Abstract Statistical heterogeneity in federated learning (FL) often causes client drift, leading to unstable convergence and degraded generalization under non-independent and identically distributed data. Existing personalized FL (PFL) methods typically mitigate heterogeneity at a single stage of the FL pipeline (e.g., initialization, local optimization, or server aggregation), which may yield limited or inconsistent gains when drift accumulates across rounds. In this paper, we propose federated learning with adaptive local aggregation and global tuning (FedAGT), a stage-consistent PFL framework that formulates personalization as a cross-stage coordination problem across client initialization, local optimization, and server aggregation, rather than as an isolated stage-specific intervention. Specifically, FedAGT performs adaptive local aggregation to construct client-specific initial models, introduces a lightweight model-level contrastive regularization to stabilize local updates against drift across communication rounds, and adopts a discrepancy-aware aggregation strategy that jointly accounts for data volume and model alignment to promote globally consistent updates. Extensive experiments on benchmark datasets (MNIST, Cifar10/100, and Tiny-ImageNet) and a real-world medical imaging dataset (COVIDx CXR-4) demonstrate that FedAGT empirically improves convergence stability and achieves consistently competitive accuracy across diverse heterogeneity levels and training settings.
Millimeter-wave (mmWave) technology has enabled emerging applications such as vital-sign-based healthcare monitoring, user authentication, and emotion-aware human-computer interaction. By capturing subtle chest displacements induced by heartbeat and respiration, mmWave systems provide high-resolution, contactless chest-vibration sensing. However, the mmWave signals that power these applications are vulnerable to spoofing attacks, posing serious risks such as identity impersonation and falsified health assessments. While prior studies have demonstrated the feasibility of spoofing mmWave sensing, existing methods often require access to raw mmWave data or rely on expensive, specialized RF equipment, limiting their real-world applicability. In this work, we present a real-time, low-cost spoofing attack using a programmable actuator concealed under clothing to physically mimic a target user’s chest vibrations. Our attack allows adversaries to bypass authentication systems or falsify health data, potentially granting unauthorized access, or concealing critical medical conditions and triggering false emergency responses. To ensure high-fidelity spoofing, we introduce a mitigation strategy that integrates IMU-assisted compensation and quaternion-based alignment to mitigate interference from the attacker’s own chest motion. We further employ deep learning to dynamically adjust actuator behavior in real time. Experiments with eight participants over six months validate the attack’s effectiveness, revealing a critical security vulnerability in emerging mmWave-based sensing systems.
The rise of wearables such as fitness trackers and smartwatches has increased the need for strong security to protect personal data. Although two-factor authentication methods improve security, they often require additional user input, making them inconvenient. Recently, hardware flaws in accelerometers and WiFi interfaces have been leveraged to create low-effort two-factor authentication methods. However, these hardware-based device credentials are static, necessitating device replacement if the credentials are compromised. In this study, we introduce an innovative device authentication system that identifies wearables using vibration-based credentials. By utilizing built-in vibration motors and motion sensors (i.e., accelerometers and gyroscopes), our system establishes a unique communication channel to capture the distinct characteristics of each device. Unlike existing methods, our vibration-based credentials are reprogrammable and user-friendly. We develop advanced data processing techniques to minimize the impact of noise, body motion artifacts, and wearing position. We design a lightweight convolutional neural network for feature extraction and device authentication, with a majority vote mechanism to improve identification robustness. Extensive experiments with five different smartwatches demonstrate that our system achieves an average precision of 98% and a recall of 94% under various attacks, demonstrating that including gyroscope data significantly improves performance across different wearing poses and watch orientations.
With the widespread proliferation of mobile devices, touchless interaction has become increasingly desirable in both indoor and outdoor environments. WiFi signals provide a compelling medium for such interaction, as hand gestures naturally perturb channel state information (CSI) without requiring specialized hardware. Beamforming feedback information (BFI), a compressed representation of CSI accessible on IEEE 802.11ac/ax devices without firmware modification, remains largely unexplored for gesture recognition on mobile platforms such as smartphones. However, deploying BFI-based recognition on mobile platforms presents two challenges: 1) the inherently low sampling rate of the standard constrains temporal resolution; 2) the inevitable body motion inherent to mobile usage introduces non-trivial signal interference. In this paper, we present a motion-resilient hand gesture recognition system leveraging smartphones-transmitted BFI. To address signal discontinuity caused by practical MIMO mode switching between multiuser and single-user, we develop an automatic mode switching detection mechanism to identify switching events and a BFI adjustment scheme to preserve signal consistency across modes. To mitigate motion artifacts induced by body motion, we design two complementary feature extractors to learn gesture-invariant and gesture-interference representations, optimized with distinct loss functions. These two representations are then fused via a multi-head cross-fusion architecture to suppress the body motioninduced signal noise. Additionally, a parameter-efficient few-shot transfer learning strategy is proposed to adapt the pretrained model to unseen domains with minimal effort. Experiments conducted over six months across various factors demonstrate that our system achieves robust and accurate gesture recognition up to 89% under three motion statuses (i.e., standing, shaking, walking), demonstrating that BeamGes pushes the boundary of practical WiFi sensing on commercial smartphones.
Blood pressure (BP) is one of the most essential biomarkers for various diseases. It is considered protected health information under HIPAA and usually needs the user's consent for access. In this work, we uncover an insidious privacy breach in metaverse usage: private BP information can be covertly obtained from unrestricted motion sensors in virtual reality (VR) headsets. The insight is that the motion sensors can capture the subtle vibrations induced by the blood waves in the major arteries. Such vibrations are highly correlated with users' cardiac cycles and BP. As adversaries can continuously obtain motion sensor data from VR headsets without users' consent, they can derive and collect users' BP information in metaverse apps or websites, leading to more severe consequences, such as discrimination, exploitation, and targeted harassment. To demonstrate this severe privacy leakage in the metaverse, we develop a practical attack, BPSniff, which can reconstruct fine-grained blood flow patterns and derive BP based on motion sensor data from users' VR headsets. BP-Sniff is the first practical attack revealing the BP leakage in the metaverse without using dedicated equipment. Unlike previous mobile sensing approaches that require user-specific calibration, BPSniff bypasses this constraint, enabling truly stealthy passive BP attacks at scale. Our attack first employs a variational autoencoder to reconstruct high-fidelity blood flow patterns from VR headset motion sensor data. We then develop an Adam-optimized long short-term memory (LSTM) regression model that leverages BP-related fiducial features from successive blood flow patterns to continuously estimate the user's BP. We evaluate BPSniff through extensive experiments and a longitudinal study of 8 weeks, involving 37 participants and two VR headset models. The results show that BPSniff can achieve low mean errors of 1.75 mmHg for systolic blood pressure (SBP) and 1.34 mmHg for diastolic blood pressure (DBP), which are comparable to commercial BP monitors and satisfy the standard (i.e., mean error <= 5.0 mmHg) specified by FDA's AAMI protocol.
Cannabis use has become increasingly prevalent due to evolving legal and societal attitudes, raising concerns about its influence on public safety, particularly in driving. Existing studies mostly rely on simulators or specialized equipment, which do not capture the complexities of real-world driving and pose cost and scalability issues. In this paper, we investigate the effects of cannabis on driving behavior using participants’ smartphones to gather data in natural settings. Our method focuses on three critical behaviors: weaving & swerving, wide turning, and hard braking. We propose a two-step segmentation algorithm for processing continuous motion sensor data and use threshold-based methods for efficient detection. A custom application autonomously records driving events during actual road scenarios. On-road experiments with 9 participants who consumed cannabis under controlled conditions reveal a correlation between cannabis use and altered driving behaviors, with significant effects emerging approximately 2∼3 h after consumption.
Extended Reality (XR) headsets are increasingly serving as repositories for substantial volumes of sensitive data and gateways to web applications. This transition highlights the need for convenient and secure user authentication solutions. Traditional password/PIN-based schemes are ill-suited to the XR's gesture- and voice-based interfaces and are prone to shoulder-surfing attacks. Some recent XR systems incorporate two-factor authentication, but it requires additional operations on a second device (e.g., a smartphone or wearable). In this work, we introduce the first effortless and inbuilt XR user authentication system by leveraging the harmonics of vibrations excited by users' vital signs. The system is transparent to users (no efforts during enrollment and authentication) and requires no additional hardware. The key idea is that vital signs (i.e., breathing and heart beating) naturally generate low-frequency mechanical vibrations, causing human skull to vibrate and produces harmonic signals. When the harmonics pass the human head, they carry rich biometrics associated with the wearer's skull structure and soft tissues, which can be captured by the XR motion sensors. Instead of directly utilizing the vibrations, we extract more reliable biometrics from the ratios among different harmonic frequencies, which capture wearers' unique head and facial attenuation properties and are non-volatile when the periodicity and amplitude of vital signs fluctuate. We further design an adaptive filter to mitigate the body motion distortions in common XR interactions. By adopting advanced deep learning models with the attention mechanism, our system realizes effective and robust authentication across XR scenarios. Evaluations across 10 months, with 52 users and two popular XR headsets, show that our system can accurately authenticate users with over 95% true positive rates and rejects unauthorized users with over 98% true negative rates under various XR scenarios, with biometrics remaining consistent over long-term periods.
Launching effective black-box adversarial attack against a deep neural network (DNN) without knowledge of the model's details is challenging. Previous studies involved performing numerous queries on the target model to generate adversarial examples, which is unacceptable due to the high query volume. Additionally, many of these queries are unnecessary as the dataset may contain redundant or duplicate data. To address these issues, we propose a two-stage black-box adversarial attack approach that combines side-channel attacks and a data reduction technique. In the first stage, we employ Long Short Term Memory (LSTM) to gather partial information about the target DNN through side-channel attacks, enabling us to obtain the class probability of the dataset. In the second stage, we utilize a new data reduction algorithm based on the class probability to enhance the efficiency of generating adversarial examples. Our approach is capable of precisely identifying the target model and the data reduction performs better than other reduction methods. Furthermore, when utilizing the reduced datasets to train the shadow model, the adversarial examples generated on this shadow model demonstrate a higher transferability success rate than SOTA data reduction methods.
This article comprehensively studies the often-overlooked privacy risks associated with sensor-rich extended reality headsets. We demonstrate how motion sensors, typically accessed without user permission, can capture subtle facial vibrations, potentially leaking sensitive data such as speech, identity, and physiological information.
Deep learning (DL) has recently become a key technology supporting radio frequency (RF) signal classification applications. Given the heavy DL training requirement, adopting outsourced training is a practical option for RF application developers. However, the outsourcing process exposes a security vulnerability that enables a backdoor attack. While backdoor attacks have been explored in the vision domain, it is rarely explored in the RF domain. In this work, we present a stealthy backdoor attack that targets DL-based RF signal classification. To realize such an attack, we extensively explore the characteristics of the RF data in different applications, which include RF modulation classification and RF fingerprint-based device identification. Then, we design a training-based backdoor trigger generation approach with different optimization procedures for two backdoor attack scenarios (i.e., poison-label and clean-label). Extensive experiments on two RF signal classification datasets show that the attack success rate is over 99.2%, while its classification accuracy for the clean data remains high (i.e., less than a 0.6% drop compared to the clean model). The low NMSE (less than 0.091) indicates the stealthiness of the attack. Additionally, we demonstrate that our attack can bypass existing defense strategies, such as Neural Cleanse and STRIP.
The physical layer secret key generation exploiting wireless channel reciprocity has demonstrated its viability and effectiveness in various wireless scenarios, such as the Internet of Things (IoT) network, mobile communication network, and industrial control system. Most of the existing studies rely on the quantization technique to convert channel measurements into secret bits for confidential communications. However, non-simultaneous packet exchanges in time-division duplex systems and noise effects usually induce inconsistent quantization results and mismatched secret bits. Although recent research has spent significant effort mitigating such non-reciprocity, it is still far from practical error-free key generation. Unlike previous quantization-based approaches, we take a different viewpoint to match the randomly manipulated (i.e., permuted or edited) channel measurements between a pair of users by minimizing their discrepancy holistically. Specifically, two novel secret key generation algorithms based on bipartite graph matching (BMSKG) and edited sequence alignment (SA-SKG) are developed. BM-SKG allows two users to generate the same secret key based on the permutation order of channel measurements, while SASKG aims to align the edited channel measurements between a pair of users for secret key agreement. In both algorithms, one user can preset the secret key and embed encrypted messages in the exchanged data packets, which reduces communication overheads in key generation. Extensive experimental results show that both BM-SKG and SA-SKG algorithms achieve error-free key agreement on channel measurements at a low cost under various scenarios.
Traditional smartphone touchscreens often raise privacy concerns. We thus propose a novel system using low-cost smartphone cases for privacy-preserving finger activity sensing via passive acoustic signals from the back of the smartphone case. It leverages embedded mini-structures to regulate and enhance the acoustic signals gen-erated by finger activities on the case. We develop a multi-task learning framework with a multi-scale shared encoder and task-specific decoders to extract comprehensive acous-tic features of finger activities. During offline training, our system uses raw passive finger activity sound as input and camera supervision. A Siamese network is utilized to extract finger activity-specific feature files, eliminating the need for users to collect training data. Initial experimental evaluations validate the system's superior performance.
Richard P. Martin合作论文数Department of Computer Science, Rutgers University10