Xia Cheng

dblp:237/7601 · DBLP profile ↗
← Back
11ranked-venue papers
10as first author
8since 2021 · last 2024
0000-0002-8145-7656ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 7 first-author · 7 since 2021Security and privacy · 2 · 2 first-author
YearPublicationVenuePosition
2024 Configuring Industrial Wireless Mesh Networks via Multi-Source Domain Adaptation
Xia Cheng, Mo Sha 0001, Dong Chen 0025
EWSN1
2024 Adapting Wireless Network Configuration From Simulation to Reality via Deep Learning-Based Domain Adaptation
abstract
Today, wireless mesh networks (WMNs) are deployed globally to support various applications, such as industrial automation, military operations, and smart energy. Significant efforts have been made in the literature to facilitate their deployments and optimize their performance. However, configuring a WMN well is challenging because the network configuration is a complex process, which involves theoretical computation, simulation, and field testing, among other tasks. Our study shows that the models for network configuration prediction learned from simulations may not work well in physical networks because of the simulation-to-reality gap. In this paper, we employ deep learning-based domain adaptation to close the gap and leverage a teacher-student neural network and a physical sampling method to transfer the network configuration knowledge learned from a simulated network to its corresponding physical network. Experimental results show that our method effectively closes the gap and increases the accuracy of predicting a good network configuration that allows the network to meet performance requirements from 30.10% to 70.24% by learning robust machine learning models from a large amount of inexpensive simulation data and a few costly field testing measurements.
Junyang Shi, Aitian Ma, Xia Cheng, Mo Sha 0001, Xi Peng 0005
IEEE/ACM Trans. Netw.3
2024 MERA: Meta-Learning Based Runtime Adaptation for Industrial Wireless Sensor-Actuator Networks
abstract
IEEE 802.15.4-based industrial wireless sensor-actuator networks (WSANs) have been widely deployed to connect sensors, actuators, and controllers in industrial facilities. Configuring an industrial WSAN to meet the application-specified quality of service (QoS) requirements is a complex process, which involves theoretical computation, simulation, and field testing, among other tasks. Since industrial wireless networks become increasingly hierarchical, heterogeneous, and complex, many research efforts have been made to apply wireless simulations and advanced machine learning techniques for network configuration. Unfortunately, our study shows that the network configuration model generated by the state-of-the-art method decays quickly over time. To address this issue, we develop a ME ta-learning based R untime A daptation (MERA) method that efficiently adapts network configuration models for industrial WSANs at runtime. Under MERA, the parameters of the network configuration model are explicitly trained such that a small number of optimization steps with only a few new measurements will produce good generalization performance after the network condition changes. We also develop a data sampling method to reduce the measurements required by MERA at runtime without sacrificing its performance. Experimental results show that MERA achieves higher prediction accuracy with less physical measurements, less computation time, and longer adaptation intervals compared to a state-of-the-art baseline.
Xia Cheng, Mo Sha 0001
ACM Trans. Sens. Networks1
2023 Meta-Learning Based Runtime Adaptation for Industrial Wireless Sensor-Actuator Networks
abstract
IEEE 802.15.4-based industrial wireless sensor-actuator networks (WSANs) have been widely deployed to connect sensors, actuators, and controllers in industrial facilities. Configuring an industrial WSAN to meet the application-specified quality of service (QoS) requirements is a complex process, which involves theoretical computation, simulation, and field testing, among other tasks. Since industrial wireless networks become increasingly hierarchical, heterogeneous, and complex, many research efforts have been made to apply wireless simulations and advanced machine learning techniques for network configuration. Unfortunately, our study shows that the network configuration model generated by the state-of-the-art method decays quickly over time. To address this issue, we develop a MEta-learning based Runtime Adaptation (MERA) method that efficiently adapts network configuration models for industrial WSANs at runtime. Under MERA, the parameters of the network configuration model are explicitly trained such that a small number of optimization steps with only a few new measurements will produce good generalization performance after the network condition changes. Experimental results show that MERA achieves higher prediction accuracy with less physical measurements, less computation time, and longer adaptation intervals compared to a state-of-the-art baseline.
Xia Cheng, Mo Sha 0001
IWQoS1
2023 Revealing Smart Selective Jamming Attacks in WirelessHART Networks
abstract
As a leading industrial wireless standard, WirelessHART has been widely implemented to build wireless sensor-actuator networks (WSANs) in industrial facilities, such as oil refineries, chemical plants, and factories. For instance, 54,835 WSANs that implement the WirelessHART standard have been deployed globally by Emerson process management, a WirelessHART network supplier, to support process automation. While the existing research to improve industrial WSANs focuses mainly on enhancing network performance, the security aspects have not been given enough attention. We have identified a new threat to WirelessHART networks, namely smart selective jamming attacks, where the attacker first cracks the channel usage, routes, and parameter configuration of the victim network and then jams the transmissions of interest on their specific communication channels in their specific time slots, which makes the attacks energy efficient and hardly detectable. In this paper, we present this severe, stealthy threat by demonstrating the step-by-step attack process on a 50-node network that runs a publicly accessible WirelessHART implementation. Experimental results show that the smart selective jamming attacks significantly reduce the network reliability without triggering network updates.
Xia Cheng, Junyang Shi, Mo Sha 0001, Linke Guo
IEEE/ACM Trans. Netw.1
2023 Autonomous Traffic-Aware Scheduling for Industrial Wireless Sensor-Actuator Networks
abstract
Recent years have witnessed rapid adoption of low-power Wireless Sensor-Actuator Networks (WSANs) in process industries. To meet the critical demand for reliable and real-time communication in harsh industrial environments, the industrial WSAN standards make a set of specific design choices, such as employing the Time-Slotted Channel Hopping (TSCH) technique. Such design choices distinguish industrial WSANs from traditional Wireless Sensor Networks, which were designed for best-effort services. Recently, there has been increasing interest in developing new methods to enable autonomous transmission scheduling for industrial WSANs that run TSCH and the Routing Protocol for Low-Power and Lossy Networks (RPL). Our study shows that the current approaches fail to consider the traffic loads of different devices when assigning time slots and channels, which significantly compromises network performance when facing high data rates. In this article, we introduce a novel Autonomous Traffic-Aware transmission scheduling method for industrial WSANs. The device that runs ATRIA can detect its traffic load based on its local routing information and then schedule its transmissions accordingly without the need to exchange information with neighboring devices. Experimental results show that ATRIA provides significantly higher end-to-end network reliability and lower end-to-end latency without introducing additional overhead compared with a state-of-the-art baseline.
Xia Cheng, Mo Sha 0001
ACM Trans. Sens. Networks1
2021 ATRIA: Autonomous Traffic-Aware Scheduling for Industrial Wireless Sensor-Actuator Networks
abstract
Recent years have witnessed rapid adoption of low-power Wireless Sensor-Actuator Networks (WSANs) in process industries. To meet the critical demand for reliable and real-time communication in harsh industrial environments, the industrial WSAN standards, such as WirelessHART, ISA100, WIA-FA, and 6TiSCH, make a set of specific design choices, such as employing the Time Slotted Channel Hopping (TSCH) technique. Such design choices distinguish industrial WSANs from traditional Wireless Sensor Networks (WSNs), which were designed for best-effort services. Recently, there has been increasing interest in developing new methods to enable autonomous transmission scheduling for industrial WSANs that run TSCH and the Routing Protocol for Low-Power and Lossy Networks (RPL). Our study shows that the current approaches fail to consider the traffic loads of different devices when assigning time slots and channels, which significantly compromises network performance when facing high data rates. In this paper, we introduce ATRIA, a novel Autonomous Traffic-Aware transmission scheduling method for industrial WSANs. The device that runs ATRIA can detect its traffic load based on its local routing information and then schedule its transmissions accordingly without the need to exchange information with neighboring devices. Experimental results show that ATRIA provides significantly higher end-to-end network reliability and lower end-to-end latency without introducing additional overhead compared with a state-of-the-art baseline.
Xia Cheng, Mo Sha 0001
ICNP1
2021 Launching Smart Selective Jamming Attacks in WirelessHART Networks
abstract
As a leading industrial wireless standard, WirelessHART has been widely implemented to build wireless sensor-actuator networks (WSANs) in industrial facilities, such as oil refineries, chemical plants, and factories. For instance, 54,835 WSANs that implement the WirelessHART standard have been deployed globally by Emerson process management, a WirelessHART network supplier, to support process automation. While the existing research to improve industrial WSANs focuses mainly on enhancing network performance, the security aspects have not been given enough attention. We have identified a new threat to WirelessHART networks, namely smart selective jamming attacks, where the attacker first cracks the channel usage, routes, and parameter configuration of the victim network and then jams the transmissions of interest on their specific communication channels in their specific time slots, which makes the attacks energy efficient and hardly detectable. In this paper, we present this severe, stealthy threat by demonstrating the step-by-step attack process on a 50-node network that runs a publicly accessible WirelessHART implementation. Experimental results show that the smart selective jamming attacks significantly reduce the network reliability without triggering network updates.
Xia Cheng, Junyang Shi, Mo Sha 0001, Linke Guo
INFOCOM1
2020 Cracking Channel Hopping Sequences and Graph Routes in Industrial TSCH Networks
abstract
Industrial networks typically connect hundreds or thousands of sensors and actuators in industrial facilities, such as manufacturing plants, steel mills, and oil refineries. Although the typical industrial Internet of Things (IoT) applications operate at low data rates, they pose unique challenges because of their critical demands for reliable and real-time communication in harsh industrial environments. IEEE 802.15.4-based wireless sensor-actuator networks (WSANs) technology is appealing for use to construct industrial networks because it does not require wired infrastructure and can be manufactured inexpensively. Battery-powered wireless modules easily and inexpensively retrofit existing sensors and actuators in industrial facilities without running cables for communication and power. To address the stringent real-time and reliability requirements, WSANs made a set of unique design choices such as employing the Time-Synchronized Channel Hopping (TSCH) technology. These designs distinguish WSANs from traditional wireless sensor networks (WSNs) that require only best effort services. The function-based channel hopping used in TSCH simplifies the network operations at the cost of security. Our study shows that an attacker can reverse engineer the channel hopping sequences and graph routes by silently observing the transmission activities and put the network in danger of selective jamming attacks. The cracked knowledge on the channel hopping sequences and graph routes is an important prerequisite for launching selective jamming attacks to TSCH networks. To our knowledge, this article represents the first systematic study that investigates the security vulnerability of TSCH channel hopping and graph routing under realistic settings. In this article, we demonstrate the cracking process, present two case studies using publicly accessible implementations (developed for Orchestra and WirelessHART), and provide a set of insights.
Xia Cheng, Junyang Shi, Mo Sha 0001
ACM Trans. Internet Techn.1
2019 Cracking the Graph Routes in WirelessHART Networks
abstract
As a key response to the Fourth Industrial Revolution, IEEE 802.15.4-based wireless sensor-actuator network (WSAN) technology is gaining rapid adoption in process industries because of its advantage in lowering deployment and maintenance cost and effort in industrial facilities, such as steel mills, oil refineries, and chemical plants. Although most industrial applications operate at low data rates, they often require their underlying networks to provide real-time and reliable data deliveries in harsh industrial environments. IEEE 802.15.4-based WSANs are appealing for use in industrial networks, since they operate at low-power and can be manufactured inexpensively. To meet the stringent real-time and reliability requirements, WSANs, such as WirelessHART networks, make a set of unique design choices such as employing the Time Slotted Channel Hopping (TSCH) and graph routing that distinguish themselves from traditional wireless sensor networks designed for best effort services. However, the security aspects of this increasingly important class of wireless networks are insufficiently investigated in the literature. Our recent work shows that an attacker can reverse engineer the TSCH channel hopping sequences by silently observing the channel activities and put the network in danger of selective jamming attacks, where the attacker jams only the transmission of interest on its specific communication channel in its specific time slot, which makes the attacks energy-efficient and hardly detectable. A critical step for an attacker to launch selective jamming is to identify the routing paths. Our study shows that an attacker can crack the routes used by the graph routing in WirelessHART networks by silently observing the packet transmission activities. In this poster proposal, we present a vulnerability analysis and our case study performed on a 50-device physical testbed using a publicly accessible WirelessHART implementation.
Xia Cheng, Junyang Shi, Mo Sha 0001
AsiaCCS1
2018 Cracking the TSCH Channel Hopping in IEEE 802.15.4e
abstract
Industrial networks typically connect hundreds or thousands of sensors and actuators in industrial facilities, such as steel mills and oil refineries. Although the typical industrial applications operate at low data rates, they pose unique challenges because of their critical demands for reliable and real-time communication in harsh industrial environments. IEEE 802.15.4 based Wireless Sensor-Actuator Networks (WSANs) technology is appealing for use to construct industrial networks because it can be deployed and maintained inexpensively. Battery-powered wireless modules easily and inexpensively retrofit existing sensors and actuators in industrial facilities without running cabling for communication and power. To address the stringent real-time and reliability requirements, WSANs adopt a set of novel design choices such as employing the Time-Synchronized Channel Hopping (TSCH) technology that distinguish themselves from traditional Wireless Sensor Networks (WSNs) that require only best effort services. The equation-based channel hopping used in TSCH simplifies the network operations at the cost of security. Our case study shows that an attacker can reverse engineer the channel hopping sequence by silently observing the channel activities and then perform smart collision attacks. In this poster proposal, we describe our target problem and present our case study based on a publicly accessible implementation of TSCH.
Xia Cheng, Mo Sha 0001
CCS1