VLDB 2026 Research / reviewers in the wild / expert
Chuan Sheng
dblp:207/5413
· DBLP profile ↗
14ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0001-7739-8828ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-scale hierarchical causality-inspired graph network for interpretable anomaly detection in industrial time series
Yushan Fang, Yu Yao 0002, Wei Yang 0044, Xiaoli Lin, Chuan Sheng |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | Security script arrangement based on enhanced BERT for cooperative defense in networked control systems
Shengbao An, Aiping Tan, Chuan Sheng |
Expert Syst. Appl. | 6 |
| 2026 | Target detection and SINR, CRB analysis for bistatic coherent FDA radar based on multichannel parallel ADMF receiving structure
Xuchen Gao, Junwei Xie 0001, Chuan Sheng, Jingwei Xu 0002, Haowei Zhang 0001 |
Signal Process. | 3 |
| 2026 | Reverse Engineering of Industrial Protocols From Network TrafficabstractReliable protocol knowledge is often difficult to obtain in industrial networks, as industrial communications come with limited documentation, vendor-specific encodings, and opaque payloads. This lack of transparency hinders message interpretation and protocol analysis. To recover this missing protocol knowledge, network-trace-based protocol reverse engineering (PRE) infers message structure, field roles, and interaction logic directly from recorded traces. This enables protocol-aware intrusion detection, process monitoring, and protocol testing and fuzzing without access to device internals. Although PRE has advanced rapidly, existing techniques are developed under diverse objectives and assumptions. As a result, it is often unclear how isolated results relate to an end-to-end reverse-engineering workflow, and how evaluation outcomes should be compared across tasks and protocols. In this article, we cast reverse engineering of industrial protocols from network traces as a task-driven pipeline and articulate a unified task decomposition spanning message type identification, protocol syntax and semantic inference, payload pattern recognition and semantic inference, and protocol state machine reconstruction. For each task, we describe key methodological themes, common evaluation practices, and practical limitations that affect robustness and deployability in industrial settings. We further discuss security, privacy, and ethical risks that accompany increasingly capable PRE, and identify promising research directions toward more systematic, dependable, and deployment-oriented PRE methodologies. Chuan Sheng, Shan Jiang 0023, Qing-Long Han, Wei Zhou 0044, Wanlun Ma, Xiaogang Zhu 0001, Sheng Wen, Yang Xiang 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2026 | IMADP: Imputation-Based Anomaly Detection in SCADA Systems via Adversarial Diffusion ProcessabstractAs the confrontation of the industrial cybersecurity upgrades, multi-dimensional variables measured by the SCADA multi-sensor are critical for assessing security risks in industrial field devices. While Deep Learning (DL) methods based on generative models have demonstrated effectiveness, the impact of missing features in samples and temporal window size on modeling and detection processes has been consistently overlooked. To address these challenges, this work proposes an IMADP framework that integratively solves two tasks of missingness patching and anomaly detection. Firstly, the Window-based Adaptive Selection Strategy (WASS) is also designed to intelligently window samples, reducing reliance on prior settings. Secondly, an imputer is constructed under WASS to restore sample integrity, which is implemented by a fully-connected network centered on Neural Controlled Differential Equations (NCDEs). Thirdly, a adversarial diffusion detection model with the variant Transformer as the inverse solver is proposed. Additionally, the Adaptive Dynamic Mask Mechanism (ADMM) is built upon to bolster the model’s comprehension of inter-dependencies between time and sensor nodes. Simultaneously, adversarial training is introduced to optimize training and detection latency caused by the excessive diffusion step size during the native Conditional Diffusion process. The experimental results validate that the proposed framework has the capability to build detectors using missing training samples, and its overall detection performance, tested across six datasets, is superior to existing methods. Yu Yao 0002, Chuan Sheng, Ziyong Ran, Wei Yang 0044 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | Network Traffic Fingerprinting for IIoT Device Identification: A SurveyabstractAs the Industrial Internet of Things (IIoT) continues to expand, the need for effective device identification becomes critical for securing industrial environments. Network traffic fingerprinting has emerged as an important technique for IIoT device identification, leveraging the unique communication patterns embedded in network traffic. Despite significant efforts in this area, a comprehensive overview of the relevant research is still missing. To address the lack of comprehensive research, this paper, for the first time, identifies critical knowledge gaps constraining IIoT device identification through network traffic analysis: obscure fingerprint feature space, limited generalizability to unknowns, and scarce data sources. Focusing on these gaps, existing methods are analyzed and summarized in detail across network traffic fingerprinting, IIoT device identification, and public IIoT datasets. Specifically, network traffic fingerprinting methods are categorized into three levels: Packet-level, flow-level, and business-level, and relevant methods are examined in terms of data formats, segmentation units, and extraction or generation techniques. In the context of IIoT device identification, tasks such as device type, model, and instance recognition, as well as abnormal device detection, are extensively investigated using rule-based, traditional machine learning- based, and deep learning-based approaches, with a focus on device fingerprints and application scenarios. Furthermore, main public datasets from the IoT, ICS, and IIoT scenarios are highlighted to support the development of fingerprinting and identification methods. Finally, several future research directions are proposed to guide new advancements in this area. Chuan Sheng, Wei Zhou 0044, Qing-Long Han, Wanlun Ma, Xiaogang Zhu 0001, Sheng Wen, Yang Xiang 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | ALOC: Attack-Aware by Utilizing the Adversarially Learned One-Class Classifier for SCADA SystemabstractAs the volume of network attacks on Supervisory Control and Data Acquisition (SCADA) systems increases, the existing supervised methods that over-rely on priori knowledge can hardly cope with increasingly stealthy and legitimate unknown protocol attacks for heterogeneous industrial scenarios. In this paper, we present an anomaly-based deep learning attack-aware method called ALOC, which constitutes the dual Frequency Domain Transform (FDT) and implicit Generative Adversarial Networks (GANs). The former is proposed that reduces the cost of hand-designed features and normalizes raw traffic bytes as the input under different protocol types. With the assistance of a Deep Auto-Encoder (DAE) with 1D Convolutional Neural Networks (1D-CNNs), the latter can automatically build a behavioral baseline based on the multi-scale distribution of transformed raw bytes. The potential SCADA anomalies or intrusions can be effectively detected, which enables field operators to avoid security risks in a timely manner. Essentially, the trained model conveniently determines the anomaly boundaries by augmenting the representation capabilities of raw session information in high-dimensional space. In response, adversarial training with different loss functions is introduced to constrain the reconstruction of anomalous samples extremely, which in turn improves the detection performance and analyzes anomaly attributes. The experimental results show that the proposed approach is more effective and generalized than existing state-of-the-art baselines. Yu Yao 0002, Chuan Sheng, Wei Yang 0044 |
IEEE Internet Things J. | 3 |
| 2024 | Scanner-Hunter: An Effective ICS Scanning Group Identification SystemabstractAs the precursor of cyber-attacks, the campaigns of scanning groups are able to reflect the attack target and attack trend to a great extent, which provide highly valuable threat intelligence for cyber defenders to understand the current cyber security situation. However, how to identify scanning groups in the context of limited information, especially in the absence of relevant threat intelligence, remains a challenging problem. In this paper, we utilize the honeynet as the unique data source to propose a scanning group identification system, Scanner-Hunter, which focuses on identifying scanning groups targeting ICS devices. To better characterize scanning patterns, a novel traffic representation scheme for scanning traffic is proposed, which is composed of a set of feature vectors to describe all the ICS request packets. On this basis, we propose a novel self-expanding multi-class classification (SEMCC) model and the IP prefix judgment, which are deliberately integrated to cope with sophisticated scanning groups. Take the Modbus protocol as an example, we implement a prototype of Scanner-Hunter, and use six years of real-world honeynet datasets to evaluate its performance. The experimental results illustrate its effectiveness and superior performance compared with some popular machine learning methods and existing SOTA scanning group identification methods. In addition, Scanner-Hunter is further leveraged to investigate the group distribution and maliciousness of 506 unknown scanners, and some suspicious attack groups with APT characteristics are analyzed. Furthermore, accurate scanning group information will contribute to revealing potential attack organizations and supporting decision making to prevent or interrupt cyber-attacks in time. Chuan Sheng, Yu Yao 0002, Lianxiang Zhao, Peng Zeng 0001, Jianming Zhao |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Unknown Attack Traffic Classification in SCADA Network Using Heuristic Clustering TechniqueabstractAttack Traffic Classification (ATC) technique is an essential tool for Industrial Control System (ICS) network security, which can be widely used in active defense, situational awareness, attack source traceback and so on. At present, the state-of-the-art ATC methods are usually based on traffic statistical features and machine learning techniques, including supervised classification methods and unsupervised clustering methods. However, it is difficult for these methods to overcome the problems of lack of attack samples and high real-time requirement in ATC in Supervisory Control and Data Acquisition (SCADA) networks. In order to address the above problems, we propose a self-growing ATC model based on a new density-based heuristic clustering method, which can continuously and automatically detect and distinguish different kinds of unknown attack traffic generated by various attack tools against SCADA networks in real time. An effective representation method of SCADA network traffic is proposed to further improve the performance of ATC. In addition, a large number of experiments are conducted on a compound dataset consisting of the SCADA network dataset, the attack tool dataset and the ICS honeypot dataset, to evaluate the proposed method. The experimental results show that the proposed method outperforms existing state-of-the-art ATC methods in the crucial situation of only normal SCADA network traffic. Chuan Sheng, Yu Yao 0002, Wei Yang 0044 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | A cyber-physical model for SCADA system and its intrusion detection
Chuan Sheng, Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044 |
Comput. Networks | 1 |
| 2021 | Study on the intelligent honeynet model for containing the spread of industrial viruses
Chuan Sheng, Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044 |
Comput. Secur. | 1 |
| 2018 | An Epidemic Model of Computer Worms with Time Delay and Variable Infection RateabstractWith rapid development of Internet, network security issues become increasingly serious. Temporary patches have been put on the infectious hosts, which may lose efficacy on occasions. This leads to a time delay when vaccinated hosts change to susceptible hosts. On the other hand, the worm infection is usually a nonlinear process. Considering the actual situation, a variable infection rate is introduced to describe the spread process of worms. According to above aspects, we propose a time-delayed worm propagation model with variable infection rate. Then the existence condition and the stability of the positive equilibrium are derived. Due to the existence of time delay, the worm propagation system may be unstable and out of control. Moreover, the threshold τ0 of Hopf bifurcation is obtained. The worm propagation system is stable if time delay is less than τ0 . When time delay is over τ0 , the system will be unstable. In addition, numerical experiments have been performed, which can match the conclusions we deduce. The numerical experiments also show that there exists a threshold in the parameter a , which implies that we should choose appropriate infection rate β(t) to constrain worm prevalence. Finally, simulation experiments are carried out to prove the validity of our conclusions. Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044, Chuan Sheng |
Secur. Commun. Networks | 5 |
| 2017 | A scheduling method based on a hybrid genetic particle swarm algorithm for multifunction phased array radarabstractA hybrid optimization approach combining a particle swarm algorithm, a genetic algorithm, and a heuristic inter-leaving algorithm is proposed for scheduling tasks in the multifunction phased array radar. By optimizing parameters using chaos theory, designing the dynamic inertia weight for the particle swarm algorithm as well as introducing crossover operation and mutation operation of the genetic algorithm, both the efficiency and exploration ability of the hybrid algorithm are improved. Under the frame of the intelligence algorithm, the heuristic interleaving scheduling algorithm is presented to further use the time resource of the task waiting duration. A large-scale simulation demonstrates that the proposed algorithm is more robust and efficient than existing algorithms. Haowei Zhang 0001, Junwei Xie 0001, Wen-long Lu, Chuan Sheng |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2017 | Deceptive jamming discrimination based on range-angle localization of a frequency diverse arrayabstractWe propose a method to suppress deceptive jamming by frequency diverse array (FDA) in radar electronic countermeasure environments. FDA offers a new range-angle-dependent beam pattern through a small frequency increment across elements. Due to the coupling between the angle and range, a mismatch between the test angle and physical angle occurs when the slant range on which the beam focuses is not equal to the slant range of the real target. In addition, the range of the target can be extracted by sum-difference beam except for time-delay testing, because the beam provides a range resolution in the FDA that cannot be deceived by traditional deceptive jamming. A strategy of using FDA to transmit two pulses with zero and nonzero frequency increments, respectively, is proposed to ensure that the angle of a target can be obtained by FDA. Moreover, the localization performance is examined by analyzing the Cramer-Rao lower bound and detection probability. Effectiveness of the proposed method is confirmed by simulation results. Zhaojian Zhang, Junwei Xie 0001, Chuan Sheng, Zhun Tang |
Frontiers Inf. Technol. Electron. Eng. | 3 |