VLDB 2026 Research / reviewers in the wild / expert
Rongkuan Ma
dblp:255/2194
· DBLP profile ↗
10ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0002-4791-6847ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TRACE: Trusted Return-Path Authentication via Context and Lightweight Encryption for IoT DevicesabstractReturn-Oriented Programming (ROP) attacks pose a significant threat to the control-flow integrity of Internet of Things (IoT) devices, which operate in resource-constrained environments with limited memory isolation and runtime protection. Existing defenses, such as shadow stacks and message authentication code (MAC)-based schemes, face key limitations in IoT: shadow stacks depend on trusted hardware often absent in lightweight devices, while message authentication code (MAC) schemes lack semantic binding to the call path, making them vulnerable to replay attacks during recursion or stack reuse. To address these challenges, this paper proposes TRACE, a lightweight return-path authentication mechanism with path-semantic awareness, designed for IoT devices. TRACE dynamically encodes the function call context into an evolving path-state vector, which is then combined with the return address and cryptographically processed to generate a semantically unique authentication tag. At each function return, TRACE reconstructs the path state and verifies the tag to enforce precise runtime control-flow integrity. We evaluate TRACE in both synthetic and real-world attack scenarios. With the RIPE test suite, we demonstrate its robustness across five representative attack dimensions. Additionally, we identify a stack overflow vulnerability in the widely used libmodbus v2.9.3 protocol stack, construct a complete attack chain in a realistic IoT context, and validate TRACE’s effectiveness in mitigating such attacks. Experimental results show that TRACE reliably detects return-path tampering even without Address Space Layout Randomization (ASLR) or stack protections and incurs only a 5.3% runtime overhead, offering strong security with lightweight performance suitable for resource-constrained IoT deployments. Rongkuan Ma, Yong Yu 0002, Siqi Lu, Yongjuan Wang |
IEEE Internet Things J. | 2 |
| 2025 | Yesterday Once MorE: Facilitating Linux Kernel Bug Reproduction via Reverse FuzzingabstractThe Linux kernel remains vulnerable to numerous bugs, with approximately 65% detected by Syzkaller lacking Proof-of-Concept (PoC), hampering risk mitigation efforts. These bugs, termed irreproducible kernel bugs, highlight the challenge of statefulness issue-related irreproducibility in kernel fuzzing, which is an open research without definitive solutions. Our investigation reveals that suboptimal seed quality distribution in fuzzing is the root obstacle preventing effective tracking of the states leading to crashes. Inspired by this insight, we introduce Reverse Fuzzing (RF), an innovative approach that infers hard-to- reach states by continuously reverse-oriented deriving from subsequently encountered bridge states to increase reproduction probability. RF differentiates between the “trigger” seed, which directly causes crashes, and “activator” seeds, which establish the necessary preconditions, prioritizing exploration around trigger while simultaneously regenerating and maintaining activators during fuzzing, which effectively facilitate to restructure such elusive states from “yesterday”. We implement YOME, a prototype leveraging RF to strike a balance between fuzzing efficiency and effectiveness through customized scheduling and mutation strategies, armed with a refinement mechanism to improve seed quality distribution. Our evaluations validate that YOME reproduce 110% more bugs than previous kernel fuzzers and demonstrate its practicality in real-world scenarios. YOME generated 125 PoCs (30.1% of the total) and uncovered 23 unique bugs, with 40 confirmed and 5 assigned CVEs. Xingwei Li, Yan Kang 0002, Chenggang Wu 0002, Danjun Liu, Jiming Wang, Zehui Wu, Yunchao Wang, Rongkuan Ma |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2024 | Control Logic Attack Detection and Forensics Through Reverse-Engineering and Verifying PLC Control ApplicationsabstractIndustrial control systems (ICSs) are prevalent in critical infrastructures, where programmable logic controllers (PLCs) and physical instruments are integrated. However, multiple successful attacks against PLC control logic programs have caused significant damage to ICSs, which has led to an urgent need for detection and forensics of such attacks. Although several off-the-shelf defending mechanisms have been presented in the past, few of them can detect and locate the control logic attacks at run time. In this article, we propose a practical and automatic control logic attack detection and forensics framework (CLADF) to conduct control logic attack detection and forensics in ICSs. Specifically, the core of CLADF includes: 1) a control application extraction module to extract PLC binary control applications by simulating PLC normal upload functionality; 2) a control application reverse engineering module to disassemble binary control applications; and 3) an attack detection and forensics module for verifying the integrity of PLC control applications, recovering the normal control application, and locating the modified control instructions. We extensively evaluated CLADF in five different application scenarios and two real-world Schneider PLCs. For each PLC, we generated three types of 150 mutated control logic attacks. The results demonstrate that CLADF can effectively extract the run-time binary control application in different application scenarios and disassemble these binary control applications into assembly instructions. Moreover, CLADF can accurately detect the attacks and locate the modified subroutines. Yangyang Geng, Rongkuan Ma, Mufeng Wang, Yuqi Chen 0001 |
IEEE Internet Things J. | 3 |
| 2023 | A Lightweight Few-Shot Attack Detection Scheme for Industrial Cognitive Radio NetworksabstractIndustrial cognitive radio networks (ICRNs) have been a promising spectrum -sharing solution for massive resource-constrained wireless devices in the industrial Internet of things (1IoT). However, ICRNs are raising new opportunities for ma-licious users, wherein the threat landscape is compounded with few-shot attacks due to the insufficiency of high-quality examples. In this paper, we propose a novel lightweight intrusion detection system focusing on few-shot attacks for ICRNs, called KDFS-IDS. Specifically, we first develop a teacher-student model based hierarchical intrusion detection framework for ICRNs. Second, we design a convolutional neural network-based intrusion detection model as the fundamental model for identifying few-shot attacks. Third, a knowledge distillation strategy is crafted to obtain a lightweight but sufficiently accurate model for KDFS-IDS. Extensive experiments on three public datasets demonstrate the superiorities of our proposed scheme in detecting few-shot attacks for I CRN s, in terms of both effectiveness and accuracy. Beibei Li 0002, Wanying Dai, Rongkuan Ma, Hanyuan Huang |
GLOBECOM | 4 |
| 2023 | Defending Cyber-Physical Systems Through Reverse-Engineering-Based Memory Sanity CheckabstractCyber–physical systems (CPSs) are ubiquitous in critical infrastructures, where programmable logic controllers (PLCs) and physical components intertwine. However, multiple successful attacks targeting safety-related CPSs, in particular the PLCs, manifest their vulnerability toward malicious cyber attacks, which may cause significant damage consequently. Though several kinds of defending techniques exist in the literature, few of them can be practically and widely applied to real-world CPSs equipped with PLCs from leading vendors, primarily due to the lack of specific hardware or unrealistic defense assumptions. In this article, we propose PLC-READER, a practical memory attacks detection and response framework to secure the CPS. The core of PLC-READER includes: 1) a comprehensive semantic analysis solution specifically for PLC’s proprietary protocol based on software reverse engineering and network traffic difference analysis and 2) a fine-grained memory structure analysis solution to identify the critical memory data. Based on the results of such reverse engineering, PLC-READER further performs sanity checks for the PLC’s critical memory by periodically checking the hash values and dynamic checksum values of these memory data. We extensively evaluated PLC-READER against four types of 366 different memory attacks, with some newly developed ones which got six CVE IDs from Schneider and Rockwell, by analyzing three kinds of proprietary protocols and six kinds of memory structures in six kinds of real-world PLCs from three leading manufacturers. The results demonstrate that the PLC-READER can detect all memory attacks with an accuracy of 100% and perform corresponding emergency responses in time. Yangyang Geng, Yuqi Chen 0001, Rongkuan Ma, Jingyi Wang 0004, Peng Cheng 0001 |
IEEE Internet Things J. | 3 |
| 2022 | MinSIB: Minimized static instrumentation for fuzzing binaries
Yeming Gu, Hui Shu, Pan Yang 0024, Rongkuan Ma |
Comput. Secur. | 4 |
| 2022 | Detection and localization of cyber attacks on water treatment systems: an entropy-based approachabstractWith the advent of Industry 4.0, water treatment systems (WTSs) are recognized as typical industrial cyber-physical systems (iCPSs) that are connected to the open Internet. Advanced information technology (IT) benefits the WTS in the aspects of reliability, efficiency, and economy. However, the vulnerabilities exposed in the communication and control infrastructure on the cyber side make WTSs prone to cyber attacks. The traditional IT system oriented defense mechanisms cannot be directly applied in safety-critical WTSs because the availability and real-time requirements are of great importance. In this paper, we propose an entropy-based intrusion detection (EBID) method to thwart cyber attacks against widely used controllers (e.g., programmable logic controllers) in WTSs to address this issue. Because of the varied WTS operating conditions, there is a high false-positive rate with a static threshold for detection. Therefore, we propose a dynamic threshold adjustment mechanism to improve the performance of EBID. To validate the performance of the proposed approaches, we built a high-fidelity WTS testbed with more than 50 measurement points. We conducted experiments under two attack scenarios with a total of 36 attacks, showing that the proposed methods achieved a detection rate of 97.22% and a false alarm rate of 1.67%. Mufeng Wang, Rongkuan Ma, Zhenyong Zhang |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2022 | Automatic protocol reverse engineering for industrial control systems with dynamic taint analysisabstractProprietary (or semi-proprietary) protocols are widely adopted in industrial control systems (ICSs). Inferring protocol format by reverse engineering is important for many network security applications, e.g., program tests and intrusion detection. Conventional protocol reverse engineering methods have been proposed which are considered time-consuming, tedious, and error-prone. Recently, automatical protocol reverse engineering methods have been proposed which are, however, neither effective in handling binary-based ICS protocols based on network traffic analysis nor accurate in extracting protocol fields from protocol implementations. In this paper, we present a framework called the industrial control system protocol reverse engineering framework (ICSPRF) that aims to extract ICS protocol fields with high accuracy. ICSPRF is based on the key insight that an individual field in a message is typically handled in the same execution context, e.g., basic block (BBL) group. As a result, by monitoring program execution, we can collect the tainted data information processed in every BBL group in the execution trace and cluster it to derive the protocol format. We evaluate our approach with six open-source ICS protocol implementations. The results show that ICSPRF can identify individual protocol fields with high accuracy (on average a 94.3% match ratio). ICSPRF also has a low coarse-grained and overly fine-grained match ratio. For the same metric, ICSPRF is more accurate than AutoFormat (88.5% for all evaluated protocols and 80.0% for binary-based protocols). Rongkuan Ma, Mufeng Wang |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2021 | HRPDF: A Software-Based Heterogeneous Redundant Proactive Defense Framework for Programmable Logic Controller
Jing-Yi Wang, Zhenyong Zhang, Rongkuan Ma, Ruilong Deng |
J. Comput. Sci. Technol. | 6 |
| 2019 | Stealthy Attack Against Redundant Controller Architecture of Industrial Cyber-Physical SystemabstractIn an industrial cyber-physical system (iCPS), the controller plays a critical role in guaranteeing reliability and stability. Therefore, redundant controller architecture is a well-adopted approach by distributed control systems (DCS), supervisory control and data acquisition (SCADA), and other typical iCPSs. They monitor and control the critical industrial process, such as power generation, chemical industry, water treatment plant, etc. Redundant controller architecture has been designed and largely implemented in response to unpredictable mechanical failures. However, this structure initially proposed for guaranteeing reliability and safety may expand the cyber-attack surface, posing the risk that an attacker may take advantage of this architecture for stealthy attacks. In this article, we analyze the vulnerability arising from the redundant controller architecture and propose a combined attack methodology against these redundant controller architecture systems in a stealthy manner. We find several 0-day vulnerabilities of the real-world devices from three manufacturers and further implement the combined attack over these devices. Our experimental results over various types of real-world devices show that the redundant controller architecture can be exploited to compromise all tested systems stealthily. We also present guidelines for mitigating this risk. Rongkuan Ma, Peng Cheng 0001, Zhenyong Zhang |
IEEE Internet Things J. | 1 |