Name: 
TSANG Siu Chung Colin
Title ( post ): 
Lecturer
Department: 
Computer Science and Engineering
email: 
colintsang [at] cse.cuhk.edu.hk
phone: 
3943-1283
website: 
https://www.cse.cuhk.edu.hk/people/faculty/colin-s-c-tsang/
Avatar: 
Class: 
faculty_member
glossary_index: 
T
Name: 
SHI Qiu
Title ( post ): 
Research Assistant Professor
Department: 
Computer Science and Engineering
email: 
shiqiu [at] cse.cuhk.edu.hk
phone: 
3943-1285
website: 
https://www.cse.cuhk.edu.hk/people/faculty/shi-qiu/
Avatar: 
Class: 
faculty_member
glossary_index: 
S
Name: 
MA Pui Kit, Jack
Title ( post ): 
Lecturer
Department: 
Information Engineering
email: 
ackma [at] ie.cuhk.edu.hk
phone: 
3943-5113
website: 
https://www.ie.cuhk.edu.hk/faculty/ma-pui-kit-jack/
Avatar: 
Class: 
faculty_member
Chinese Name: 
馬培傑
glossary_index: 
M

European Innovation Academy_2023

Date: 
2023-08-04
Thumbnail: 
Body: 

Five students were sponsored for the entrepreneurship program held in Porto, Portugal during 16 July to 4 August 2023.   University students from around the world were mentored by professors and industrial leaders for three weeks to realize their innovative ideas through real product design and marketing plans. 

 

Filter: Dept: 
ELITE
Name: 
CHAN Pui, Barbara
Title ( post ): 
Professor
Department: 
Biomedical Engineering
email: 
bpchan [at] cuhk.edu.hk
phone: 
3943 0509
website: 
https://www2.sbs.cuhk.edu.hk/en-gb/people/academic-staff/prof-chan-pui-barbara
Avatar: 
Class: 
faculty_member
glossary_index: 
C

CUHK research team reveals vulnerabilities in enterprise networking services and mobile facial recognition systems

Date: 
2023-10-26
Thumbnail: 
Body: 
  • 11 out of 18 mobile facial recognition software development kits have security flaws. 
  • 63 out of 132 VPN front-end apps have serious vulnerabilities.
  • Out of more than 2,000 colleges and universities worldwide, 86% instruct users to adopt unsafe Wi-Fi settings on at least one device platform.
 
The use of facial recognition technology has become prolific, and with the rise of Wi-Fi and virtual private networks (VPNs), their security has become a hot-button topic. Two research teams from The Chinese University of Hong Kong (CUHK)’s Department of Information Engineering have recently revealed security vulnerabilities in mobile facial recognition software and enterprises’ Wi-Fi and VPN setups that have a real-world impact.
 
Bypassing facial identification in mobile apps is easier than previously thought
 
Users’ identity documents and selfies are easily stolen and sold on the black market, allowing them to be used for identity fraud. To prevent this from happening, most facial recognition systems require users to perform actions such as blinking or shaking their heads, known as liveness detection. While many researchers have studied deepfake or 3D mask attacks that target machine learning models, few have addressed the protocol design or implementation issues in facial recognition systems that can enable low-cost, easy-to-scale attacks. 
 
A research team led by Professor Lau Wing-cheong from the Department of Information Engineering analysed 18 mobile facial recognition software development kits (SDKs), including those from industry leaders, and revealed security flaws in 11 of them that can result in liveness detection bypasses. After building an automatic app analyser to scan more than 18,000 apps, CUHK researchers found that around 300 contained at least one of the vulnerable facial recognition libraries. By exploiting design flaws in the SDKs, an attacker can circumvent facial identification using only static photos of the victim.
 
The research team has provided security tips for the design of app facial recognition systems and contacted the software companies about the vulnerabilities. The team recently presented its findings at the Black Hat USA 2023 conference, under the title “The Living Dead: Hacking Mobile Face Recognition SDKs with Non-Deepfake Attacks”. 
 
Safety tips for the design of facial recognition systems:
  • Perform cloud-based liveness detection when possible. Never trust client-side results.
  • Defense in depth: adopt multiple layers of security control; enforce robust client protection, including app hardening and anti-debugging.
  • Properly encrypt configurations and data that are exchanged between library, app and server during the facial recognition process.
 
Insecure enterprise Wi-Fi & VPNs allow attackers to compromise passwords and devices
 
Many employers provide their employees with enterprise Wi-Fi and VPN services, making it easier for them to use mobile devices such as laptop computers and smartphones to work on the go. To better understand their security issues, a research team led by Professor Chau Sze-yiu from the Department of Information Engineering conducted in-depth testing and analysis of enterprise Wi-Fi and VPNs. 
 
With enterprise Wi-Fi, the research team discovered several design and implementation flaws in mainstream operating systems, which force users to adopt insecure wireless network settings, making them susceptible to attacks. The team also analysed more than 7,000 Wi-Fi setup guides from more than 2,000 colleges and universities around the world and found that about 86% instruct users to adopt unsafe Wi-Fi settings on at least one mainstream operating system. Due to these unfortunate oversights from software vendors and IT admins, attackers can steal users’ passwords using low-cost Wi-Fi impersonators. 
 
With VPNs, the research team tested 132 front-end applications used around the globe and found serious yet previously unknown vulnerabilities in 63. These vulnerabilities allow hackers to steal user passwords easily and stealthily. In addition, the front-end applications of some VPN products allow a network attacker to execute arbitrary malicious code with high privileges on the user’s device, compromising the entire system. The research team also analysed about 2,000 VPN user manuals from universities worldwide and found configuration issues in more than 300 of them, which could make users fall into traps and have their passwords stolen by hackers. 
 
Given the severity of these findings, the research team has made various safety recommendations to people affected and informed a number of local and foreign institutions about the defects. This research has led to the publication of three papers at well-known international academic conferences. The team was given the Best Paper Award at the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks (ACM WiSec 2023). 
 
Safety tips for enterprise Wi-Fi and VPNs. 
  • For vendors: good products are not just about functionality and usability; they need to be designed carefully to nudge users into choosing secure settings, and also tested thoroughly to prevent implementation defects that can reduce security.
  • For IT admins: when it comes to educating users, it is important to teach them not only how to make things work, but also how to make things safe. Think about scenarios where the unexpected can happen and teach users how to deal with them properly. 
  • For users: although it can be very tempting, blindly clicking buttons like “OK”, “Connect” and “Accept” is generally bad practice. Try to understand the potential implications before giving in to the convenience. When in doubt, talk to IT admin and ask questions. 
 
Appendix
 
Please click the links below for the conference briefing and papers.
 
 

 

A low-cast, portable Evil Twin (ET) attack setup

Professor Chau Sze-yiu’s team won the Best Paper Award at the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks (ACM WiSec 2023)

Different types of liveness detection schemes used by facial recognition systems

From left: Professor Lau Wing-cheong and Professor Chau Sze-yiu

 

Filter: Dept: 
Faculty
IE
Media Release

55 Engineering Professors listed as World's Top 2% Scientists by Stanford University

Date: 
2023-10-24
Thumbnail: 
Body: 
55 Engineering professors, i.e., more than one-third of the academic staff of the Faculty of Engineering, are listed as the world’s top 2% most-cited scientists by Stanford University in its recently updated science-wide author database.   3 of them are ranked among the top 100 of their respective fields. This recognition manifests the substantial impacts of the research accomplished by the Faculty members, and hence their research strengths worldwide. 
 
Stanford University published in October 2023 its updated database (version 6) of the top 2% scientists that are most widely cited till end of citation year 2022. In this update of the database, over 100,000 top worldwide scientists in 22 scientific fields and 174 sub-fields are ranked. The ranking is twofold: the scientists’ career-long citation impacts up to the end of 2022 and their impacts specific to the year 2022. Among the 55 Engineering professors of CUHK, 54 of them are on the career-long ranking list, and 42 are on the list of the single-year impacts in 2022. The ranking in the database is based on various indicators, for instance the number of citations they received, their individuals’ scientific research output, and citations to papers in different authorship positions.
  
The database could be downloaded at: https://elsevier.digitalcommonsdata.com/datasets/btchxktzyw/6. This version of the database details out various standardized citation metrics of individual top-cited scientists, such as h-index, co-authorship adjusted hm-index and a composite indicator (c-score), according to the 1 October 2023 snapshot of the data updated to end of citation year 2022 by Scopus, an abstract and citation database covering over eight million records of scholarly literature across a wide variety of disciplines.  
 
A list of the aforementioned 55 Engineering professors is available here.  Congratulations to our Faculty members!
 

 

Filter: Dept: 
Faculty

CUHK and HKMA sign MoU to establish CBDC Expert Group

Date: 
2023-10-20
Thumbnail: 
Body: 
The Chinese University of Hong Kong (CUHK) together with four other local universities, signed a Memorandum of Understanding (MoU) with The Hong Kong Monetary Authority (HKMA) on 20 October 2023 for the establishment of a Central Bank Digital Currency (CBDC) Expert Group in supporting the foster of collaboration and exchange on CBDC research between the practitioner and the academia. 
 
The MoU was signed by Prof. Hon Ki TSANG, Interim Dean of the Faculty of Engineering of CUHK and Mr Colin POU, Executive Director (Financial Infrastructure) of HKMA. 
 
Professor Tsang remarked, “It is our honour to be a part of the CBDC Expert Group, working alongside the HKMA and other experts to address key policy and technical issues in CBDC research. The Faculty of Engineering is recognized for our excellence in research. With our experts in Engineering and FinTech, we are delighted to witness the development and enhancement of CBDC research with our advanced technologies.” 
 
Through the establishment of the CBDC Expert Group, experts from a range of disciplines, including business, computer science, economics, finance, and law are brought together with the aim to foster collaboration and knowledge exchange on CBDC research work. Under the MoU, the group will support the exploration of key policy and technical issues surrounding CBDC, and offer advices, training sessions, and workshops pertaining to CBDC and related fintech topics to the HKMA.
 

Professor Hon Ki Tsang (right) and Mr Colin Pou (left) signed the MoU.

 

 

Filter: Dept: 
Faculty
Media Release

MPhil/PhD Virtual Information Session 2023 - Faculty of Engineering

Date: 27 Oct 2023 (Friday)
Time: 4:30pm - 5:45pm (Hong Kong Time)
Mode of Delivery: Online via ZOOM
Registration Deadline: 5pm, 26 Oct 2023
 
Rundown:
• Brief Introduction of the Faculty of Engineering by Associate Dean (Research)
• Brief Introduction of Engineering MPhil/PhD Programmes by Vice-Chairmen (Graduate) or Programme Representatives 
   -- MPhil-PhD in Biomedical Engineering
   -- MPhil-PhD in Computer Science and Engineering
   -- MPhil-PhD in Electronic Engineering
   -- MPhil-PhD in Information Engineering
   -- MPhil-PhD in Mechanical and Automation Engineering
   -- MPhil-PhD in Systems Engineering and Engineering Management
• Q&A
Venue
online via Zoom [registration link: https://cloud.itsc.cuhk.edu.hk/webform/view.php?id=13673728]
Date: 
Friday, October 27, 2023
Time
Friday, October 27, 2023 to 17:45
e_title: 
MPhil/PhD Virtual Information Session 2023 - Faculty of Engineering
Not Available
Allow Regsiter: 

港中大廖維新獲達文西獎 為首位獲獎香港學者

香港新聞網9月18日電 香港中文大學18日公佈,機械與自動化工程學系系主任廖維新最近獲美國機械工程師學會(ASME)設計工程分部頒發2023年達文西獎,是該獎項創立45年來首位獲獎的香港學者。

Date: 
Monday, September 18, 2023
Media: 
HKCNA

Pages