VLDB 2026 Research / reviewers in the wild / expert
Licheng Yang 0002
dblp:237/5899-2
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0009-1387-5846ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A generalizable anomaly detection framework with dynamic concept drift suppression for non-stationary time series
Licheng Yang 0002, Yu Yao 0002, Daoqing Yang, Wei Yang 0044, Yuming Hao |
Knowl. Based Syst. | 1 |
| 2026 | RL-ACID: Reinforcement Learning-Optimized Adaptive Causal Discovery for Robust Anomaly Detection in Industrial SystemsabstractAnomaly detection is essential for the security of industrial control systems. However, dynamic operating conditions introduce nonstationarity and time-varying causal structures, degrading performance and undermining interpretability. To address this, we propose RL-ACID, a lightweight reinforcement learning framework for adaptive causal discovery. It reformulates anomaly detection as sequential causal discovery, introducing the first unified architecture that integrates lightweight reinforcement learning-based search with causal clustering to resolve the adaptability, efficiency, and interpretability tradeoff. Our framework employs a joint time-frequency encoder to extract and construct candidate causal graphs. Building upon this, we design the causal reinforcement learning-based lightweight search algorithm, which formulates graph exploration as a sequential decision process under sparsity and acyclicity constraints, enabling iterative causal structure optimization. To further enhance adaptability in dynamic environments, we introduce a causal clustering module that softly assigns time-varying graphs to latent operational modes through structural experts, thereby distinguishing normal operational fluctuations from true anomalies. Extensive experiments on multiple industrial benchmarks demonstrate the superior performance of RL-ACID. Our framework not only achieves higher accuracy than baselines but also provides interpretable anomaly analysis through causal path tracing. Hechen Yang, Yu Yao 0002, Licheng Yang 0002, Wei Yang 0044 |
IEEE Trans. Ind. Informatics | 3 |
| 2025 | InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation LearningabstractIndustrial control protocols (ICPs) play a significant role in ensuring dependable interconnection among devices in industrial environments. Protocol reverse engineering (PRE) techniques are commonly used to analyze a large number of agnostic and proprietary protocols based on network traffic traces or programs. However, conventional PRE methods face several challenges in reversing ICPs with complex data representations that contain rich structural features. In this work, we present a new perspective on message representation using the graph, and design a syntax inference framework for ICPs reverse analysis (InSyfer). Specifically, we propose a novel method to construct a single message graph for entire traces, automatically extracting syntactical similarity features. We also design an adaptive message clustering model that abstracts the clustering problem into a binary pairwise-classification framework to judge whether pairs of messages belong to the same groups and jointly optimizes it with feature extraction. The above design enables InSyfer to accurately identify message types and greatly improves the correctness of protocol format inference. We conduct extensive experiments to verify the effectiveness of InSyfer. Evaluations of four standard ICPs and two unknown protocols demonstrate that InSyfer outperforms the state-of-the-art PRE methods. Daoqing Yang, Yu Yao 0002, Yao Shan, Xiaoli Lin, Wei Yang 0044, Licheng Yang 0002 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control ProtocolsabstractReverse engineering of agnostic industrial control protocols (ICPs) based on traffic traces is significant for the security analysis of industrial control systems. Field semantics deduction is an essential step in protocol reverse engineering following the discovery of the message field. Most existing methods rely on knowledge-based analysis for specific fields of common protocols, which require too numerous assumptions and lack semantic knowledge about ICPs. In this paper, we propose a new concept, pattern series, and design the first classification framework for inferring the semantic types of unknown ICPs. Specifically, we first present the definition of pattern series and design the field pattern series generation algorithm for building training data, then develop a field semantics classification model to learn and apply semantic features from known protocols to predict semantic types in unknown protocols. Lastly, we implement a probability-maximizing selection algorithm to obtain optimal semantic types. We demonstrate the effectiveness of the proposed method through extensive experiments with five popular ICPs, including their mixed protocols. Evaluations show that our approach significantly outperforms baseline methods in field semantic recognition, achieving ≥90.8% F1-score. Daoqing Yang, Yu Yao 0002, Yao Shan, Licheng Yang 0002, Wei Yang 0044, Fuyi Liu |
IEEE Trans. Inf. Forensics Secur. | 4 |