misalignment of the radiation direction of transceiver antennas with height difference leads to additional signal strength loss, which is ignored by existing ground-to-ground transmissions. In this paper, we propose a directivity-aware ground-to-air link model called annulus model to quantify the impact of directivity on the ground-to-air link quality. Based on our model, a new ground-to-air channel access scheme for UAV-assisted LoRa networks, PreLoRa, is proposed. By predicting the link quality variations, PreLoRa schedules the transmission periods and adopts optimal transmission configurations for ground nodes to improve the link throughput. We implement PreLoRa on commercial LoRa platforms and extensively evaluate its performance in the wild. Experimental results show that PreLoRa can significantly improve data collection throughput by up to 65.5% compared to baseline methods.
LoRa is widely deployed for various applications. Though the knowledge of the channel occupancy is the prerequisite of all aspects of network management, acquiring the channel occupancy for LoRa is challenging due to the large number of channels to be detected. In this paper, we propose LoRadar, a novel LoRa channel occupancy acquirer based on cross-channel scanning. Our in-depth study finds that Channel Activity Detection (CAD) in a narrow band can indicate the channel activities of wide bands because they have the same slope in the time-frequency domain. Based on our finding, we design the cross-channel scanning mechanism that infers the channel occupancy states of all the overlapping channels by the distribution of CAD results. We elaborately select and adjust the CAD settings to enhance the distribution features. We also design the pattern correction method to cope with distribution distortions. We implement LoRadar on commodity LoRa platforms and evaluate its performance on the indoor testbed and the outdoor deployed network. The experimental results show that LoRadar can achieve a detection accuracy of 0.99 and reduce the acquisition overhead by up to 0.90, compared to existing traversal-based methods.
This paper focuses on cross-channel interference caused by collided chirps with different bandwidths but same slope in time-frequency domain. Existing concurrency decoding methods cannot resolve it because they require the accurate time duration of all chirps. But in limited receiving bandwidth, interfering chirps with asymmetric bandwidths are incomplete. Their time duration is unpredictable due to the randomly modulated symbols. We instead propose Elora to decode target packets under cross-channel interference. Elora leverages the difference in chirps' time duration instead of absolute time duration to identify target chirp because only target chirp fills the decoding window in time and frequency. Elora adopts chirp elimination to test whether each received chirp can be completely eliminated after subtracting the reference chirp that fully occupies the decoding window because only the target chirp is completely eliminated while interfering chirps remain unaffected. However, in practice, unexpected frequency shift and phase rotation prevent the target chirp from being completely eliminated. We propose a linear-fitting method to correct frequency shift and then compensate phase rotation by an energy varying model. We also adopt window dividing to estimate energy intensity of chirp's residue. The experiments show that Elora reduces the symbol error rate by up to 86.3% compared with existing methods.
Accurate prediction of LoRa link quality is crucial for optimizing network performance in mobile LoRaWAN. However, this task remains challenging in mobile scenarios due to the highly dynamic and volatile nature of wireless links. Existing approaches typically oversimplify link volatility, treating it as smooth trends or random noise and thereby overlooking its predictive value. In this work, we show that link volatility itself can serve as a core predictive signal and propose DLQP, a dual-branch neural network that decouples link dynamics into long-term trends and short-term volatility. Leveraging historical link quality measurements, the trend branch captures longterm temporal patterns from raw sequences, while the volatility branch models packet reception state (PRS) transitions using volatility-driven statistics. A conditional fusion mechanism then adaptively integrates these features based on the latest link state. Extensive evaluations on a real-world urban LoRaWAN dataset show that DLQP outperforms the current representative method by $33.0 \%$ and an LSTM baseline by $10.3 \%$ in AUC-ROC for link connectivity classification, while also improving accuracy in the critical downlink gateway selection task by over $\mathbf{1 0 \%}$.
Cross-Technology Communication (CTC) is an emerging technique that enables direct interconnection among incompatible wireless technologies. However, for the downlink from WiFi to multiple IoT technologies, serially emulating and transmitting the data of each IoT technology has extremely low spectrum efficiency. In this paper, we propose WiCast, a parallel CTC that uses IEEE 802.11ax to emulate a composite signal that can be received by commodity BLE, ZigBee, and LoRa devices. By taking advantage of OFDMA in 802.11ax, WiCast uses a single Resource Unit (RU) for parallel CTC and sets other RUs free for high-rate WiFi users. But such a sophisticated composite signal is very easily distorted by emulation imperfections, dynamic channel noises, cyclic prefix, and center frequency offset. We propose a CTC link model that jointly models the emulation errors and channel distortions. Then we carve the emulated signal with elaborate compensations in both time and frequency domains. Based on the proposed CTC scheme, a unified Media Access Control approach is introduced to discover and synchronize the heterogeneous IoT devices. We implement a prototype of WiCast using USRP N210 platform along with commodity ZigBee, BLE, and LoRa devices. The extensive experiments demonstrate WiCast can achieve an efficient parallel transmission with the aggregated goodput up to 390.24kbps.
Deep Neural Networks (DNNs) play a crucial role in the smart Internet of Things (IoT), with widespread applications in inference tasks like interactive games, intelligent driving, and augmented reality. Along with these promising applications, various task-offloading methods were proposed to improve the utilization of system resources, given that DNN model inference typically requires substantial computational power. However, existing offloading methods focus primarily on a specific model, and research addressing heterogeneous DNN models (with different structures and layers) remains limited in practical IoT environments. Directly integrating these methods would require frequent re-initialization to adapt to changes in the search space during the offloading of mixed heterogeneous DNN inference tasks, resulting in insufficient flexibility and the waste of computational resources. Thus, we propose AutoCut, a global heterogeneous model offloading service based on a customized multi-objective differential evolution algorithm, to find low-latency and energyefficient offloading partitions. AutoCut utilizes a group-layer granularity partitioning that avoids frequent changes in the search space when continuously offloading heterogeneous DNN inference tasks, thereby improving search efficiency. Experiments with six popular models show that AutoCut significantly improves inference performance regarding latency and energy efficiency.
The rapid development of low Earth orbit (LEO) satellite constellations is reshaping global communication infrastructure, but also presents frequent and complex challenges for distributed handover management. Existing handover schemes typically rely on global network state “snapshots” for resource allocation. However, in highly dynamic LEO networks, such snapshot-based mechanisms often lead to concurrent conflicts, high handover failure rates, and excessive retries, especially under heavy load or increased latency. To address these challenges, this paper proposes the Conflict-Free Bid-Offer based Two-Phase Commit Protocol (CBO-2PC), which implements a pessimistic and orderly resource negotiation mechanism to eliminate information asymmetry and critical concurrency conflicts in distributed resource competition. Simulation results demonstrate that, compared with conventional snapshot-based handover schemes, CBO-2PC achieves markedly lower average handover failure rates and exhibits greater robustness to information latency, thereby effectively mitigating performance degradation caused by outdated information and concurrent conflicts. These results indicate that CBO-2PC provides a robust, efficient and reliable handover solution for large-scale LEO satellite networks.
As an application of fine-grained wireless sensing, RF-based material identification follows the paradigm of RF computing that fetches the information during RF signal propagation. Specifically, the RF signal accesses the objects’ material-related information and carries the information with its electromagnetic properties. With a variety of important applications, research on RF-based material identification has gained significant progress in recent years. However, several fundamental problems remain insufficiently studied, such as the sensing models, signal processing approaches, performance and future extensions. This paper presents the first comprehensive survey of RF-based material identification. According to the basic sensing model used for sensing, we propose a taxonomy to classify the existing works into two categories: reflection-based and penetration-based. The works in each category are further grouped by the type of RF signals used, with elaborated discussion of the detailed approaches and the common challenges. We provide a framework that benchmarks the performance of the existing works, followed by a thorough discussion of future extensions.
Subsea Internet of Things (IoT) networks have rapidly developed but still suffer the inefficient underwater-to-air communication. Due to wireless signals exhibiting different properties in different media, it is difficult to use any single modality of signal for cross-medium communication. In this paper, we propose Exocoetus, a novel passive relay based water-to-air communication system. By taking advantage of the out-of-specification characteristics of the RF switch, Exocoetus can trigger acoustic-to-RF conversion even if the input voltage is below the standard threshold and use a clamp circuit to further maximize the efficiency of the acoustic-to-RF signal conversion. We design a dual-capacitor circuit-based pulse position modulation method to amplify the acoustic signals emitted by power-constrained underwater nodes, ensuring reliable communication over greater distances. We implement a prototype of Exocoetus and evaluate its performance in the real environment. The results show that Exocoetus can achieve a communication distance of 6 meters above water and 1.25 meters underwater.
In industry,various machinery involves spinning components,and monitoring their rotation speed is important for predicting the operation state.There are many approaches for rotation speed estimation,each with its own limitations,e.g.,traditional contact methods,requiring specialized equipment,non-contact methods,such as op-tical methods affected by illumination and occlusion,and acoustic methods,susceptible to environmental noise.Radio frequency signals like wireless fidelity(WiFi)can provide non-intrusive approach for rotation sensing.However,con-ventional WiFi sensing struggles to capture self-spinning objects when there is no radial motion towards or away from the WiFi transceivers.This paper proposes a rotation speed estimation method based on vortex electromagnetic(EM)waves.By using a q-shaped patch antenna on commodity WiFi,vortex EM waves with spiral phase front can be transmitted in WiFi communication channel.When these vortex EM waves interact with the surface of a self-spinning object,the echos exhibit a frequency shift compared to the original wave.This frequency shift is proportional to the object's rotation speed,and is known as the rotational Doppler effect.This paper first derives the mathematical rela-tionship between WiFi channel state information(CSI)and rotational Doppler frequency shift(RDS),and we design a series of signal processing methods to extract RDS from WiFi CSI,achieving the rotation speed estimation of self-spinning targets.Experimental results show that this method is applicable to a rotation speed range of 0-7000 rpm,with an relative error within 5%.
Current WiFi imaging approaches focus on monitoring dynamic targets to facilitate easy object distinction and capture rich signal reflections for image construction. In static object imaging, massive antenna array or emulated antenna array is often necessary. We propose WiCamera, a novel WiFi imaging prototype that utilizes vortex electromagnetic waves (VEMWs) to monitor stationary human postures using commodity WiFi, by generating human silhouettes with only 3 x 3 MIMO. VEMWs possess a helical wavefront with different phase variations, enabling the imaging of stationary objects through different OAM (Orbital Angular Momentum) modes with time-division multiplexing. WiCamera emits three OAM modes waves from WiFi devices and utilizes their phase variations for imaging. By ray tracing the received signals to a target image plane, WiCamera generates a wavefront image. A generative adversarial network (GAN)-based model is further utilized to refine the wavefront image and create a high-resolution human silhouette. The system's output images are evaluated using metrics such as structural similarity index measure (SSIM) and Szymkiewicz-Simpson coefficient (SSC), comparing them to ground truth images captured by cameras. The evaluation shows that WiCamera performs consistently well in various environments and with different users, with an SSIM reaching up to 0.89 and an SSC reaching up to 0.93.
The Bluetooth 5.1 specification introduces the Angle of Arrival feature, which significantly enhances its applications in indoor positioning. Given the height of the target, a single BLE (Bluetooth Low Energy) base station can locate the target, thereby reducing deployment costs. However, existing methods often assume that the target's height is known in advance and remains constant, which is not always true in practice. The height can vary significantly due to user posture changes, such as when picking up a phone from a pocket, leading to positioning errors. In this paper, we propose BleHe, a novel indoor positioning system that incorporates height correction to enhance positioning accuracy in scenarios with dynamic height changes. BleHe detects height changes by utilizing on-device IMU sensor and subsequently notifies the base station of any detected height change events. To avoid altering the commodity Bluetooth protocols, rather than directly modifying application data, we create a side channel to delivery the height change information from the device to the base station by adjusting the BLE packet transmission frequency. This method allows the base station to infer the start and end times of height changes and subsequently refine the target's trajectory using a height-aware particle filtering-based positioning correction method that we propose. Experimental results demonstrate that BleHe achieves an average positioning error of 34.4cm, even in scenarios involving posture changes during walking.
De-authentication attack is one of the major threats to Unmanned Aerial Vehicle (UAV) communication, in which the attacker continuously sends de-authentication frames to disconnect the UAV communication link. Existing defense methods are based on authentication by digital passwords or physical channel features. But they suffer from replay attacks or cannot adapt to the UAV mobility. In this paper, instead of enhancing the in-channel authentication, we leverage the ambient broadcasting signal to establish a low-cost additional channel for authentication. Different from methods using another dedicated secure communication channel to perform an independent authentication, we use the ambient FM radio broadcasting channel and couple the two channels by encoding parasitic bits on the host signals of the broadcasting channel, which is called parasitic coding. To further enhance the security, we propose the FM-based Parasitic Coding Authentication (FPCA) that leverages elaborate host signal processing and vector coding to ensure that the attacker cannot decode our authentication even knowing the FM receiving frequency. We implement FPCA on the embedded UAV platform. The extensive experiments show that FPCA can resist replay attacks and brute force searching, achieving reliable continuous authentication for UAVs.