About me
Hi there. I am now a Ph.D. candidate from the Department of Computer Science and Engineering of the Ohio State University. My advisor is professor Zhiqiang Lin. I earned my bachelor degree from South China University of Technology in 2018. I am honored to be a member of the SecLab at OSU.
My current research is mobile and cellular network (5G) security, by developing security services (instrusion detection, AI-powered anomaly detection) for the 5G software-defined edge, such as user equipment and the Open Radio Access Network (O-RAN, an emerging software-defined cellular network paradigm). I'm a core contributor and researcher for Project SE-RAN supported by the NSF's 5G convergence accelerator program. Please visit our website: 5gsec.com for the most recent updates!
I spent three summers (2021-2023) as a security research intern at the computer science lab of SRI International, where I worked on 5G security supervised by Vinod Yegneswaran and Phillip Porras.
I am also interested in applying program analysis and reverse engineering to solve interesting security problems. I always love to design principled algorithms to analyze all kinds of application binaries (e.g., mobile apps, firmware binaries from embedded IoT systems and automobiles) and apply them to various security analysis tasks such as vulnerability detection, software debloating, etc.
I actively maintain an open bibliography page for cellular security papers, projects, and resources on Github. Check here for details.
Research Interest
Cellular (5G) security (
[MobiFlow],
[5G-Spector]
)
and Privacy ( [RILDefender] )
Program analysis and its application for:
Mobile security and privacy (contact tracing for COVID-19
[SecureComm1],
[SecureComm2],
[GAEN+]
)
IoT security and privacy (
[BLEScope],
[FirmXRay],
[AutoMap]
)
Vehicle security (
[DongleScope],
[CANHunter],
[QtRE]
)
Publications
5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection Service
[pdf]
[code]
[demo video]
Haohuang Wen, Phillip Porras, Vinod Yegneswaran, Ashish Gehani, and Zhiqiang Lin
To appear in the Network and Distributed System Security Symposium 2024 (NDSS 2024)
San Diego, CA, USA
Thwarting Smartphone SMS Attacks at the Radio Interface Layer
[pdf]
[slides]
[code]
Haohuang Wen, Phillip Porras, Vinod Yegneswaran, and Zhiqiang Lin
In the Network and Distributed System Security Symposium 2023 (NDSS 2023)
San Diego, CA, USA
Egg Hunt in Tesla Infotainment: A First Look at Reverse Engineering of Qt Binaries
[pdf]
[slides]
[code]
Haohuang Wen, and Zhiqiang Lin
In proceedings of the 32nd USENIX Security Symposium (USENIX Security 2023)
Anaheim, CA, USA
A Fine-Grained Telemetry Stream for Security Services in 5G Open Radio Access Networks
[pdf]
Haohuang Wen, Phillip Porras, Vinod Yegneswaran, and Zhiqiang Lin
In Proceedings of the 1st Workshop on Emerging Topics in Wireless (EmergingWireless 2022)
Rome, Italy
What You See is Not What You Get: Revealing Hidden Memory Mapping for Peripheral Modeling
[pdf]
[code]
Jun Yeon Won, Haohuang Wen, and Zhiqiang Lin
In Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2022)
Limassol, Cyprus
Replay (Far) Away: Exploiting and Fixing Google/Apple Exposure Notification Contact Tracing
[pdf]
[code]
Christopher Ellis, Haohuang Wen, Zhiqiang Lin, and Anish Arora
In Proceedings of the 29th Privacy Enhancing Technologies Symposium (PETS 2022)
Sydney, Australia
FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities from Bare-Metal Firmware
[pdf]
[slides]
[code]
Haohuang Wen, Zhiqiang Lin, and Yinqian Zhang
In Proceedings of the 27th ACM Conference on Computer and Communications Security (CCS 2020)
A Study of the Privacy of COVID-19 Contact Tracing Apps
[pdf]
Haohuang Wen, Qingchuan Zhao, Zhiqiang Lin, Dong Xuan, and Ness Shroff
In Proceedings of the International Conference on Security and Privacy in Communication Networks (SecureComm 2020)
On the Accuracy of Measured Proximity of Bluetooth-based Contact Tracing Apps
[pdf]
Qingchuan Zhao, Haohuang Wen, Zhiqiang Lin, Dong Xuan, and Ness Shroff
In Proceedings of the International Conference on Security and Privacy in Communication Networks (SecureComm 2020)
Automated Cross-Platform Reverse Engineering of CAN Bus Commands from Mobile Apps
[pdf]
[slides]
[code]
Haohuang Wen, Qingchuan Zhao, Qi Alfred Chen and Zhiqiang Lin
In Proceedings of the Network and Distributed System Security Symposium (NDSS 2020)
San Diego, CA, USA
Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoT
[pdf]
[slides]
[code]
Haohuang Wen, Qi Alfred Chen and Zhiqiang Lin
In Proceedings of the 29th USENIX Security Symposium (USENIX Security 2020)
Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps
[pdf]
Chaoshun Zuo, Haohuang Wen, Zhiqiang Lin and Yinqian Zhang
In Proceedings of the 35th Annual Computer Security Applications Conference (CCS 2019)
London, UK
An Empirical Study of SDK Credential Misuse in iOS Apps
[pdf]
Haohuang Wen, Juanru Li, Yuanyuan Zhang and Dawu Gu
In Proceedings of 25th Asia-Pacific Software Engineering Conference (APSEC 2018)
Nara, Japan
ParGen: A Parallel Method for Partitioning Data Stream Applications in Mobile Edge Computing
[pdf]
Haohuang Wen, Lei Yang and Zhenyu Wang
IEEE Access 2018
Professional Service
Technical Program Committee:
- The Web Conference: 24
- ACSAC Artifact Evaluation Committee: 19
Reviewer:
- International Conference on Security and Privacy in Communication Networks (SecureComm): 23
- IEEE Security & Privacy Magazine: 22
- IEEE Internet of Things Journal (IOT-J): 23
- IEEE Communications Magazine: 23
External Reviewer: CCS (22, 20), IEEE S&P (24, 22, 21), USENIX Security (22, 21), NDSS (20, 19),
ACSAC (22, 20, 19), DSN (22, 21, 20), ESORICS (22), SecureComm (19), DFRWS (20, 19), AutoSec (21)
Work Experience
Research intern at SRI InternationalMay 2023-Aug 2023
Graduate Teaching Assistant (CSE5474 Software Security) Spring 2023
Research intern at SRI InternationalMay 2022-Aug 2022
Research intern at SRI InternationalMay 2021-July 2021
Graduate Research AssistantAug 2018-Present
Software developer intern at TencentJuly 2017-Sep 2017